
SSO vBulletin Security & Risk Analysis
wordpress.org/plugins/sso-vbulletinImportant!!!
Is SSO vBulletin Safe to Use in 2026?
Generally Safe
Score 100/100SSO vBulletin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The sso-vbulletin plugin version 1.2.0 exhibits a mixed security posture. While it demonstrates good practices such as using prepared statements for all SQL queries and having no recorded historical vulnerabilities, significant concerns arise from its attack surface and taint analysis. The presence of two AJAX handlers without authentication checks presents a clear risk, as these entry points could be exploited by unauthenticated users. Furthermore, the taint analysis reveals a concerning number of flows with unsanitized paths, specifically two flows identified as high severity. This indicates potential for sensitive data to be manipulated or exposed if these paths are not properly handled. The plugin's static analysis shows a notable percentage of improperly escaped output, which could lead to cross-site scripting (XSS) vulnerabilities. In conclusion, the plugin has strengths in its SQL handling and vulnerability history, but the unprotected AJAX endpoints and high-severity taint flows demand immediate attention to mitigate potential security risks.
Key Concerns
- Unprotected AJAX handlers
- High severity taint flows
- Unsanitized paths in taint flows
- Improperly escaped output
SSO vBulletin Security Vulnerabilities
SSO vBulletin Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
SSO vBulletin Attack Surface
AJAX Handlers 2
WordPress Hooks 42
Maintenance & Trust
SSO vBulletin Maintenance & Trust
Maintenance Signals
Community Trust
SSO vBulletin Alternatives
WP vBulletin SSO
wp-vbulletin-sso
Looking for SSO tool for your WordPress and vBulletin sites?
SAML Single Sign On – SSO Login
miniorange-saml-20-single-sign-on
SAML SSO (Single Sign On) for WordPress Login with Okta, Entra ID, Azure AD/B2C, G-Suite, Shibboleth, OneLogin, Keycloak, Salesforce [24/7 Support]
OAuth Single Sign On – SSO (OAuth Client)
miniorange-login-with-eve-online-google-facebook
WordPress SSO (Single Sign On) with Azure, Azure B2C, Cognito, Okta, Classlink, Discord, Clever, Keycloak, OAuth & OpenID Providers [24/7 SUPPORT].
SAML IDP (Identity Provider) – Login with Website Users
miniorange-wp-as-saml-idp
Single sign on (SSO) login with WordPress Users into any Service Provider like Tableau, Thinkific, Zoom, Moodle LMS, Canvas LMS, Absorb LMS, TalentLMS
Tim's Nextcloud SSO OAuth2
tims-nextcloud-sso-oauth2
Enables you to login to your WordPress site with your Nextcloud account with OAuth2
SSO vBulletin Developer Profile
5 plugins · 100 total installs
How We Detect SSO vBulletin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sso-vbulletin/includes/assets/css/style.csssso-vbulletin/includes/assets/css/style.css?ver=HTML / DOM Fingerprints
WVSSO_REDIRECT_URL_PARAMWVSSO_REDIRECT_LINK_TEXTWVSSO_ERROR_25_CHARS_TEXTWVSSO_ERROR_ILLEGAL_CHARS_TEXTWVSSO_ERROR_PASS_EQ_USERNAME_TEXTWVSSO_USERNAME_VALID_MESSAGE+9 more