WP-Login and WP-Admin Whitelist Security & Risk Analysis

wordpress.org/plugins/swiftninjapro-wp-login-whitelist-ip

A Plugin That only allows whitelisted IP's, or optionally whitelisted browsers, to access wp-login, or optionally wp-admin.

10 active installs v1.11.1 PHP 5.2.4+ WP 3.0.1+ Updated Nov 4, 2020
loginsecuritywhitelistwp-loginwp-admin
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP-Login and WP-Admin Whitelist Safe to Use in 2026?

Generally Safe

Score 85/100

WP-Login and WP-Admin Whitelist has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "swiftninjapro-wp-login-whitelist-ip" plugin version 1.11.1 demonstrates a generally good security posture, with no known CVEs and a complete lack of critical or high severity issues in its vulnerability history. The static analysis reveals good practices such as using prepared statements for all SQL queries and performing capability checks for critical operations. However, there are some areas for concern. The plugin has a low number of entry points, with none found to be unprotected, which is positive. Despite this, the taint analysis flagged one flow with unsanitized paths, which, while not rated as critical or high severity, represents a potential avenue for unexpected behavior or information disclosure if exploited. Furthermore, the output escaping is only 63% properly escaped, indicating a moderate risk of Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not handled carefully in the remaining outputs. The absence of nonce checks on the identified entry point is also a weakness, potentially allowing for Cross-Site Request Forgery (CSRF) attacks if the shortcode's functionality can be triggered maliciously.

Key Concerns

  • Taint flow with unsanitized path
  • Moderate unescaped output risk
  • Missing nonce check on entry point
Vulnerabilities
None known

WP-Login and WP-Admin Whitelist Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP-Login and WP-Admin Whitelist Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
18
30 escaped
Nonce Checks
0
Capability Checks
5
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

63% escaped48 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

3 flows1 with unsanitized paths
SwiftNinjaPro_settings_GetOption (templates\admin.php:139)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

WP-Login and WP-Admin Whitelist Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[wp-login-recovery-page] swiftninjapro-wp-login-whitelist-ip.php:115
WordPress Hooks 3
actionafter_setup_thememain.php:39
actionwp_enqueue_scriptsswiftninjapro-wp-login-whitelist-ip.php:108
actionadmin_menuswiftninjapro-wp-login-whitelist-ip.php:109
Maintenance & Trust

WP-Login and WP-Admin Whitelist Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedNov 4, 2020
PHP min version5.2.4
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

WP-Login and WP-Admin Whitelist Developer Profile

SwiftNinjaPro

7 plugins · 710 total installs

83
trust score
Avg Security Score
84/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP-Login and WP-Admin Whitelist

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/swiftninjapro-wp-login-whitelist-ip/assets/style.css/wp-content/plugins/swiftninjapro-wp-login-whitelist-ip/assets/script.js
Script Paths
/wp-content/plugins/swiftninjapro-wp-login-whitelist-ip/assets/script.js
Version Parameters
swiftninjapro-wp-login-whitelist-ip/assets/style.css?ver=swiftninjapro-wp-login-whitelist-ip/assets/script.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- BEGIN SwiftNinjaPro Whitelist Login IP --><!-- END SwiftNinjaPro Whitelist Login IP -->
JS Globals
window.SwiftNinjaProWhitelistLoginIPSwiftNinjaProWhitelistLoginIP
Shortcode Output
[wp-login-recovery-page]
FAQ

Frequently Asked Questions about WP-Login and WP-Admin Whitelist