SSO vBulletin Security & Risk Analysis

wordpress.org/plugins/sso-vbulletin

Important!!!

0 active installs v1.2.0 PHP + WP 4.4+ Updated Unknown
loginregistrationsingle-sign-onssouser-management
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is SSO vBulletin Safe to Use in 2026?

Generally Safe

Score 100/100

SSO vBulletin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The sso-vbulletin plugin version 1.2.0 exhibits a mixed security posture. While it demonstrates good practices such as using prepared statements for all SQL queries and having no recorded historical vulnerabilities, significant concerns arise from its attack surface and taint analysis. The presence of two AJAX handlers without authentication checks presents a clear risk, as these entry points could be exploited by unauthenticated users. Furthermore, the taint analysis reveals a concerning number of flows with unsanitized paths, specifically two flows identified as high severity. This indicates potential for sensitive data to be manipulated or exposed if these paths are not properly handled. The plugin's static analysis shows a notable percentage of improperly escaped output, which could lead to cross-site scripting (XSS) vulnerabilities. In conclusion, the plugin has strengths in its SQL handling and vulnerability history, but the unprotected AJAX endpoints and high-severity taint flows demand immediate attention to mitigate potential security risks.

Key Concerns

  • Unprotected AJAX handlers
  • High severity taint flows
  • Unsanitized paths in taint flows
  • Improperly escaped output
Vulnerabilities
None known

SSO vBulletin Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

SSO vBulletin Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
13
9 escaped
Nonce Checks
1
Capability Checks
2
File Operations
4
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

41% escaped22 total outputs
Data Flows
4 unsanitized

Data Flow Analysis

5 flows4 with unsanitized paths
manageLogFiles (classes\AdminSettingsPage.php:65)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

SSO vBulletin Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_wvsso_check_loginsso-vbulletin.php:129
noprivwp_ajax_wvsso_check_loginsso-vbulletin.php:130
WordPress Hooks 42
actionadmin_menuclasses\AdminSettingsPage.php:24
actioninitclasses\AdminSettingsPage.php:25
actionwp_authenticatesso-vbulletin.php:70
actionpassword_resetsso-vbulletin.php:71
actionwppb_password_resetsso-vbulletin.php:72
actionwp_logoutsso-vbulletin.php:73
actionwp_loginsso-vbulletin.php:74
actionwpmu_new_usersso-vbulletin.php:76
actionuser_registersso-vbulletin.php:77
actionwppb_signup_usersso-vbulletin.php:80
actionprofile_updatesso-vbulletin.php:84
actionwpmu_delete_usersso-vbulletin.php:86
actiondelete_usersso-vbulletin.php:87
filterwppb_output_fields_filtersso-vbulletin.php:90
filterwppb_signup_user_notification_email_contentsso-vbulletin.php:91
filterwppb_success_email_confirmationsso-vbulletin.php:92
filtermustache_variable_ec_activation_linksso-vbulletin.php:93
filterwppb_check_form_field_default-usernamesso-vbulletin.php:97
filterregistration_errorssso-vbulletin.php:98
actionadmin_footersso-vbulletin.php:99
filterwppb_check_form_field_default-passwordsso-vbulletin.php:101
actionwppb_before_register_fieldssso-vbulletin.php:103
actionwppb_before_edit_profile_fieldssso-vbulletin.php:104
actionedit_user_profile_updatesso-vbulletin.php:106
actionwppb_after_sending_emailsso-vbulletin.php:108
actionwppb_register_successsso-vbulletin.php:109
actionlogin_form_registersso-vbulletin.php:115
actionlogin_form_loginsso-vbulletin.php:118
actionlost_passwordsso-vbulletin.php:121
filterwppb_login_form_argssso-vbulletin.php:126
filterwppb_after_login_redirect_urlsso-vbulletin.php:132
actionlogin_initsso-vbulletin.php:136
actionwp_print_stylessso-vbulletin.php:142
filterlogin_form_bottomsso-vbulletin.php:147
filterwppb_register_activate_user_error_message1sso-vbulletin.php:159
filterwppb_register_activate_user_error_message2sso-vbulletin.php:160
filterwppb_register_activate_user_error_message4sso-vbulletin.php:161
filterwppb_register_activate_user_error_message5sso-vbulletin.php:162
filterwppb_register_failed_user_activationsso-vbulletin.php:163
filteruser_profile_update_errorssso-vbulletin.php:166
actionwppb_after_sending_emailsso-vbulletin.php:411
actioninitsso-vbulletin.php:539
Maintenance & Trust

SSO vBulletin Maintenance & Trust

Maintenance Signals

WordPress version tested5.6.17
Last updatedUnknown
PHP min version
Downloads4K

Community Trust

Rating100/100
Number of ratings2
Active installs0
Developer Profile

SSO vBulletin Developer Profile

extremeidea

5 plugins · 100 total installs

81
trust score
Avg Security Score
82/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect SSO vBulletin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sso-vbulletin/includes/assets/css/style.css
Version Parameters
sso-vbulletin/includes/assets/css/style.css?ver=

HTML / DOM Fingerprints

JS Globals
WVSSO_REDIRECT_URL_PARAMWVSSO_REDIRECT_LINK_TEXTWVSSO_ERROR_25_CHARS_TEXTWVSSO_ERROR_ILLEGAL_CHARS_TEXTWVSSO_ERROR_PASS_EQ_USERNAME_TEXTWVSSO_USERNAME_VALID_MESSAGE+9 more
FAQ

Frequently Asked Questions about SSO vBulletin