
User Info Login Shortcode Security & Risk Analysis
wordpress.org/plugins/userinfologinshortcodeThis plugin provides a [user_info_login] shortcode to let you embed a User Info or Login section without farting around with page templates or widgets
Is User Info Login Shortcode Safe to Use in 2026?
Generally Safe
Score 100/100User Info Login Shortcode has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "userinfologinshortcode" v0.2.1 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding output escaping, with 100% of analyzed outputs being properly escaped. Furthermore, the plugin has no known recorded vulnerabilities (CVEs), suggesting a history of stable and secure development or a lack of widespread exploitation. The attack surface is also minimal, with only one shortcode and no AJAX handlers or REST API routes that are exposed without authentication checks. Taint analysis found no critical or high-severity flaws, and dangerous functions and file operations are absent.
However, a significant concern lies in the handling of SQL queries. All three identified SQL queries are executed without prepared statements. This makes the plugin highly susceptible to SQL injection vulnerabilities if any user-supplied data is incorporated into these queries, even if output is escaped. The lack of nonce checks and capability checks also presents a potential risk, as it implies that the functionality triggered by the shortcode might not be adequately protected against unauthorized access or misuse if those functions are called indirectly.
Key Concerns
- Raw SQL queries without prepare
- Missing nonce checks
- Missing capability checks
User Info Login Shortcode Security Vulnerabilities
User Info Login Shortcode Code Analysis
SQL Query Safety
User Info Login Shortcode Attack Surface
Shortcodes 1
Maintenance & Trust
User Info Login Shortcode Maintenance & Trust
Maintenance Signals
Community Trust
User Info Login Shortcode Alternatives
Passwordless Login
passwordless-login
Passwordless login form via a simple to use shortcode: [passwordless-login]
Bloginfo Shortcode
bloginfo-shortcode
Displays information about your blog in a page or post.
Bloginfo Shortcode
wp-bloginfo-shortcode
Add a [blog] shortcode to the Wordpress editor to include data from bloginfo()
Dig Bloginfo Shortcode
dig-bloginfo-shortcode
Fetch the blog info data and use it through a shortcode in html or post editor.
Read More Login
read-more-login
Put a combined read more/login/registration form in your posts and pages. The visitors must log in or sign up to read more.
User Info Login Shortcode Developer Profile
6 plugins · 620 total installs
How We Detect User Info Login Shortcode
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
inboxsubmit-buttonchk<!-- user info / login block --><!-- end user info / login block -->name="log"id="user_login"name="pwd"id="user_pass"name="submit"name="rememberme"+3 more<form name="loginform" action="