Primary-Login-Logout-Menu Security & Risk Analysis

wordpress.org/plugins/primary-login-logout-menu

This is an easy way to add Login/Logout link in primary menu with redirect user to specific URL, on login. This plugin willl adds Settings page ( Unde …

0 active installs v1.0.0 PHP + WP 3.0+ Updated Oct 17, 2017
login-redirectlogin-logoutprimary-login-menu
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Primary-Login-Logout-Menu Safe to Use in 2026?

Generally Safe

Score 85/100

Primary-Login-Logout-Menu has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The "primary-login-logout-menu" plugin v1.0.0 presents a generally good security posture with no known vulnerabilities or critical code signals. The absence of AJAX handlers, REST API routes, shortcodes, cron events, and file operations, combined with the complete avoidance of dangerous functions and raw SQL queries, indicates a well-contained plugin. The presence of a capability check further enhances its security.

However, a significant concern arises from the output escaping. With two outputs identified and none properly escaped, there is a clear risk of Cross-Site Scripting (XSS) vulnerabilities. Any user-supplied data that is reflected in the plugin's output without proper sanitization could be exploited to inject malicious scripts, compromising user sessions or redirecting users to malicious sites. The lack of taint analysis results might suggest limited testing or complexity, but it doesn't negate the explicit output escaping issue.

The plugin's vulnerability history is clean, showing no past CVEs. This, coupled with the current static analysis findings of no critical issues, suggests a developer who is either diligent in their coding practices or has kept the plugin simple enough to avoid common pitfalls. Nonetheless, the unescaped output is a tangible risk that needs immediate attention to ensure a secure user experience.

Key Concerns

  • Unescaped output identified
Vulnerabilities
None known

Primary-Login-Logout-Menu Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Primary-Login-Logout-Menu Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped2 total outputs
Attack Surface

Primary-Login-Logout-Menu Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_menuclasses\class-bsf-menu-loader.php:54
actionadmin_enqueue_scriptsclasses\class-bsf-menu-loader.php:55
actionadmin_initclasses\class-bsf-menu-loader.php:56
filterwp_nav_menu_itemsincludes\class-bsf-primary-menu.php:8
actionadmin_initincludes\class-bsf-primary-menu.php:34
Maintenance & Trust

Primary-Login-Logout-Menu Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedOct 17, 2017
PHP min version
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

Primary-Login-Logout-Menu Developer Profile

Anil Jadhav

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Primary-Login-Logout-Menu

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/primary-login-logout-menu/assets/css/admin.css

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Primary-Login-Logout-Menu