Single Sign-On – Professional SSO solution for WordPress Security & Risk Analysis

wordpress.org/plugins/single-sign-on-sso

Single Sign-On is a professional SSO extension that works accross different domains, servers and websites. Installed in just a few minutes.

30 active installs v2.1.2 PHP + WP 3.0+ Updated Feb 11, 2022
access-controlsingle-loginsingle-passwordsingle-sign-onsso
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Single Sign-On – Professional SSO solution for WordPress Safe to Use in 2026?

Generally Safe

Score 85/100

Single Sign-On – Professional SSO solution for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The "single-sign-on-sso" v2.1.2 plugin exhibits a generally positive security posture, with no known historical vulnerabilities or critical issues identified in the static analysis. The plugin correctly utilizes prepared statements for all SQL queries, which is a strong indicator of good database security practices and mitigates the risk of SQL injection. Furthermore, the absence of taint analysis findings, particularly for unsanitized paths and critical/high severity flows, suggests a well-managed data handling process within the plugin.

However, there are areas for improvement. The plugin has 12 total output escalations, with 67% properly escaped, leaving 33% of outputs potentially unescaped. This could open the door to cross-site scripting (XSS) vulnerabilities if user-supplied data is displayed without adequate sanitization. Additionally, while the plugin has two AJAX handlers, neither has capability checks, meaning any authenticated user could potentially trigger these actions, regardless of their role or permissions. The presence of file operations and external HTTP requests, while not inherently risky, warrants careful review for potential vulnerabilities that could be exploited by manipulating these functions.

Overall, the plugin demonstrates a commitment to secure coding by avoiding dangerous functions and using prepared statements. The lack of historical CVEs is also a positive sign. Nevertheless, the unescaped output and the absence of capability checks on AJAX handlers represent tangible security risks that should be addressed to further harden the plugin's security. Addressing these specific concerns would elevate the plugin's security to a more robust level.

Key Concerns

  • Unescaped output found
  • AJAX handlers without capability checks
Vulnerabilities
None known

Single Sign-On – Professional SSO solution for WordPress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Single Sign-On – Professional SSO solution for WordPress Release Timeline

v2.1.2Current
v2.1.1
v2.0.1
v2.0
v1.0.1
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

Single Sign-On – Professional SSO solution for WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
4
8 escaped
Nonce Checks
2
Capability Checks
0
File Operations
10
External Requests
1
Bundled Libraries
0

SQL Query Safety

100% prepared4 total queries

Output Escaping

67% escaped12 total outputs
Attack Surface

Single Sign-On – Professional SSO solution for WordPress Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_oa_single_sign_on_admin_autodetect_api_connection_handlerincludes/admin_interface.php:106
authwp_ajax_oa_single_sign_on_admin_check_api_settingsincludes/admin_interface.php:220
WordPress Hooks 19
actionadmin_initincludes/admin_interface.php:19
actionadmin_enqueue_scriptsincludes/admin_interface.php:20
actionadmin_menuincludes/admin_interface.php:22
actionadmin_noticesincludes/admin_interface.php:48
actionwp_enqueue_scriptsincludes/core.php:198
actionadmin_enqueue_scriptsincludes/core.php:199
actionlogin_enqueue_scriptsincludes/core.php:200
filterwp_loginincludes/core.php:211
actionprofile_updateincludes/core.php:274
actionuser_registerincludes/core.php:341
filterauthenticateincludes/core.php:365
filterauthenticateincludes/core.php:397
actionclear_auth_cookieincludes/core.php:455
actionset_auth_cookieincludes/core.php:480
actionlogin_headincludes/user_interface.php:212
actionwp_footerincludes/user_interface.php:289
actionadmin_footerincludes/user_interface.php:290
filterplugin_action_linksoa-single-sign-on.php:53
actioninitoa-single-sign-on.php:69
Maintenance & Trust

Single Sign-On – Professional SSO solution for WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested5.9.13
Last updatedFeb 11, 2022
PHP min version
Downloads22K

Community Trust

Rating100/100
Number of ratings1
Active installs30
Developer Profile

Single Sign-On – Professional SSO solution for WordPress Developer Profile

Claude

3 plugins · 5K total installs

78
trust score
Avg Security Score
86/100
Avg Patch Time
89 days
View full developer profile
Detection Fingerprints

How We Detect Single Sign-On – Professional SSO solution for WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/single-sign-on-sso/assets/css/admin.css/wp-content/plugins/single-sign-on-sso/assets/css/style.css/wp-content/plugins/single-sign-on-sso/assets/js/admin.js/wp-content/plugins/single-sign-on-sso/assets/js/sso.js
Script Paths
/wp-content/plugins/single-sign-on-sso/assets/js/sso.js/wp-content/plugins/single-sign-on-sso/assets/js/admin.js
Version Parameters
single-sign-on-sso/assets/css/admin.css?ver=single-sign-on-sso/assets/css/style.css?ver=single-sign-on-sso/assets/js/admin.js?ver=single-sign-on-sso/assets/js/sso.js?ver=

HTML / DOM Fingerprints

CSS Classes
oa-sso-login-buttonoa-sso-login-buttons-container
HTML Comments
<!-- OA SSO START --><!-- OA SSO END --><!-- OneAll Single Sign On -->
Data Attributes
data-oa-sso-login-urldata-oa-sso-login-textdata-oa-sso-login-providersdata-oa-sso-login-layout
JS Globals
oa_sso_admin_ajax_urloa_sso_admin_ajax_nonceoa_sso_params
Shortcode Output
[oa_social_login]
FAQ

Frequently Asked Questions about Single Sign-On – Professional SSO solution for WordPress