
When Last Login Security & Risk Analysis
wordpress.org/plugins/when-last-loginShow a users last login date by creating a sortable column in your WordPress users list.
Is When Last Login Safe to Use in 2026?
Generally Safe
Score 100/100When Last Login has a strong security track record. Known vulnerabilities have been patched promptly.
The 'when-last-login' plugin v1.2.3 exhibits a generally positive security posture with several strong practices in place. The complete absence of critical or high-severity taint flows, along with the use of prepared statements for all SQL queries, indicates a good understanding of secure coding principles. Furthermore, the limited attack surface, with only one AJAX handler and no REST API routes, shortcodes, or cron events, minimizes potential entry points for attackers. The presence of nonce and capability checks on the existing AJAX handler is also a commendable security measure.
However, a significant concern arises from the plugin's vulnerability history. The presence of one medium-severity CVE, even if currently patched, suggests a past weakness. While the current version might be clean, it highlights a potential for vulnerabilities to emerge in the plugin's codebase. The 53% rate of proper output escaping is another area for improvement; while not critically low, it leaves room for potential cross-site scripting (XSS) vulnerabilities if untrusted data is directly output without sufficient sanitization in the remaining 47% of cases. The single external HTTP request also warrants careful monitoring to ensure it doesn't become a vector for further attacks.
In conclusion, 'when-last-login' v1.2.3 has commendable strengths in its limited attack surface and secure database interaction. However, the past medium-severity vulnerability and the moderate output escaping rate present areas that require attention. While the plugin is not currently flagged with critical issues based on the provided data, ongoing vigilance and potential code review for the unescaped outputs would be prudent for maintaining a robust security profile.
Key Concerns
- Medium severity CVE history
- Moderate output escaping (53% proper)
When Last Login Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
When Last Login <= 1.2.1 - Cross-Site Request Forgery via wll_hide_subscription_notice
When Last Login Code Analysis
SQL Query Safety
Output Escaping
When Last Login Attack Surface
AJAX Handlers 1
WordPress Hooks 34
Maintenance & Trust
When Last Login Maintenance & Trust
Maintenance Signals
Community Trust
When Last Login Alternatives
Last Login Time
last-login-time
A lightweight plugin that allows you to see active users according to their last login time/date.
User Login Plus
user-login-plus
Show a users last login date by creating a sortable column in your WordPress users list.
Check your Last Login
last-login-on-dashboard
The ideal plugin to check your last login ip and time for his account security. Extra details like browser and operating system.
WPForce Logout – WordPress User Login Logout Management Plugin
wp-force-logout
Forcefully log out users from your WordPress site, manage online status, and track last login activity.
When Last Login – Export User Records
when-last-login-export-user-records
Export your user's login records into a CSV or JSON file in seconds.
When Last Login Developer Profile
7 plugins · 66K total installs
How We Detect When Last Login
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/when-last-login/css/admin.css/wp-content/plugins/when-last-login/js/notice-update.jsjs/notice-update.jswhen-last-login/js/notice-update.js?ver=1.0HTML / DOM Fingerprints
wll-update-notice-newsletterwll_notice_update