
Unloct Security & Risk Analysis
wordpress.org/plugins/unloctUnloct is a microsubscription platform. Subscribers pay one monthly fee for unlimited access to an entire network of creators.
Is Unloct Safe to Use in 2026?
Generally Safe
Score 85/100Unloct has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'unloct' plugin v3.1.0 demonstrates a generally good security posture based on the static analysis. It features a minimal attack surface with no apparent unprotected entry points. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is a positive indicator. Furthermore, the presence of capability checks suggests an awareness of WordPress security best practices.
However, a key concern arises from the taint analysis, which identified one flow with an unsanitized path. While no critical or high severity issues were detected, this single unsanitized path represents a potential avenue for malicious input to be processed insecurely, which could lead to vulnerabilities depending on the context.
The plugin's history of zero known CVEs is a strong positive, indicating a history of secure development or a lack of discovered vulnerabilities. This, combined with the strengths observed in the code analysis, suggests a relatively safe plugin. Nevertheless, the identified unsanitized path warrants attention as it is the only noted deviation from an otherwise robust security profile.
Key Concerns
- Taint flow with unsanitized path
- Output escaping only 63% properly escaped
- No nonce checks on entry points
Unloct Security Vulnerabilities
Unloct Code Analysis
Output Escaping
Data Flow Analysis
Unloct Attack Surface
Shortcodes 2
WordPress Hooks 12
Maintenance & Trust
Unloct Maintenance & Trust
Maintenance Signals
Community Trust
Unloct Alternatives
No alternatives data available yet.
Unloct Developer Profile
1 plugin · 0 total installs
How We Detect Unloct
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/unloct/unloct-login.css/wp-content/plugins/unloct/unloct-login.js/wp-content/plugins/unloct/unloct-login.jsunloct-login.css?ver=unloct-login.js?ver=HTML / DOM Fingerprints
galogingalogin-ordata-unloct-loginunloctLogin[unloct_login][visitor_login]