
qrLogin Security & Risk Analysis
wordpress.org/plugins/qrloginqrLogin is an authentication system based on the reading of the qr code by the mobile phone and the transfer of authentication data via the http/https …
Is qrLogin Safe to Use in 2026?
Generally Safe
Score 85/100qrLogin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "qrlogin" v1.3.1 plugin demonstrates some good security practices, notably the complete absence of known vulnerabilities and the exclusive use of prepared statements for all SQL queries. This indicates a level of awareness regarding common web application security threats. However, the static analysis reveals a concerning weakness in output escaping, with only 42% of outputs being properly escaped. This significantly increases the risk of Cross-Site Scripting (XSS) vulnerabilities. Additionally, the presence of one unsanitized path flow in the taint analysis, even though it's not classified as critical or high, warrants attention as it represents a potential avenue for malicious input to reach sensitive functions without proper validation or sanitization. The plugin's minimal attack surface and lack of external HTTP requests are positive, but the unescaped output and potential taint flow issues are significant concerns that need to be addressed to improve its overall security posture.
Key Concerns
- Unescaped output (42% proper)
- Flow with unsanitized paths (1 total)
qrLogin Security Vulnerabilities
qrLogin Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
qrLogin Attack Surface
WordPress Hooks 7
Maintenance & Trust
qrLogin Maintenance & Trust
Maintenance Signals
Community Trust
qrLogin Alternatives
IDer Login for WordPress
ider-login
This plugin provides functionality to register and connect to your WordPress via IDer Service.
PasswordleSSI
passwordlessi
This plugin allows passwordless login for Worpdress using SSI as a decentralized technology. Sideos has deployed a proxy service for you to use with y …
Limit Login Attempts Reloaded – Login Security, Brute Force Protection, Firewall
limit-login-attempts-reloaded
Block excessive login attempts and protect your site against brute force attacks. Simple, yet powerful tools to improve site performance.
WPS Hide Login
wps-hide-login
Change wp-login.php to anything you want.
All-In-One Security (AIOS) – Security and Firewall
all-in-one-wp-security-and-firewall
Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plugin designed especially for WordPress.
qrLogin Developer Profile
1 plugin · 10 total installs
How We Detect qrLogin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/qrlogin/qrcode.jsqrcode.jsHTML / DOM Fingerprints
id="qrlogin_wplogin_div"id="qrlogin_qrcode"id="qrl_qrcode"id="qrl_login_status"id="qrlogin_login_error"qrl_divqrl_parent_divqrlogin_wplogin_move_divqrlogin_set_dotsqrlogin_if_loggedqrlogin_stop_scan+3 moreqrl_ajax