Unloct Security & Risk Analysis

wordpress.org/plugins/unloct

Unloct is a microsubscription platform. Subscribers pay one monthly fee for unlimited access to an entire network of creators.

0 active installs v3.1.0 PHP 7.2+ WP 5.4.2+ Updated Dec 24, 2020
premium-content-subscription-platform-sidehustle-sidegig
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Unloct Safe to Use in 2026?

Generally Safe

Score 85/100

Unloct has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The 'unloct' plugin v3.1.0 demonstrates a generally good security posture based on the static analysis. It features a minimal attack surface with no apparent unprotected entry points. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is a positive indicator. Furthermore, the presence of capability checks suggests an awareness of WordPress security best practices.

However, a key concern arises from the taint analysis, which identified one flow with an unsanitized path. While no critical or high severity issues were detected, this single unsanitized path represents a potential avenue for malicious input to be processed insecurely, which could lead to vulnerabilities depending on the context.

The plugin's history of zero known CVEs is a strong positive, indicating a history of secure development or a lack of discovered vulnerabilities. This, combined with the strengths observed in the code analysis, suggests a relatively safe plugin. Nevertheless, the identified unsanitized path warrants attention as it is the only noted deviation from an otherwise robust security profile.

Key Concerns

  • Taint flow with unsanitized path
  • Output escaping only 63% properly escaped
  • No nonce checks on entry points
Vulnerabilities
None known

Unloct Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Unloct Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
22
38 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

63% escaped60 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
unloct_options_do_network_errors (core\core_unloct_login.php:404)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Unloct Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[unloct] unloct_short_code.php:33
[visitor] visitor_short_code.php:33
WordPress Hooks 12
actionadmin_noticescore\core_unloct_login.php:283
actionnetwork_admin_noticescore\core_unloct_login.php:285
actionlogin_enqueue_scriptscore\core_unloct_login.php:577
actionlogin_formcore\core_unloct_login.php:578
filterauthenticatecore\core_unloct_login.php:579
filterlogin_redirectcore\core_unloct_login.php:581
actioninitcore\core_unloct_login.php:582
actionadmin_initcore\core_unloct_login.php:584
filterunloct_get_clientidcore\core_unloct_login.php:588
filterplugin_action_linkscore\core_unloct_login.php:590
actionwidgets_initunloct_login.php:119
actionwidgets_initunloct_widget.php:20
Maintenance & Trust

Unloct Maintenance & Trust

Maintenance Signals

WordPress version tested5.6.0
Last updatedDec 24, 2020
PHP min version7.2
Downloads950

Community Trust

Rating0/100
Number of ratings0
Active installs0
Alternatives

Unloct Alternatives

No alternatives data available yet.

Developer Profile

Unloct Developer Profile

gabefiftyone

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Unloct

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/unloct/unloct-login.css/wp-content/plugins/unloct/unloct-login.js
Script Paths
/wp-content/plugins/unloct/unloct-login.js
Version Parameters
unloct-login.css?ver=unloct-login.js?ver=

HTML / DOM Fingerprints

CSS Classes
galogingalogin-or
Data Attributes
data-unloct-login
JS Globals
unloctLogin
Shortcode Output
[unloct_login][visitor_login]
FAQ

Frequently Asked Questions about Unloct