
Twelve Legs Marketing SSO Security & Risk Analysis
wordpress.org/plugins/twelve-legs-marketing-ssoSingle sign-on plugin for WordPress that accepts RS256 JWTs from the TWL SSO application for secure authentication.
Is Twelve Legs Marketing SSO Safe to Use in 2026?
Generally Safe
Score 100/100Twelve Legs Marketing SSO has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The twelve-legs-marketing-sso plugin v1.0.2 exhibits a strong security posture based on the provided static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events without proper authentication and permission checks, coupled with zero recorded vulnerabilities, is highly commendable. The code signals also indicate good practices with 100% of SQL queries using prepared statements and all output being properly escaped. There are no indications of dangerous functions, file operations, or critical taint flows. However, the presence of a single external HTTP request without further context raises a slight concern, as it could potentially be a vector for certain types of attacks if not handled securely within the plugin's logic. Additionally, the complete lack of nonce checks and capability checks across all potential entry points (though there are none explicitly identified) signifies a gap in defense-in-depth, which could become a risk if new entry points are added in future versions without these checks. The absence of any vulnerability history is a positive sign, suggesting a history of secure development or minimal exposure to attackers. Overall, this plugin appears to be developed with security in mind, but vigilance regarding external dependencies and the implementation of standard WordPress security features for any future expansion is advised.
Key Concerns
- External HTTP request without auth/sanitization context
- 0 Nonce checks found
- 0 Capability checks found
Twelve Legs Marketing SSO Security Vulnerabilities
Twelve Legs Marketing SSO Release Timeline
Twelve Legs Marketing SSO Code Analysis
Output Escaping
Twelve Legs Marketing SSO Attack Surface
WordPress Hooks 2
Maintenance & Trust
Twelve Legs Marketing SSO Maintenance & Trust
Maintenance Signals
Community Trust
Twelve Legs Marketing SSO Alternatives
AH JWT Auth
ah-jwt-auth
This plugin allows sign in to WordPress using a JSON Web Token (JWT) contained in a HTTP Header.
JWT Authenticator
jwt-authenticator
This plugin integrates JWT authentication and automates user creation.
Frontegg SAML SSO
frontegg-saml-sso
Replace the WordPress login and logout flows with secure SAML-based authentication via Frontegg. Easily configure your SSO app from the admin panel.
TokenLink SSO Login for Zendesk
tokenlink-sso-login-for-zendesk
Provides secure JWT-based single sign-on (SSO) between WordPress and Zendesk. No third-party plugins, no tracking, no bloat. Totally free.
wp-sso-client
wp-sso-client
Documentacion completa https://gitlab.com/wp-sso/wp-sso-client
Twelve Legs Marketing SSO Developer Profile
1 plugin · 0 total installs
How We Detect Twelve Legs Marketing SSO
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/twelve-legs-marketing-sso/twelve-legs-marketing-sso/style.css?ver=HTML / DOM Fingerprints
/?action=oidc.jwks