StayLogged Security & Risk Analysis

wordpress.org/plugins/staylogged

StayLogged is a WordPress plugin that automatically logs out users after any period of inactivity that you want, so you can keep users logged in for a …

0 active installs v1.0 PHP + WP 4.0+ Updated Jun 14, 2023
inactivity-logoutsecuritystay-logged
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is StayLogged Safe to Use in 2026?

Generally Safe

Score 85/100

StayLogged has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The "staylogged" v1.0 plugin exhibits a seemingly strong security posture based on the provided static analysis. There are no identified dangerous functions, SQL queries are all prepared, and all output is properly escaped. Crucially, the plugin has no recorded vulnerabilities in its history, indicating a history of secure development or thorough vetting. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the attack surface, which is a positive sign.

However, the static analysis also reveals significant gaps. The complete lack of nonce checks and capability checks across all potential entry points is a major concern. While the attack surface is currently reported as zero, any future addition of features like AJAX handlers or REST API routes without these fundamental security measures would immediately introduce vulnerabilities. The zero taint flows analyzed is also noted, though this could simply mean the analysis tools found no such flows, or that the plugin's scope is very limited.

In conclusion, while "staylogged" v1.0 benefits from a clean vulnerability history and diligent output escaping, its current lack of authorization checks on any potential entry points represents a significant risk. This is a critical oversight that could lead to severe vulnerabilities if the plugin were to be expanded or if the analysis did not capture all potential interaction points. The current score reflects this strong history of security but also highlights a concerning lack of basic security controls.

Key Concerns

  • Missing nonce checks for all entry points
  • Missing capability checks for all entry points
Vulnerabilities
None known

StayLogged Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

StayLogged Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

StayLogged Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped2 total outputs
Attack Surface

StayLogged Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionadmin_menustaylogged.php:35
actioninitstaylogged.php:50
Maintenance & Trust

StayLogged Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedJun 14, 2023
PHP min version
Downloads653

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

StayLogged Developer Profile

وندا نوژن

2 plugins · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect StayLogged

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
wrap
FAQ

Frequently Asked Questions about StayLogged