
When Last Login – Welcome Email Security & Risk Analysis
wordpress.org/plugins/when-last-login-welcome-email-add-onSend your users a welcome email when logging into your site for the first time.
Is When Last Login – Welcome Email Safe to Use in 2026?
Generally Safe
Score 85/100When Last Login – Welcome Email has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "when-last-login-welcome-email-add-on" v1.0 plugin exhibits a generally good security posture, with no readily apparent vulnerabilities indicated by the static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. Furthermore, the reliance on prepared statements for all SQL queries and the lack of direct external HTTP requests are strong security indicators. The plugin also shows no recorded vulnerability history, suggesting a history of responsible development and maintenance.
However, several areas present potential concerns. The low percentage of properly escaped output (29%) raises a red flag, indicating a risk of Cross-Site Scripting (XSS) vulnerabilities if any of the unescaped output reaches an authenticated user or is displayed on a public-facing page. Additionally, the absence of nonce checks and capability checks on any potential entry points, even though none were identified in this analysis, leaves the door open for future vulnerabilities if new entry points are introduced without proper security measures. The single file operation also warrants attention, as it could be a point of exploitation if not handled securely.
In conclusion, while the plugin currently presents a low risk due to its limited attack surface and lack of historical vulnerabilities, the unescaped output and missing authorization checks are weaknesses that could be exploited. Developers should prioritize addressing the output escaping issues to mitigate XSS risks and ensure robust authorization mechanisms are in place for any future updates or additions to the plugin's functionality.
Key Concerns
- Low output escaping percentage
- No nonce checks
- No capability checks
- File operations present
When Last Login – Welcome Email Security Vulnerabilities
When Last Login – Welcome Email Code Analysis
Output Escaping
When Last Login – Welcome Email Attack Surface
WordPress Hooks 6
Maintenance & Trust
When Last Login – Welcome Email Maintenance & Trust
Maintenance Signals
Community Trust
When Last Login – Welcome Email Alternatives
Newsletter – Send awesome emails from WordPress
newsletter
An email marketing tool for your blog: subscription forms to create your lists with unlimited subscribers and newsletters.
When Last Login
when-last-login
Show a users last login date by creating a sortable column in your WordPress users list.
WP Last Login
wp-last-login
Make the last login for each user visible in the user overview.
Swift SMTP (formerly Welcome Email Editor)
welcome-email-editor
Swift SMTP is a free & simple SMTP Plugin for WordPress.
WPForce Logout – WordPress User Login Logout Management Plugin
wp-force-logout
Forcefully log out users from your WordPress site, manage online status, and track last login activity.
When Last Login – Welcome Email Developer Profile
7 plugins · 66K total installs
How We Detect When Last Login – Welcome Email
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/when-last-login-welcome-email-add-on/js/admin.js