
Surbma | Secure Login Security & Risk Analysis
wordpress.org/plugins/surbma-secure-loginThe most simple two factor authentication plugin for WordPress.
Is Surbma | Secure Login Safe to Use in 2026?
Generally Safe
Score 85/100Surbma | Secure Login has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "surbma-secure-login" v3.1 plugin exhibits a generally positive security posture based on the static analysis. It demonstrates a lack of known vulnerabilities (CVEs) and boasts a clean code signal with no dangerous functions, file operations, or external HTTP requests. The plugin also correctly utilizes prepared statements for all SQL queries. However, there are significant areas of concern regarding output escaping and a complete absence of nonces and capability checks. While the attack surface appears minimal with no exposed AJAX handlers or REST API routes, the lack of fundamental security checks like nonces and capability checks is concerning, especially if the plugin's functionality expands in future versions. The two identified flows with unsanitized paths, even without a critical or high severity rating, suggest potential for unexpected behavior or data manipulation if triggered. The vulnerability history being clean is a strong positive, but it's crucial to address the identified code-level weaknesses proactively to maintain this favorable track record. Overall, while the plugin is not demonstrably vulnerable in this version due to the limited attack surface and lack of known exploits, the identified code quality issues and missing security mechanisms represent potential weaknesses that could be exploited if the plugin evolves or interacts with other components in unforeseen ways.
Key Concerns
- Unescaped output detected
- Flows with unsanitized paths detected
- Missing nonce checks
- Missing capability checks
Surbma | Secure Login Security Vulnerabilities
Surbma | Secure Login Code Analysis
Output Escaping
Data Flow Analysis
Surbma | Secure Login Attack Surface
WordPress Hooks 1
Maintenance & Trust
Surbma | Secure Login Maintenance & Trust
Maintenance Signals
Community Trust
Surbma | Secure Login Alternatives
All-In-One Security (AIOS) – Security and Firewall
all-in-one-wp-security-and-firewall
Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plugin designed especially for WordPress.
Wordfence Login Security
wordfence-login-security
Secure your website with Wordfence Login Security, providing two-factor authentication, login and registration CAPTCHA, and XML-RPC protection.
Titan Anti-spam & Security
anti-spam
Block spam comments, defend against login attempts, and strengthen site security with anti-spam, brute-force protection, and two-factor authentication …
IP & Country Blocker Lite
ip-blocker-lite
Advanced WordPress security plugin with IP/country blocking and two-factor authentication for comprehensive website protection.
Bearmor Security
bearmor-security
Lightweight, powerful WordPress security for small businesses. Malware scanning, login protection, 2FA, hardening - most features FREE.
Surbma | Secure Login Developer Profile
27 plugins · 30K total installs
How We Detect Surbma | Secure Login
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
wpmailauthform