
TomS Social Login Security & Risk Analysis
wordpress.org/plugins/toms-social-loginSupport users use their Facebook,Google,Paypal,Github,Wechat,QQ,Weibo,Dingtalk accounts to login your wordpress site. Compatibility Woocommerce, Ultim …
Is TomS Social Login Safe to Use in 2026?
Generally Safe
Score 85/100TomS Social Login has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The toms-social-login plugin version 1.1.0 exhibits a generally strong security posture based on the provided static analysis. A significant portion of its SQL queries are prepared, and a high percentage of outputs are properly escaped, indicating good development practices for preventing common vulnerabilities like SQL injection and XSS. The plugin also demonstrates good security hygiene by including a substantial number of nonce and capability checks, and importantly, has no recorded vulnerabilities or CVEs, suggesting a history of secure development and maintenance.
However, there are some areas that warrant attention. The presence of four taint flows with unsanitized paths, while not classified as critical or high severity, represents a potential risk. While the analysis didn't find direct evidence of exploitability, unsanitized paths can be a precursor to vulnerabilities if user input is not handled rigorously throughout the code. Additionally, the plugin makes several external HTTP requests, which can introduce risks if not carefully managed, though no specific issues are highlighted in this regard from the provided data.
Overall, the plugin appears to be developed with security in mind, evidenced by its lack of historical vulnerabilities and good practices in handling SQL and output. The primary concern lies in the identified taint flows with unsanitized paths, which, though unexploited in this version, should be investigated further to ensure robust input validation and sanitization. The absence of any critical or high severity issues and the lack of known CVEs are positive indicators, but the identified taint flows suggest a need for vigilance.
Key Concerns
- Taint flows with unsanitized paths
TomS Social Login Security Vulnerabilities
TomS Social Login Release Timeline
TomS Social Login Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
TomS Social Login Attack Surface
AJAX Handlers 2
Shortcodes 2
WordPress Hooks 33
Maintenance & Trust
TomS Social Login Maintenance & Trust
Maintenance Signals
Community Trust
TomS Social Login Alternatives
Nextend Social Login and Register
nextend-facebook-connect
One click registration & login plugin for Facebook, Google, X (formerly Twitter) and more. Quick setup and easy configuration.
miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn)
miniorange-login-openid
Social Login with Discord, Facebook, Google, Twitter, LinkedIn and 40+ apps. Social login with social share and comments. Free, fast & easy! WooCo …
UsersWP – Social Login
userswp-social-login
Social Login addon for UsersWP.
One Tap Google Sign in
one-tap-google-sign-in
Allows users to add Google One Tap Sign-in Or Sign-up to wordpress website.
Happy Social Login
happy-social-login
Enables user authentication through various social media accounts. Login through Google, Facebook, LinkedIn, GitHub and more.
TomS Social Login Developer Profile
7 plugins · 1K total installs
How We Detect TomS Social Login
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/toms-social-login/admin/assets/css/toms-social-login-global.css/wp-content/plugins/toms-social-login/library/assets/css/iconfont.css/wp-content/plugins/toms-social-login/admin/assets/css/toms-social-login.css/wp-content/plugins/toms-social-login/admin/assets/js/toms-social-login.js/wp-content/plugins/toms-social-login/admin/assets/css/toms-social-login-global.css/wp-content/plugins/toms-social-login/library/assets/css/iconfont.css/wp-content/plugins/toms-social-login/admin/assets/css/toms-social-login.css/wp-content/plugins/toms-social-login/admin/assets/js/toms-social-login.jsHTML / DOM Fingerprints
toms-menu-itemtoms-menu-text<!-- IMPORTANT: Dont remove this file --><!-- TomS Social Login admin-->data-nonce-unbinddata-nonce-ordertomsSocialLogin