
Recent Logins Security & Risk Analysis
wordpress.org/plugins/recent-loginsIs there someone else logging in to your account? Keep an eye on your recent login records.
Is Recent Logins Safe to Use in 2026?
Generally Safe
Score 85/100Recent Logins has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "recent-logins" plugin v1.0.0 presents a concerning security posture, despite a clean vulnerability history. While the plugin boasts a zero attack surface for common entry points like AJAX, REST API, shortcodes, and cron events, indicating good initial design in those areas, the code analysis reveals significant underlying risks. The presence of the `unserialize` function is a major red flag, especially when combined with the fact that no nonce checks are implemented. This combination can lead to remote code execution vulnerabilities if an attacker can control the data being unserialized.
Furthermore, the plugin executes SQL queries without using prepared statements, increasing the risk of SQL injection attacks. The lack of output escaping on all identified outputs means that any data displayed by the plugin is vulnerable to cross-site scripting (XSS) attacks. Although there are no known CVEs, this does not negate the inherent risks identified in the code. The plugin demonstrates a clear weakness in secure coding practices, particularly around input validation and data sanitization, which could be easily exploited if an attacker can influence the serialized data or database inputs.
Key Concerns
- Unescaped output (all outputs)
- Raw SQL without prepare
- Dangerous function: unserialize
- Missing nonce checks
Recent Logins Security Vulnerabilities
Recent Logins Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Recent Logins Attack Surface
WordPress Hooks 8
Maintenance & Trust
Recent Logins Maintenance & Trust
Maintenance Signals
Community Trust
Recent Logins Alternatives
When Last Login – Export User Records
when-last-login-export-user-records
Export your user's login records into a CSV or JSON file in seconds.
WP Users Login History
wp-users-login-history
Track website's users by their login related information like Last login Date/Time, Environment/Server IP address,Country/City/Continent/Timezone …
User Login Tracker
user-login-tracker
Monitor user login activity with advanced analytics, visual charts, and comprehensive tracking dashboard.
Login Activity Tracker
login-activity-tracker
Tracks user login attempts and displays login logs with styled pagination for admins and users.
WP Easy Login – Remember Recent Usernames
wp-easy-login
WP Easy Login stores the recent logins and makes it easy for you to login by selecting an account.
Recent Logins Developer Profile
6 plugins · 180 total installs
How We Detect Recent Logins
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
recent-logins-wraprecent-login-table