
SAML IDP – Login with WordPress Users via SAML SSO Security & Risk Analysis
wordpress.org/plugins/saml-identity-provider-by-wpintegrals‼️ Important - This plugin is deprecated and no longer maintained.
Is SAML IDP – Login with WordPress Users via SAML SSO Safe to Use in 2026?
Generally Safe
Score 100/100SAML IDP – Login with WordPress Users via SAML SSO has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The saml-identity-provider-by-wpintegrals plugin v2.1.3 exhibits a mixed security posture. While a significant majority of SQL queries utilize prepared statements and output escaping is robust, there are notable areas of concern. The presence of 9 AJAX handlers, with 6 lacking authentication checks, represents a considerable attack surface. Furthermore, taint analysis reveals 4 flows with unsanitized paths, all classified as high severity, indicating potential for sensitive data exposure or unauthorized actions if these flows can be triggered by an attacker. The plugin's history of zero known CVEs is a positive indicator, suggesting either good development practices or limited historical scrutiny. However, the identified taint issues and unprotected AJAX endpoints present real risks that outweigh the positive history.
Key Concerns
- AJAX handlers without authentication
- High severity unsanitized taint flows
- Dangerous function: unserialize
SAML IDP – Login with WordPress Users via SAML SSO Security Vulnerabilities
SAML IDP – Login with WordPress Users via SAML SSO Release Timeline
SAML IDP – Login with WordPress Users via SAML SSO Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
SAML IDP – Login with WordPress Users via SAML SSO Attack Surface
AJAX Handlers 9
WordPress Hooks 10
Maintenance & Trust
SAML IDP – Login with WordPress Users via SAML SSO Maintenance & Trust
Maintenance Signals
Community Trust
SAML IDP – Login with WordPress Users via SAML SSO Alternatives
SAML IDP – Login with WordPress Users via SAML SSO Developer Profile
2 plugins · 20 total installs
How We Detect SAML IDP – Login with WordPress Users via SAML SSO
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/saml-identity-provider-by-wpintegrals/css/wp-saml-idp-styles.css/wp-content/plugins/saml-identity-provider-by-wpintegrals/css/wp-saml-idp-admin.css/wp-content/plugins/saml-identity-provider-by-wpintegrals/js/wp-saml-idp-admin.jswp-content/plugins/saml-identity-provider-by-wpintegrals/js/wp-saml-idp-admin.jssaml-identity-provider-by-wpintegrals/css/wp-saml-idp-styles.css?ver=saml-identity-provider-by-wpintegrals/css/wp-saml-idp-admin.css?ver=saml-identity-provider-by-wpintegrals/js/wp-saml-idp-admin.js?ver=HTML / DOM Fingerprints
wp-saml-idp-admin-wrapwpintidp_configured_sp_tabswpintidp_sp_form_wrapperwpintidp_sp_add_button<!-- Settings --><!-- IdP Metadata --><!-- Support --><!-- License -->+5 moredata-noncedata-ajaxurlwpSamlIdp/wp-json/wpintidp/v1/settings/wp-json/wpintidp/v1/service-providers