
Token Access Security & Risk Analysis
wordpress.org/plugins/token-accessLimit access to the site to those with a cookie token. Visitors without the cookie see a customisable "coming soon" style of page.
Is Token Access Safe to Use in 2026?
Generally Safe
Score 100/100Token Access has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "token-access" plugin v1.8.2 demonstrates a generally good security posture with no recorded vulnerabilities and a clean static analysis report in several key areas. The absence of known CVEs and a lack of critical or high severity taint flows is highly positive. Furthermore, the plugin utilizes prepared statements for all SQL queries, indicating robust protection against SQL injection. However, the static analysis does reveal a couple of areas that warrant attention. The presence of file operations without explicit security checks could be a concern depending on the nature of these operations. Additionally, the report shows that 17% of output is not properly escaped, which could lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is involved in these outputs. The lack of capability checks and nonce checks on any potential entry points, while currently showing zero entry points, means that if new entry points are introduced in future updates, they might be unprotected. Overall, while the plugin has a strong foundation, these specific areas require further scrutiny to ensure complete security.
Key Concerns
- Unescaped output detected
- File operations detected without clear security context
- No capability checks on entry points
- No nonce checks on entry points
Token Access Security Vulnerabilities
Token Access Code Analysis
Output Escaping
Data Flow Analysis
Token Access Attack Surface
WordPress Hooks 4
Maintenance & Trust
Token Access Maintenance & Trust
Maintenance Signals
Community Trust
Token Access Alternatives
Intranet & Private Site – All-In-One Intranet
all-in-one-intranet
Private intranet in one click. Auto-logout for security, login redirect, and multisite privacy controls included.
Wbcom Designs – Private Community for BuddyPress
lock-my-bp
Create a private BuddyPress community by restricting access to non-members. Control who sees what with flexible privacy settings.
ExpressTechSoftwares Addon for MemberPress and Discord
expresstechsoftwares-memberpress-discord-add-on
This add-on enables connecting your MemberPress enabled website to your discord server. Now you can add/remove MemberPress members directly to your di …
Private Website – Login Required
private-website
This plugin requires users to be logged in to view the website. Activate the plugin to enforce login, and deactivate it to remove the restriction.
DiaryPress
diarypress
DiaryPress lets you keep a private diary.
Token Access Developer Profile
5 plugins · 270 total installs
How We Detect Token Access
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/token-access/assets/css/token-access.css/wp-content/plugins/token-access/assets/js/token-access.js/wp-content/plugins/token-access/assets/js/token-access.jstoken-access.css?ver=token-access.js?ver=HTML / DOM Fingerprints
token-access-placeholder-content<!-- Token Access Placeholder --><!-- End Token Access Placeholder -->data-token-access-token-keydata-token-access-expiry-hoursdata-token-access-remove-token-urldata-token-access-add-token-urltokenAccessSettings