Twelve Legs Marketing SSO Security & Risk Analysis

wordpress.org/plugins/twelve-legs-marketing-sso

Single sign-on plugin for WordPress that accepts RS256 JWTs from the TWL SSO application for secure authentication.

0 active installs v1.0.2 PHP 8.0+ WP 5.8+ Updated Oct 22, 2025
authenticationjwtloginsingle-sign-onsso
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Twelve Legs Marketing SSO Safe to Use in 2026?

Generally Safe

Score 100/100

Twelve Legs Marketing SSO has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6mo ago
Risk Assessment

The twelve-legs-marketing-sso plugin v1.0.2 exhibits a strong security posture based on the provided static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events without proper authentication and permission checks, coupled with zero recorded vulnerabilities, is highly commendable. The code signals also indicate good practices with 100% of SQL queries using prepared statements and all output being properly escaped. There are no indications of dangerous functions, file operations, or critical taint flows. However, the presence of a single external HTTP request without further context raises a slight concern, as it could potentially be a vector for certain types of attacks if not handled securely within the plugin's logic. Additionally, the complete lack of nonce checks and capability checks across all potential entry points (though there are none explicitly identified) signifies a gap in defense-in-depth, which could become a risk if new entry points are added in future versions without these checks. The absence of any vulnerability history is a positive sign, suggesting a history of secure development or minimal exposure to attackers. Overall, this plugin appears to be developed with security in mind, but vigilance regarding external dependencies and the implementation of standard WordPress security features for any future expansion is advised.

Key Concerns

  • External HTTP request without auth/sanitization context
  • 0 Nonce checks found
  • 0 Capability checks found
Vulnerabilities
None known

Twelve Legs Marketing SSO Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Twelve Legs Marketing SSO Release Timeline

v1.0.2Current
v1.0.1
v1.0
Code Analysis
Analyzed Mar 17, 2026

Twelve Legs Marketing SSO Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
6 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

100% escaped6 total outputs
Attack Surface

Twelve Legs Marketing SSO Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
filterallowed_redirect_hoststwelve-legs-marketing-sso.php:114
actionlogin_inittwelve-legs-marketing-sso.php:587
Maintenance & Trust

Twelve Legs Marketing SSO Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 22, 2025
PHP min version8.0
Downloads202

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Twelve Legs Marketing SSO Developer Profile

websitetwelvelegsmarketing

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Twelve Legs Marketing SSO

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/twelve-legs-marketing-sso/
Version Parameters
twelve-legs-marketing-sso/style.css?ver=

HTML / DOM Fingerprints

REST Endpoints
/?action=oidc.jwks
FAQ

Frequently Asked Questions about Twelve Legs Marketing SSO