
Was it you? Account login notifications Security & Risk Analysis
wordpress.org/plugins/was-it-youSend an email notification to users each time someone logs in from a new IP. This helps users figure out if someone accessed their accounts without th …
Is Was it you? Account login notifications Safe to Use in 2026?
Generally Safe
Score 85/100Was it you? Account login notifications has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "was-it-you" v1.0.1 plugin exhibits a strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits its attack surface. Crucially, all SQL queries are performed using prepared statements, and all identified output is properly escaped, mitigating common vulnerabilities like SQL injection and cross-site scripting. The presence of a nonce check is also a positive indicator of secure development practices. The plugin's vulnerability history is completely clean, with zero known CVEs, which suggests either a well-developed codebase or a lack of historical scrutiny.
While the static analysis reveals no immediate critical flaws or unsanitized data flows, the absence of any capability checks is a notable concern. This means that any functionality exposed by the plugin, however small, might be accessible to any logged-in user, regardless of their role or permissions. This could be a significant oversight if the plugin were to introduce any features in future versions. Given the current state, the plugin appears secure for its current functionality, but the lack of permission controls is a potential weakness that could be exploited if functionality expands.
Overall, "was-it-you" v1.0.1 demonstrates good development practices regarding data handling and sanitization. The lack of any historical vulnerabilities is a testament to its perceived security. However, the complete absence of capability checks represents a gap in secure access control that should be addressed to ensure a robust security posture, especially if the plugin's feature set evolves.
Key Concerns
- No capability checks found
Was it you? Account login notifications Security Vulnerabilities
Was it you? Account login notifications Code Analysis
Output Escaping
Was it you? Account login notifications Attack Surface
WordPress Hooks 5
Maintenance & Trust
Was it you? Account login notifications Maintenance & Trust
Maintenance Signals
Community Trust
Was it you? Account login notifications Alternatives
Loginizer
loginizer
Loginizer is a WordPress security plugin which helps you fight against bruteforce attacks.
Easy Basic Authentication – Add basic auth to site or admin area
easy-basic-authentication
Secure your WordPress site with easy and effective basic authentication. Restrict access, monitor attempts, and enhance security.
Login Require Press
loginrequirepress
Easy way to require user login to view specific pages / posts.
Attributes User Access
attributes-user-access
Lightweight WordPress authentication with custom login pages, role-based redirections, and secure user access control.
Hetjens Registered Only
hetjens-registered-only
This plug-in restricts the access to blog and feed. Visitors need to login before accessing the blog. It offers a private feed for every user.
Was it you? Account login notifications Developer Profile
2 plugins · 910 total installs
How We Detect Was it you? Account login notifications
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/was-it-you/assets/js/wasityou.js/wp-content/plugins/was-it-you/assets/css/wasityou.css/wp-content/plugins/was-it-you/assets/js/wasityou.jswasityou.js?ver=wasityou.css?ver=HTML / DOM Fingerprints
e11-wasityou-login-notifiere11_wasityou_params