
WP Cassify Security & Risk Analysis
wordpress.org/plugins/wp-cassifyThe plugin is an Apereo CAS Client. It performs CAS authentication and autorization for Wordpress.
Is WP Cassify Safe to Use in 2026?
Generally Safe
Score 99/100WP Cassify has a strong security track record. Known vulnerabilities have been patched promptly.
The wp-cassify plugin v2.3.9 presents a mixed security posture. While the static analysis shows a limited attack surface with no identified unprotected entry points, and a respectable number of nonce and capability checks, there are several areas of concern. The presence of dangerous functions like `unserialize` and `assert` is a significant red flag. Additionally, the SQL query usage is concerning, with 67% of queries not employing prepared statements, increasing the risk of SQL injection vulnerabilities. The output escaping is also suboptimal, with 41% of outputs not properly escaped, potentially leading to Cross-Site Scripting (XSS) vulnerabilities. The vulnerability history indicates one past medium-severity CVE related to XSS, which, coupled with the code analysis, suggests a recurring pattern of input sanitization and output escaping issues. Despite the limited attack surface and absence of unpatched CVEs currently, the identified code signals and historical pattern warrant caution.
Key Concerns
- Dangerous functions (unserialize, assert)
- SQL queries not using prepared statements
- Output escaping not properly handled
- Medium severity CVE in history
WP Cassify Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WP Cassify <= 2.3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
WP Cassify Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Cassify Attack Surface
Shortcodes 2
WordPress Hooks 14
Maintenance & Trust
WP Cassify Maintenance & Trust
Maintenance Signals
Community Trust
WP Cassify Alternatives
wpCAS
wpcas
wpCAS integrates WordPress into an established CAS architecture, allowing centralized management and authentication of user credentials in a heterogen …
wpCAS Server
wpcas-server
Turns WordPress or WordPress MU into a CAS single sign-on authenticator.
Cassava CAS Server
wp-cas-server
Cassava provides authentication services based on the Jasig CAS protocol.
Authorizer
authorizer
Authorizer limits login attempts, restricts access to specific users, and authenticates against external sources (OAuth2, Google, LDAP, or CAS).
YEGHRO Nostr Login
nostr-login
Enable secure WordPress authentication using Nostr keys - login with your Nostr identity.
WP Cassify Developer Profile
1 plugin · 900 total installs
How We Detect WP Cassify
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-cassify/admin/css/wp-cassify-admin-menu.css/wp-content/plugins/wp-cassify/admin/js/wp-cassify-admin-menu.js/wp-content/plugins/wp-cassify/js/wp-cassify-login.js/wp-content/plugins/wp-cassify/js/wp-cassify-service-validation.js/wp-content/plugins/wp-cassify/admin/css/wp-cassify-admin-menu.css/wp-content/plugins/wp-cassify/admin/js/wp-cassify-admin-menu.js/wp-content/plugins/wp-cassify/js/wp-cassify-login.js/wp-content/plugins/wp-cassify/js/wp-cassify-service-validation.jswp-cassify/admin/css/wp-cassify-admin-menu.css?ver=wp-cassify/admin/js/wp-cassify-admin-menu.js?ver=wp-cassify/js/wp-cassify-login.js?ver=wp-cassify/js/wp-cassify-service-validation.js?ver=HTML / DOM Fingerprints
wp-cassify-admin-pagewp-cassify-login-page<!-- Begin WP Cassify Shortcode: wp_cassify_login --><!-- End WP Cassify Shortcode: wp_cassify_login --><!-- Begin WP Cassify Shortcode: wp_cassify_logout --><!-- End WP Cassify Shortcode: wp_cassify_logout -->+4 moredata-wp-cassify-login-urldata-wp-cassify-logout-urldata-wp-cassify-service-validation-urlwpCassifyAdminMenuwpCassifyLoginwpCassifyServiceValidation[wp_cassify_login][wp_cassify_logout][wp_cassify_login_logout][wp_cassify_service_validation]