TWST Login Block Security & Risk Analysis

wordpress.org/plugins/twst-login-block

Easily insert a log in block into your post.

1K active installs v1.0.1 PHP 5.6+ WP 5.5+ Updated Aug 25, 2020
blockformlog-inlogin
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is TWST Login Block Safe to Use in 2026?

Generally Safe

Score 85/100

TWST Login Block has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The static analysis of the 'twst-login-block' plugin v1.0.1 reveals a generally strong security posture, characterized by the absence of immediately identifiable vulnerabilities within the provided metrics. The plugin demonstrates good practices by not utilizing dangerous functions, all SQL queries are prepared, and output is properly escaped. Furthermore, there are no file operations, external HTTP requests, or bundled libraries, which minimizes potential attack vectors. The lack of any recorded vulnerabilities in its history also suggests a consistent focus on security by the developers or a very low exposure rate.

However, the analysis does highlight some areas that, while not explicitly flagged as vulnerabilities in this version, warrant caution. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events, while indicating a minimal attack surface, also means there are no opportunity to assess capability checks or nonce checks in these common areas of interaction. This doesn't necessarily mean they are missing, but rather not present in this specific code scan's scope. If the plugin were to introduce these elements in future versions without proper security controls, it could become vulnerable.

In conclusion, 'twst-login-block' v1.0.1 appears to be a secure plugin based on the static analysis provided, with no identified vulnerabilities and adherence to several key security best practices. The plugin's vulnerability history is clean, further bolstering this assessment. The main consideration is the very limited attack surface observed; while this is positive now, it means future additions of interactive elements will require careful security implementation to maintain this strong record.

Vulnerabilities
None known

TWST Login Block Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

TWST Login Block Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

TWST Login Block Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actioninitlogin-block.php:41
Maintenance & Trust

TWST Login Block Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedAug 25, 2020
PHP min version5.6
Downloads17K

Community Trust

Rating0/100
Number of ratings0
Active installs1K
Developer Profile

TWST Login Block Developer Profile

twst

1 plugin · 1K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect TWST Login Block

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/twst-login-block/build/index.js/wp-content/plugins/twst-login-block/build/index.css
Script Paths
/wp-content/plugins/twst-login-block/build/index.js
Version Parameters
twst-login-block/build/index.js?ver=twst-login-block/build/index.css?ver=

HTML / DOM Fingerprints

CSS Classes
twst-loginlogin-blockwp-block-button__link
Shortcode Output
<div class="twst-login login-block"><style>.twst-login form label { display: block; }</style><input type="submit" [^>]+ class=" wp-block-button__link
FAQ

Frequently Asked Questions about TWST Login Block