TokenLink SSO Login for Zendesk Security & Risk Analysis

wordpress.org/plugins/tokenlink-sso-login-for-zendesk

Provides secure JWT-based single sign-on (SSO) between WordPress and Zendesk. No third-party plugins, no tracking, no bloat. Totally free.

0 active installs v1.0.9 PHP 7.4+ WP 5.5+ Updated Jan 26, 2026
jwtloginsingle-sign-onssozendesk
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is TokenLink SSO Login for Zendesk Safe to Use in 2026?

Generally Safe

Score 100/100

TokenLink SSO Login for Zendesk has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The tokenlink-sso-login-for-zendesk plugin version 1.0.9 exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, direct SQL queries, file operations, and external HTTP requests, coupled with 100% proper output escaping, indicates good development practices. The plugin also has no recorded vulnerabilities, which is a positive indicator.

However, a significant concern arises from the complete lack of capability checks and nonce checks across all identified entry points. While the static analysis did not reveal any directly exploitable vulnerabilities in this specific version, this absence of standard WordPress security measures creates a latent risk. If any of the entry points were to introduce vulnerabilities in future versions, they would be far more accessible and exploitable due to the missing authorization and integrity checks. The single shortcode, while not inherently dangerous, is an entry point that lacks any explicit security validation, which could be a future vector if not handled carefully in subsequent updates.

In conclusion, the plugin is currently secure due to its clean code and lack of historical vulnerabilities. However, the reliance on the absence of vulnerabilities rather than robust security controls like capability and nonce checks presents a notable weakness. This means the plugin is more susceptible to future attacks if new vulnerabilities are introduced. For a truly secure plugin, these fundamental checks should be implemented.

Key Concerns

  • No capability checks implemented
  • No nonce checks implemented
  • Shortcode without security checks
Vulnerabilities
None known

TokenLink SSO Login for Zendesk Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

TokenLink SSO Login for Zendesk Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
12 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped12 total outputs
Attack Surface

TokenLink SSO Login for Zendesk Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[tokenlink_zendesk_login] tokenlink-sso-login-for-zendesk.php:713
WordPress Hooks 2
actionadmin_menutokenlink-sso-login-for-zendesk.php:31
actionadmin_inittokenlink-sso-login-for-zendesk.php:614
Maintenance & Trust

TokenLink SSO Login for Zendesk Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 26, 2026
PHP min version7.4
Downloads204

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

TokenLink SSO Login for Zendesk Developer Profile

Jerry Benton

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect TokenLink SSO Login for Zendesk

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/tokenlink-sso-login-for-zendesk/css/about-page.css/wp-content/plugins/tokenlink-sso-login-for-zendesk/css/tokenlink-settings.css/wp-content/plugins/tokenlink-sso-login-for-zendesk/js/settings-page.js
Script Paths
/wp-content/plugins/tokenlink-sso-login-for-zendesk/js/settings-page.js
Version Parameters
tokenlink-sso-login-for-zendesk/css/about-page.css?ver=tokenlink-sso-login-for-zendesk/css/tokenlink-settings.css?ver=tokenlink-sso-login-for-zendesk/js/settings-page.js?ver=

HTML / DOM Fingerprints

CSS Classes
tokenlink-outer-tabstokenlink-outer-tab-linktokenlink-outer-tab-contenttokenlink-about-wraptokenlink-about-maintokenlink-about-sidebartokenlink-herotokenlink-version-badge+8 more
HTML Comments
<!-- Settings page under Settings → Zendesk SSO --><!-- Adds a Settings link to the plugin action links. --><!-- Renders the TokenLink Zendesk SSO settings page in the WordPress admin. --><!-- Renders the General settings tab content. -->+1 more
Data Attributes
data-tab
JS Globals
tokenlink_zendesk_sso_settings
FAQ

Frequently Asked Questions about TokenLink SSO Login for Zendesk