Web3 Wallet Login Security & Risk Analysis

wordpress.org/plugins/web3-wallet-login

This module allows for users to login to their wordpress account via their web3 wallet.

0 active installs v1.1.1 PHP 7.3+ WP 4.7+ Updated Apr 13, 2022
ethereumloginpolygonwalletweb3
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Web3 Wallet Login Safe to Use in 2026?

Generally Safe

Score 85/100

Web3 Wallet Login has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The web3-wallet-login plugin version 1.1.1 exhibits a strong security posture based on the provided static analysis. The absence of critical or high-severity taint flows, coupled with 100% of SQL queries using prepared statements, indicates good development practices for preventing common injection vulnerabilities. Furthermore, the presence of nonce and capability checks on its two AJAX entry points, along with a high percentage (95%) of properly escaped output, suggests an awareness of basic security principles to mitigate cross-site scripting (XSS) and unauthorized action risks.

The plugin's vulnerability history is a significant strength, with zero recorded CVEs across all severities. This lack of past vulnerabilities, especially critical or high ones, generally points to a well-maintained and secure codebase over time, or at least a lack of publicly discovered flaws. The total entry points are low and all are protected, which further reinforces a positive security outlook.

While the current data presents a favorable security assessment, it's important to note that static analysis is not exhaustive. The limited number of entry points and flows analyzed (1 flow analyzed out of 1 total) means there's a possibility of undiscovered issues. However, based solely on the provided evidence, the plugin appears to be developed with security in mind, demonstrating good practices and a clean vulnerability track record.

Vulnerabilities
None known

Web3 Wallet Login Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Web3 Wallet Login Release Timeline

v1.1.1Current
v1.1.0
v1.0.0
Code Analysis
Analyzed Mar 17, 2026

Web3 Wallet Login Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
1
18 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

95% escaped19 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

1 flows
<web3-wallet-login> (web3-wallet-login.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Web3 Wallet Login Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_WEB3_WALLET_LOGIN_authenticateweb3-wallet-login.php:352
noprivwp_ajax_WEB3_WALLET_LOGIN_authenticateweb3-wallet-login.php:353
WordPress Hooks 10
actionadmin_menuweb3-wallet-login.php:94
actionadmin_initweb3-wallet-login.php:100
actionadmin_noticesweb3-wallet-login.php:103
actionshow_user_profileweb3-wallet-login.php:106
actionprofile_updateweb3-wallet-login.php:109
actionedit_user_profile_updateweb3-wallet-login.php:110
actionwp_loadedweb3-wallet-login.php:113
actionlogin_enqueue_scriptsweb3-wallet-login.php:144
actionlogin_formweb3-wallet-login.php:163
actionplugins_loadedweb3-wallet-login.php:671
Maintenance & Trust

Web3 Wallet Login Maintenance & Trust

Maintenance Signals

WordPress version tested5.9.13
Last updatedApr 13, 2022
PHP min version7.3
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Web3 Wallet Login Developer Profile

vpallegar

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Web3 Wallet Login

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/web3-wallet-login/public/css/web3-wallet-login-styles.css/wp-content/plugins/web3-wallet-login/public/js/web3.min.js/wp-content/plugins/web3-wallet-login/public/js/bops.js/wp-content/plugins/web3-wallet-login/public/js/web3-wallet-login-library.js
Script Paths
public/css/web3-wallet-login-styles.csspublic/js/web3.min.jspublic/js/bops.jspublic/js/web3-wallet-login-library.js
Version Parameters
web3-wallet-login/public/css/web3-wallet-login-styles.css?ver=web3-wallet-login/public/js/web3-wallet-login-library.js?ver=

HTML / DOM Fingerprints

CSS Classes
web3-wallet-login-button-wrapperweb3loginMsg
Data Attributes
id="web3loginConnect"
JS Globals
loginvars
REST Endpoints
/wp-json/web3-wallet-login/v1/checkLogin
FAQ

Frequently Asked Questions about Web3 Wallet Login