
Secure Passkeys Security & Risk Analysis
wordpress.org/plugins/secure-passkeysSecure Passkeys is a powerful WordPress plugin that enables passwordless authentication using WebAuthn technology.
Is Secure Passkeys Safe to Use in 2026?
Generally Safe
Score 99/100Secure Passkeys has a strong security track record. Known vulnerabilities have been patched promptly.
The secure-passkeys plugin v1.2.4 exhibits a mixed security posture. On the positive side, it demonstrates strong practices in SQL query preparation (89%) and output escaping (97%), with no identified dangerous functions or external HTTP requests. The low number of file operations and the presence of a nonce check and some capability checks are also encouraging signs. However, a significant concern is the large attack surface exposed through AJAX handlers, with 100% of the 13 identified AJAX handlers lacking authentication checks. Furthermore, the taint analysis revealed 6 high-severity flows with unsanitized paths, indicating potential vulnerabilities where untrusted data could lead to unintended consequences.
Key Concerns
- AJAX handlers without auth checks
- High severity taint flows (unsanitized paths)
- Nonce checks present, but limited
- Capability checks present, but limited
Secure Passkeys Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Secure Passkeys <= 1.2.1 - Missing Authorization to Authenticated (Subscriber+) Passkey Exposure and Deletion
Secure Passkeys Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Secure Passkeys Attack Surface
AJAX Handlers 13
Shortcodes 2
WordPress Hooks 22
Maintenance & Trust
Secure Passkeys Maintenance & Trust
Maintenance Signals
Community Trust
Secure Passkeys Alternatives
Temporary Login Without Password
temporary-login-without-password
Create self-expiring, temporary admin accounts. Easily share direct login links (no need for username/password) with your developers or editors.
Login Links – Passwordless Login, Temporary Access Links & Custom Login Form
login-links
Create secure self-expiring login links for temporary access and guest users, and enable passwordless login for registered ones.
Keyless Auth – Login without Passwords
keyless-auth
Secure, passwordless authentication for WordPress. Your users login via magic email links – no passwords to remember or forget.
Bye Bye Passwords
bye-bye-passwords
Enable passwordless authentication for WordPress using WebAuthn/Passkeys. More secure, more convenient.
Password Less Login
password-less-login
A powerful and easy-to-use WordPress plugin for passwordless and OTP-based login.
Secure Passkeys Developer Profile
6 plugins · 1K total installs
How We Detect Secure Passkeys
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/secure-passkeys/assets/frontend/css/login.css/wp-content/plugins/secure-passkeys/assets/frontend/js/webauthn.login.js/wp-content/plugins/secure-passkeys/assets/frontend/js/vue.js/wp-content/plugins/secure-passkeys/assets/frontend/js/webauthn.register.js/wp-content/plugins/secure-passkeys/assets/frontend/css/register.csswebauthn.login.jsvue.jswebauthn.register.jssecure-passkeys/assets/frontend/css/login.css?ver=secure-passkeys/assets/frontend/js/webauthn.login.js?ver=secure-passkeys/assets/frontend/js/vue.js?ver=secure-passkeys/assets/frontend/js/webauthn.register.js?ver=secure-passkeys/assets/frontend/css/register.css?ver=HTML / DOM Fingerprints
secure-passkeys-login-formsecure-passkeys-register-formdata-noncesecure_passkeys_objectsecure_passkeys_registration_object/wp-json/secure-passkeys/v1/login/wp-json/secure-passkeys/v1/register/wp-json/secure-passkeys/v1/options[secure_passkeys_login_form][secure_passkeys_register_form]