
UsersWP – Social Login Security & Risk Analysis
wordpress.org/plugins/userswp-social-loginSocial Login addon for UsersWP.
Is UsersWP – Social Login Safe to Use in 2026?
Generally Safe
Score 100/100UsersWP – Social Login has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "userswp-social-login" v1.5.6 plugin presents a mixed security posture. On the positive side, it shows a strong reliance on prepared statements for SQL queries and avoids external HTTP requests or file operations, which are common attack vectors. The absence of any recorded vulnerabilities in its history is also a promising sign of good development practices. However, significant concerns arise from the static analysis. The plugin has a total of 2 entry points, both of which are AJAX handlers lacking authentication checks. This directly exposes critical functionality to unauthenticated users, creating a substantial risk. Furthermore, the taint analysis revealed 3 flows with unsanitized paths, with one classified as high severity. This indicates a potential for attackers to manipulate input that is not properly validated or sanitized before being used in sensitive operations, possibly leading to code execution or data compromise. The lack of nonce checks on AJAX actions exacerbates this risk, as it provides an easy avenue for Cross-Site Request Forgery (CSRF) attacks. While the plugin avoids dangerous functions and has a relatively small attack surface in terms of shortcodes and cron events, the unprotected AJAX endpoints and unsanitized taint flows are critical weaknesses that need immediate attention.
Key Concerns
- AJAX handlers without auth checks
- High severity taint flow
- Unsanitized paths in taint flows
- Lack of nonce checks
- Low percentage of properly escaped output
- Bundled library (Guzzle)
UsersWP – Social Login Security Vulnerabilities
UsersWP – Social Login Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
UsersWP – Social Login Attack Surface
AJAX Handlers 2
WordPress Hooks 36
Maintenance & Trust
UsersWP – Social Login Maintenance & Trust
Maintenance Signals
Community Trust
UsersWP – Social Login Alternatives
Social Login
oa-social-login
With Social Login your users can login, register and comment with 40+ Social Networks. Maintenance Free. Uptime Guarantee. Fulltime devs
Happy Social Login
happy-social-login
Enables user authentication through various social media accounts. Login through Google, Facebook, LinkedIn, GitHub and more.
Heateor Social Login WordPress
heateor-social-login
One click login and registration via Facebook, Twitter, Linkedin, Google and 23 others.
WP Social AutoConnect
wp-fb-autoconnect
A lightweight but powerful Facebook login plugin, easy to setup and transparent to new and returning users alike. Supports Buddypress.
Social Login by BestWebSoft
social-login-bws
Add social media login, registration, and commenting to your WordPress website.
UsersWP – Social Login Developer Profile
12 plugins · 90K total installs
How We Detect UsersWP – Social Login
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/userswp-social-login/assets/css/uwp-social-login.css/wp-content/plugins/userswp-social-login/assets/js/uwp-social-login.js/wp-content/plugins/userswp-social-login/vendor/hybridauth/hybridauth/hybridauth/hybridauth.css/wp-content/plugins/userswp-social-login/vendor/hybridauth/hybridauth/hybridauth/hybridauth.min.js/wp-content/plugins/userswp-social-login/assets/js/uwp-social-login.js/wp-content/plugins/userswp-social-login/vendor/hybridauth/hybridauth/hybridauth/hybridauth.min.jsuserswp-social-login/assets/css/uwp-social-login.css?ver=userswp-social-login/assets/js/uwp-social-login.js?ver=HTML / DOM Fingerprints
uwp-social-login-buttonsuwp-social-login-widget-containeruserswp-social-login-wrapdata-plugindata-userswp-social-login-ajax-urluwp_social_params[userswp_social_login]