
WordPass Security & Risk Analysis
wordpress.org/plugins/wordpassCreates word-based passwords for WordPress.
Is WordPass Safe to Use in 2026?
Generally Safe
Score 85/100WordPass has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wordpass" plugin v1.0.1 exhibits a generally positive security posture based on the provided static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points indicates a minimal attack surface. Furthermore, the lack of dangerous functions, file operations, or external HTTP requests is encouraging. However, a significant concern arises from the presence of a single SQL query that does not utilize prepared statements. This, combined with a low percentage of properly escaped output (57%), creates potential avenues for SQL injection and cross-site scripting (XSS) vulnerabilities.
The plugin's vulnerability history is clean, with no recorded CVEs. This, coupled with the absence of taint analysis issues, suggests that the plugin has either not been heavily targeted, or previous versions have been well-maintained. The presence of a capability check is a positive sign for access control, but the lack of nonce checks is a weakness, particularly if the plugin were to introduce any AJAX or administrative actions in the future.
In conclusion, while the plugin's limited attack surface and clean vulnerability history are strengths, the unescaped SQL query and insufficient output escaping represent tangible risks that should be addressed. The absence of nonce checks, while not an immediate critical flaw given the current entry points, is a potential vulnerability if the plugin's functionality expands.
Key Concerns
- SQL query without prepared statements
- Insufficient output escaping
- Missing nonce checks
WordPass Security Vulnerabilities
WordPass Code Analysis
SQL Query Safety
Output Escaping
WordPass Attack Surface
WordPress Hooks 5
Maintenance & Trust
WordPass Maintenance & Trust
Maintenance Signals
Community Trust
WordPass Alternatives
User Spam Remover
user-spam-remover
Automatically removes spam user registrations and other old, unused user accounts. Blocks annoying e-mail to administrator after new registrations.
Force Password Change
force-password-change
Require users to change their password on first login.
Bulk Password Reset
bulk-password-reset
Bulk Password Reset is a tool which can help you do a bulk password reset on all the users or just specific users within a category.
Create User With Password Multisite
create-user-with-password-multisite
Allow website administrators to allocate passwords to users as they add them to invidivual sites in WordPress Multisite.
Skeleton Key
skeleton-key
Gives administrators a skeleton key (their own password) to login as any user they'd like.
WordPass Developer Profile
2 plugins · 50K total installs
How We Detect WordPass
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wordpass/admin/css/style.css/wp-content/plugins/wordpass/admin/js/script.js/wp-content/plugins/wordpass/admin/js/script.jswordpass/admin/css/style.css?ver=wordpass/admin/js/script.js?ver=HTML / DOM Fingerprints
wordpass-admin-wrap<!-- WordPass Options --><!-- End WordPass Options -->data-wordpass-nonceWordPassAdmin