Unofficial – Frill.co SSO Security & Risk Analysis

wordpress.org/plugins/unofficial-frill-sso

Unofficial Frill.co SSO plugin, enable SSO (Single-sign-on) login from WordPress to [Frill](https://frill.co/ "Frill.co")

10 active installs v1.0.3 PHP 7.2+ WP 5.7+ Updated Oct 6, 2021
changelogfeedbackfrillfrill-coroadmap
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Unofficial – Frill.co SSO Safe to Use in 2026?

Generally Safe

Score 85/100

Unofficial – Frill.co SSO has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The "unofficial-frill-sso" plugin v1.0.3 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The plugin has no recorded vulnerabilities (CVEs) and no history of common security issues, which is a positive indicator. The code analysis reveals a commendable lack of dangerous functions, SQL injection vulnerabilities (all queries are prepared), and external HTTP requests. File operations are also absent. The presence of capability checks, even if only one is identified, is a good sign for access control. The output escaping rate of 85% is reasonably good, though not perfect.

However, there are areas that warrant caution. The most significant concern is the complete absence of identified AJAX handlers, REST API routes, shortcodes, and cron events. While this might imply a small attack surface, it's highly unusual for a plugin that likely interacts with authentication or user management. The lack of nonce checks on any potential entry points, combined with no detected capability checks on the limited entry points, raises a red flag. It's unclear how authentication and authorization are being handled at these points, if they exist. The taint analysis showing zero flows is also suspicious; it might indicate the analysis wasn't comprehensive enough to find potential data flow issues, or the plugin is exceptionally clean. Without more clarity on the entry points and their protective measures, a moderate level of risk remains, primarily due to the unknowns and the potential for unaddressed access control or input validation issues.

Key Concerns

  • No nonce checks found
  • Low number of capability checks identified
  • High output escaping rate, but not 100%
  • No taint flows detected - potentially incomplete analysis or oversimplification
Vulnerabilities
None known

Unofficial – Frill.co SSO Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Unofficial – Frill.co SSO Release Timeline

v1.0.3Current
v1.0.2
Code Analysis
Analyzed Apr 16, 2026

Unofficial – Frill.co SSO Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
17 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

85% escaped20 total outputs
Attack Surface

Unofficial – Frill.co SSO Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actiontemplate_redirectincludes/RedirectHandler.php:10
actionadmin_menuincludes/Settings.php:9
actionadmin_initincludes/Settings.php:10
filterplugin_row_metaunofficial-frill-sso.php:25
actionplugins_loadedunofficial-frill-sso.php:34
Maintenance & Trust

Unofficial – Frill.co SSO Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedOct 6, 2021
PHP min version7.2
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Unofficial – Frill.co SSO Developer Profile

zarex

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Unofficial – Frill.co SSO

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/unofficial-frill-sso/includes/js/frill-sso-admin.js/wp-content/plugins/unofficial-frill-sso/includes/css/frill-sso-admin.css
Script Paths
/wp-content/plugins/unofficial-frill-sso/includes/js/frill-sso-admin.js
Version Parameters
unofficial-frill-sso/includes/js/frill-sso-admin.js?ver=unofficial-frill-sso/includes/css/frill-sso-admin.css?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Unofficial – Frill.co SSO