
Temporary Login Without Password Security & Risk Analysis
wordpress.org/plugins/temporary-login-without-passwordCreate self-expiring, temporary admin accounts. Easily share direct login links (no need for username/password) with your developers or editors.
Is Temporary Login Without Password Safe to Use in 2026?
Generally Safe
Score 100/100Temporary Login Without Password has a strong security track record. Known vulnerabilities have been patched promptly.
The 'temporary-login-without-password' plugin version 1.9.7 exhibits a mixed security posture. While it demonstrates good practices such as using prepared statements for all SQL queries and a reasonably high percentage of output escaping, there are significant areas of concern. The presence of 3 AJAX handlers, with 2 lacking authentication checks, presents a substantial attack surface that could be exploited by unauthenticated users. Fortunately, the static analysis did not reveal any critical or high severity taint flows, suggesting that while entry points are exposed, the immediate risk of data compromise or code execution from these specific flows might be limited.
The plugin's vulnerability history, while not showing any currently unpatched issues, does indicate a past medium severity vulnerability related to 'Incorrect Authorization' in 2021. This historical pattern, combined with the current lack of authentication checks on AJAX handlers, suggests a potential recurring weakness in how the plugin handles user permissions and access control.
In conclusion, the plugin has strengths in its data handling (SQL, output escaping), but these are overshadowed by the significant security risk posed by unprotected AJAX endpoints. The historical vulnerability further reinforces the need for careful review of its authorization mechanisms. Immediate attention should be paid to securing the identified AJAX handlers to mitigate the risk of unauthorized actions.
Key Concerns
- Unprotected AJAX handlers
- Past medium severity vulnerability (Incorrect Authorization)
- Relatively high attack surface (3 entry points)
Temporary Login Without Password Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Temporary Login Without Password <= 1.7.0 - Subscriber+ Plugin Settings Update
Temporary Login Without Password Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Temporary Login Without Password Attack Surface
AJAX Handlers 3
WordPress Hooks 40
Maintenance & Trust
Temporary Login Without Password Maintenance & Trust
Maintenance Signals
Community Trust
Temporary Login Without Password Alternatives
Login Links – Passwordless Login, Temporary Access Links & Custom Login Form
login-links
Create secure self-expiring login links for temporary access and guest users, and enable passwordless login for registered ones.
SafeTemp Login – Temporary Access with Approval
safetemplogin-tawa
Create temporary users with any role. When a temporary user is an administrator, sensitive actions require approval from a real administrator.
Temporary Login
temporary-login
Create a secure, temporary URL for easy access to your WP admin.
Bifröst – Instant Passwordless Temporary Login Links
create-temporary-login
🔗️ Create passwordless temporary login links. Instantly ⚡️
Password Less Login
password-less-login
A powerful and easy-to-use WordPress plugin for passwordless and OTP-based login.
Temporary Login Without Password Developer Profile
9 plugins · 132K total installs
How We Detect Temporary Login Without Password
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/temporary-login-without-password/css/wp-temporary-login-without-password-admin.css/wp-content/plugins/temporary-login-without-password/js/wp-temporary-login-without-password-admin.js/wp-content/plugins/temporary-login-without-password/js/clipboard.min.js/wp-content/plugins/temporary-login-without-password/dist/main.css/wp-content/plugins/temporary-login-without-password/js/wp-temporary-login-without-password-admin.js/wp-content/plugins/temporary-login-without-password/js/clipboard.min.jstemporary-login-without-password/css/wp-temporary-login-without-password-admin.css?ver=temporary-login-without-password/js/wp-temporary-login-without-password-admin.js?ver=temporary-login-without-password/js/clipboard.min.js?ver=temporary-login-without-password/dist/main.css?ver=HTML / DOM Fingerprints
wtlwp-field-wrapwtlwp-form-groupwtlwp-inputwtlwp-btnwtlwp-btn-primarydata-tlwp-user-iddata-tlwp-roledata-tlwp-expirationdata-tlwp-copy-btndataWTLWP_PLUGIN_VERSION