
Shibboleth Security & Risk Analysis
wordpress.org/plugins/shibbolethAllows WordPress to externalize user authentication and account creation to a Shibboleth Service Provider.
Is Shibboleth Safe to Use in 2026?
Generally Safe
Score 100/100Shibboleth has a strong security track record. Known vulnerabilities have been patched promptly.
The shibboleth plugin version 2.5.3 demonstrates a generally strong security posture based on the provided static analysis. It exhibits excellent practices by having no identified dangerous functions, no raw SQL queries, and a very high percentage of properly escaped output. The absence of file operations and external HTTP requests further reduces potential attack vectors. The presence of nonce and capability checks, though limited, indicates an awareness of security fundamentals. However, the total lack of entry points identified in the static analysis is somewhat unusual for a functional plugin, which could imply either a very limited scope or a potential blind spot in the analysis itself. The vulnerability history shows a single medium-severity vulnerability from 2016 related to Cross-site Scripting. While this is old and currently unpatched CVEs are zero, it serves as a reminder that past vulnerabilities can recur if not meticulously addressed in subsequent development.
Key Concerns
- One medium vulnerability in history
- Limited capability checks (1)
- Limited nonce checks (7)
Shibboleth Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Shibboleth <= 1.6 - Reflected Cross-Site Scripting
Shibboleth Code Analysis
Output Escaping
Data Flow Analysis
Shibboleth Attack Surface
WordPress Hooks 35
Maintenance & Trust
Shibboleth Maintenance & Trust
Maintenance Signals
Community Trust
Shibboleth Alternatives
Shibboleth With LDAP Authorization
ugrm
This plugin extends the Shibboleth plugin to work with UFAD & Shibboleth at the University of Florida. Developed at the Florida Museum of Natural …
Frontegg SAML SSO
frontegg-saml-sso
Replace the WordPress login and logout flows with secure SAML-based authentication via Frontegg. Easily configure your SSO app from the admin panel.
All-In-One Security (AIOS) – Security and Firewall
all-in-one-wp-security-and-firewall
Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plugin designed especially for WordPress.
Limit Login Attempts
limit-login-attempts
Limit rate of login attempts, including by way of cookies, for each IP. Fully customizable.
WPS Limit Login
wps-limit-login
WPS Limit login limit connection attempts by IP address
Shibboleth Developer Profile
2 plugins · 3K total installs
How We Detect Shibboleth
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.