
Swipe Security & Risk Analysis
wordpress.org/plugins/swipeThe Swipe plugin allows you too securely login into Wordpress giving you 2-factor authentication without the hassle of one-time codes.
Is Swipe Safe to Use in 2026?
Generally Safe
Score 85/100Swipe has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "swipe" v1.4 plugin presents a significant security risk due to a large number of unprotected AJAX handlers. With 14 AJAX handlers identified and 13 of them lacking proper authentication checks, there's a high likelihood of unauthorized actions being performed. This is further exacerbated by the taint analysis, which reveals 9 flows with unsanitized paths and rated as high severity, indicating potential for malicious input to be processed insecurely. While the plugin has no recorded vulnerability history, this absence does not negate the substantial security concerns identified in the code. The plugin also exhibits poor SQL query sanitization, with 100% of its SQL queries not using prepared statements, increasing the risk of SQL injection vulnerabilities. Despite the lack of external HTTP requests and file operations, the critical issues with AJAX handlers and taint analysis create a concerning security posture.
Key Concerns
- Unprotected AJAX handlers
- High severity unsanitized taint flows
- SQL queries without prepared statements
- Low output escaping coverage
- Low nonce check coverage
Swipe Security Vulnerabilities
Swipe Release Timeline
Swipe Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Swipe Attack Surface
AJAX Handlers 14
WordPress Hooks 7
Maintenance & Trust
Swipe Maintenance & Trust
Maintenance Signals
Community Trust
Swipe Alternatives
Two Factor Auth
two-factor-auth
Secure WordPress login with Two Factor Auth. Users will have to enter an One Time Password when they log in.
All-In-One Security (AIOS) – Security and Firewall
all-in-one-wp-security-and-firewall
Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plugin designed especially for WordPress.
Wordfence Login Security
wordfence-login-security
Secure your website with Wordfence Login Security, providing two-factor authentication, login and registration CAPTCHA, and XML-RPC protection.
Titan Anti-spam & Security
anti-spam
Block spam comments, defend against login attempts, and strengthen site security with anti-spam, brute-force protection, and two-factor authentication …
IP & Country Blocker Lite
ip-blocker-lite
Advanced WordPress security plugin with IP/country blocking and two-factor authentication for comprehensive website protection.
Swipe Developer Profile
1 plugin · 10 total installs
How We Detect Swipe
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/swipe/css/swipe.css/wp-content/plugins/swipe/js/swipe.js/wp-content/plugins/swipe/js/admin-script.js/wp-content/plugins/swipe/js/login-script.js/wp-content/plugins/swipe/js/swipe.js/wp-content/plugins/swipe/js/admin-script.js/wp-content/plugins/swipe/js/login-script.jsswipe/style.css?ver=swipe/script.js?ver=HTML / DOM Fingerprints
swipe_loginswipe_qr_loginswipe-logo-container<!-- Swipe Login Form --><!-- Swipe QR Code Container -->data-swipe-noncedata-swipe-ajax-urlswipe_ajax_object/wp-json/swipe/v1/check_login/wp-json/swipe/v1/logout<div class="swipe_login"><div class="swipe_qr_login">