
User Login Plus Security & Risk Analysis
wordpress.org/plugins/user-login-plusShow a users last login date by creating a sortable column in your WordPress users list.
Is User Login Plus Safe to Use in 2026?
Generally Safe
Score 85/100User Login Plus has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The user-login-plus plugin v1.1 exhibits a generally strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with insufficient authentication significantly limits the plugin's attack surface. Furthermore, the code shows good practices with all SQL queries utilizing prepared statements and the presence of a capability check. The lack of file operations and external HTTP requests also reduces potential risks. However, the analysis did reveal a weakness in output escaping, with only 50% of outputs being properly escaped. This could potentially lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is displayed without adequate sanitization.
The vulnerability history for user-login-plus is entirely clear, with no recorded CVEs. This suggests a history of responsible development and timely patching, or that the plugin has not been a significant target for past vulnerabilities. Coupled with the zero taint flows indicating no critical or high-severity unsanitized paths, the plugin appears to be developed with security in mind. The primary concern highlighted by the static analysis is the output escaping. While the overall security is good, this specific area warrants attention to ensure all dynamic content is handled securely.
Key Concerns
- 50% of outputs not properly escaped
User Login Plus Security Vulnerabilities
User Login Plus Release Timeline
User Login Plus Code Analysis
SQL Query Safety
Output Escaping
User Login Plus Attack Surface
WordPress Hooks 13
Maintenance & Trust
User Login Plus Maintenance & Trust
Maintenance Signals
Community Trust
User Login Plus Alternatives
When Last Login
when-last-login
Show a users last login date by creating a sortable column in your WordPress users list.
Last Login Time
last-login-time
A lightweight plugin that allows you to see active users according to their last login time/date.
Check your Last Login
last-login-on-dashboard
The ideal plugin to check your last login ip and time for his account security. Extra details like browser and operating system.
WPForce Logout – WordPress User Login Logout Management Plugin
wp-force-logout
Forcefully log out users from your WordPress site, manage online status, and track last login activity.
When Last Login – Export User Records
when-last-login-export-user-records
Export your user's login records into a CSV or JSON file in seconds.
User Login Plus Developer Profile
1 plugin · 0 total installs
How We Detect User Login Plus
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/user-login-plus/user-login-plus.phpHTML / DOM Fingerprints
message