
Web3 – Crypto wallet Login & NFT token gating Security & Risk Analysis
wordpress.org/plugins/web3-authenticationUsers can sign up for your WordPress using their crypto wallets. Gate content based on NFTs owned. Web3 authentication plugin supports crypto wallets …
Is Web3 – Crypto wallet Login & NFT token gating Safe to Use in 2026?
Generally Safe
Score 88/100Web3 – Crypto wallet Login & NFT token gating has a strong security track record. Known vulnerabilities have been patched promptly.
The web3-authentication plugin v3.1.4 exhibits a mixed security posture. On the positive side, it demonstrates strong adherence to secure coding practices in several areas. The absence of dangerous functions, raw SQL queries, and file operations is commendable. The plugin also shows a high degree of output escaping and implements nonce and capability checks, indicating a good understanding of WordPress security fundamentals. However, the presence of two past critical vulnerabilities, both related to Authentication Bypass Using an Alternate Path or Channel, is a significant concern. While currently unpatched vulnerabilities are zero, this history suggests a recurring pattern of weaknesses that attackers could exploit if similar flaws are reintroduced. The taint analysis, while showing no critical or high severity flows, did reveal that all analyzed flows had unsanitized paths, which, combined with the history of authentication bypass, warrants careful scrutiny. The limited attack surface with all entry points protected is a strength, but the history of critical vulnerabilities cannot be overlooked.
Key Concerns
- History of 2 critical vulnerabilities
- All taint flows with unsanitized paths
- External HTTP requests present
Web3 – Crypto wallet Login & NFT token gating Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Web3 <= 2.8.0 - Authentication Bypass
Web3 – Crypto wallet Login & NFT token gating <= 2.6.0 - Authentication Bypass
Web3 – Crypto wallet Login & NFT token gating Code Analysis
Output Escaping
Data Flow Analysis
Web3 – Crypto wallet Login & NFT token gating Attack Surface
AJAX Handlers 2
WordPress Hooks 16
Maintenance & Trust
Web3 – Crypto wallet Login & NFT token gating Maintenance & Trust
Maintenance Signals
Community Trust
Web3 – Crypto wallet Login & NFT token gating Alternatives
Kredeum NFTs, the easiest way to sell your NFTs directly on your WordPress site
kredeum-nfts
Sell your NFTs directly on your WordPress site in an easy and fast way.
WordThree – Easily Login & Register Using Your MetaMask Wallet
wordthree
Allow users to login and register using their MetaMask wallet.
Opensea NFT Gallery
gallery-openseanft
In just few clicks you can display NFTs (from Opensea) on your Wordpress website.
Web3 Wallet Login
web3-wallet-login
This module allows for users to login to their wordpress account via their web3 wallet.
WPSmartContracts
wp-smart-contracts
WP Smart Contracts: The first WordPress plugin bringing blockchain technology to your fingertips since 2019.
Web3 – Crypto wallet Login & NFT token gating Developer Profile
38 plugins · 83K total installs
How We Detect Web3 – Crypto wallet Login & NFT token gating
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/web3-authentication/resources/css/prod/style_settings.min.css/wp-content/plugins/web3-authentication/resources/css/prod/phone.min.css/wp-content/plugins/web3-authentication/resources/js/prod/phone.min.jsresources/js/prod/phone.min.jsweb3-authentication/resources/css/prod/style_settings.min.css?ver=web3-authentication/resources/css/prod/phone.min.css?ver=web3-authentication/resources/js/prod/phone.min.js?ver=HTML / DOM Fingerprints
moweb3-login-btnmoweb3-login-btn-textmoweb3-btnmoweb3-input<!-- Custom JS to handle redirection--><!-- Web3 Login/Register Form--><!-- Web3 Login Button-->data-modal-iddata-wallet-typemoweb3_login_popupMoWeb3ConstantsMOWEB3_URL[mo_web3_login_button][mo_web3_login_form][mo_web3_logout_button]