
QR User Login Security & Risk Analysis
wordpress.org/plugins/qr-user-loginAllow users to login using a link (or QR code). This plugin can be used for create custom event invitation, for example: wedding, etc.
Is QR User Login Safe to Use in 2026?
Generally Safe
Score 85/100QR User Login has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'qr-user-login' v1.0.0 plugin exhibits a generally good security posture based on the provided static analysis. There are no identified critical or high-severity code signals, dangerous functions, or SQL injection vulnerabilities. The absence of known CVEs and a clean vulnerability history further contribute to this positive assessment, suggesting a mature and well-maintained codebase. The presence of a nonce check is a positive indicator of basic security awareness.
However, a significant concern arises from the complete lack of output escaping. With 7 total outputs identified and 0% properly escaped, this presents a substantial risk for cross-site scripting (XSS) vulnerabilities. Any data rendered to the user interface without proper escaping can be manipulated by attackers to inject malicious scripts. Furthermore, the absence of any capability checks is concerning, as it implies that certain functionalities might be accessible to users who shouldn't have access, depending on what these functions actually do, which is not detailed in the provided data. While the attack surface appears small and unprotected entry points are zero, the lack of output escaping creates a glaring vulnerability. The absence of taint analysis data makes it impossible to fully assess risks related to data manipulation, but the output escaping issue is a concrete and significant threat.
In conclusion, while the plugin avoids common pitfalls like SQL injection and dangerous functions, and has no known vulnerabilities, the critical lack of output escaping is a major security flaw that requires immediate attention. The lack of capability checks, though not as immediately critical as XSS, also warrants investigation. The absence of recorded vulnerabilities is a strength, but does not negate the identified code issues. Addressing the output escaping would significantly improve the plugin's security.
Key Concerns
- All identified outputs are unescaped
- No capability checks found
QR User Login Security Vulnerabilities
QR User Login Code Analysis
Output Escaping
QR User Login Attack Surface
WordPress Hooks 4
Maintenance & Trust
QR User Login Maintenance & Trust
Maintenance Signals
Community Trust
QR User Login Alternatives
SQRL Login
sqrl-login
Secure Quick Reliable Login, this plugin will enable logging in using SQRL clients.
IDer Login for WordPress
ider-login
This plugin provides functionality to register and connect to your WordPress via IDer Service.
Login with QR
login-with-qr
Make your users login via link or QR code.
QR Code Login Admin
qr-code-login-admin
Permette l'accesso al tuo sito web senza inserire username e password, generando semplicemente un qr-code. Abilitato solo per gli amministratori.
qrLogin
qrlogin
qrLogin is an authentication system based on the reading of the qr code by the mobile phone and the transfer of authentication data via the http/https …
QR User Login Developer Profile
1 plugin · 10 total installs
How We Detect QR User Login
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/qr-user-login/templates/edit_user_profile.php/wp-content/plugins/qr-user-login/templates/qr-login-capability.phpqr-user-login/style.css?ver=qr-user-login/script.js?ver=HTML / DOM Fingerprints
name="qr_login_roles[]"value="administrator"value="editor"value="author"value="contributor"value="subscriber"