
RapID Secure Login Security & Risk Analysis
wordpress.org/plugins/rapid-secure-loginRapID Secure Login (RapID-SL) is a simple and convenient authentication plugin.
Is RapID Secure Login Safe to Use in 2026?
Generally Safe
Score 85/100RapID Secure Login has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "rapid-secure-login" plugin v2.0.15 presents a mixed security posture. On the positive side, the plugin demonstrates a strong commitment to secure coding practices by exclusively using prepared statements for all SQL queries and avoiding dangerous functions. Its vulnerability history is clean, with no recorded CVEs, suggesting a generally well-maintained codebase.
However, significant concerns arise from the static analysis. The plugin exposes a large attack surface, with 27 out of 30 entry points lacking authentication checks. This is further exacerbated by the taint analysis revealing 9 unsanitized path flows, 7 of which are classified as high severity. These unsanitized paths, combined with the unprotected entry points, create a substantial risk of unauthorized access, data manipulation, or even remote code execution if an attacker can leverage these weaknesses.
While the absence of known vulnerabilities is a good sign, the high number of unprotected entry points and critical taint flows overshadows this strength. The plugin's developers need to prioritize implementing proper authentication and authorization checks on all AJAX handlers and thoroughly sanitize the identified unsanitized paths to mitigate the substantial risks identified.
Key Concerns
- Large attack surface without auth checks
- High severity unsanitized taint flows
- Unsanitized path flows
- Moderate output escaping
- Bundled TCPDF library
RapID Secure Login Security Vulnerabilities
RapID Secure Login Release Timeline
RapID Secure Login Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
RapID Secure Login Attack Surface
AJAX Handlers 27
Shortcodes 3
WordPress Hooks 16
Maintenance & Trust
RapID Secure Login Maintenance & Trust
Maintenance Signals
Community Trust
RapID Secure Login Alternatives
Wordfence Login Security
wordfence-login-security
Secure your website with Wordfence Login Security, providing two-factor authentication, login and registration CAPTCHA, and XML-RPC protection.
Llavero.io
llavero-io
Este plugin permite vincular las cuentas de usuario de WordPress con Llavero.io para tener un segundo factor de authenticación (2FA) en el login de lo …
PassClip Auth for WordPress
passclip-auth-for-wordpress
"PassClip Auth" provides strong and easy authentication. "PassClip Auth for WordPress" is the plugin to launch PassClip Auth to Wo …
4Login for Secure And Smart Access
4login-for-secure-and-smart-access
4Login will give you an easy and powerful authentication (connect to an external server for authentication).
AV 2FA
av-2fa
A simple and secure Two-Factor Authentication plugin that sends a verification code to your email.
RapID Secure Login Developer Profile
1 plugin · 10 total installs
How We Detect RapID Secure Login
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/rapid-secure-login/css/rpsl_style.css/wp-content/plugins/rapid-secure-login/js/rpsl_login.js/wp-content/plugins/rapid-secure-login/js/rpsl_registration.js/wp-content/plugins/rapid-secure-login/js/rpsl_devices.js/wp-content/plugins/rapid-secure-login/js/rpsl_adduser.js/wp-content/plugins/rapid-secure-login/js/rpsl_useraccess.js/wp-content/plugins/rapid-secure-login/js/rpsl_my_devices.js/wp-content/plugins/rapid-secure-login/js/rpsl_diagnostics.js+1 more/wp-content/plugins/rapid-secure-login/js/rpsl_login.js/wp-content/plugins/rapid-secure-login/js/rpsl_registration.js/wp-content/plugins/rapid-secure-login/js/rpsl_devices.js/wp-content/plugins/rapid-secure-login/js/rpsl_adduser.js/wp-content/plugins/rapid-secure-login/js/rpsl_useraccess.js/wp-content/plugins/rapid-secure-login/js/rpsl_my_devices.js+2 morerapid-secure-login/css/rpsl_style.css?ver=rapid-secure-login/js/rpsl_login.js?ver=rapid-secure-login/js/rpsl_registration.js?ver=rapid-secure-login/js/rpsl_devices.js?ver=rapid-secure-login/js/rpsl_adduser.js?ver=rapid-secure-login/js/rpsl_useraccess.js?ver=rapid-secure-login/js/rpsl_my_devices.js?ver=rapid-secure-login/js/rpsl_diagnostics.js?ver=rapid-secure-login/js/rpsl_direct_enrolment.js?ver=HTML / DOM Fingerprints
rpsl-login-containerrpsl-registration-containerrpsl-devices-containerrpsl-adduser-containerrpsl-useraccess-containerrpsl-mydevices-containerrpsl-diagnostics-containerrpsl-directenrolment-container<!-- Important note: As this plugin is concerned with security aspects of your site, --><!-- any modifications to is should be made with care! --><!-- Security trap to block direct access to this script --><!-- Contains global configuration values -->+30 moredata-rpsl-actiondata-rpsl-noncewindow.rpsl_login_ajax_objectwindow.rpsl_registration_ajax_objectwindow.rpsl_devices_ajax_objectwindow.rpsl_adduser_ajax_objectwindow.rpsl_useraccess_ajax_objectwindow.rpsl_mydevices_ajax_object+2 more/wp-json/rpsl/v1/login/wp-json/rpsl/v1/register/wp-json/rpsl/v1/devices/wp-json/rpsl/v1/adduser/wp-json/rpsl/v1/useraccess/wp-json/rpsl/v1/mydevices/wp-json/rpsl/v1/diagnostics/wp-json/rpsl/v1/directenrolment[rpsl_secure_login][rpsl_my_devices][rpsl_direct_enrolment]