
WP Direct Login Link Security & Risk Analysis
wordpress.org/plugins/wp-direct-login-linkCreate a secure way to login by Link.
Is WP Direct Login Link Safe to Use in 2026?
Generally Safe
Score 92/100WP Direct Login Link has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-direct-login-link" v2.0 plugin exhibits a generally strong security posture based on the provided static analysis. It demonstrates good practices by exclusively using prepared statements for its SQL queries and a high percentage of properly escaped outputs. The absence of file operations and external HTTP requests further reduces its attack surface. The presence of a nonce check is a positive indicator of security awareness, even if capability checks are absent. The plugin also boasts a clean vulnerability history with no known CVEs, suggesting a history of secure development.
However, the taint analysis reveals a potential concern with two flows identified as having unsanitized paths. While these did not escalate to critical or high severity in this analysis, they represent an area where a malicious actor could potentially manipulate input to affect program execution, especially if the plugin's functionality involves handling user-provided data in these specific flows. The lack of explicit capability checks on any entry points is another area of potential weakness, as it relies solely on WordPress's default access controls which might not be sufficient for all scenarios, although the very limited attack surface currently mitigates this risk.
In conclusion, the plugin is largely secure with a commitment to best practices like prepared statements and output escaping. The vulnerability history is a significant strength. The primary areas for improvement lie in thoroughly sanitizing the identified unsanitized paths and implementing capability checks where appropriate to further harden the plugin against potential attacks. The current risk level is moderate, leaning towards low due to the minimal attack surface and lack of historical vulnerabilities.
Key Concerns
- Flows with unsanitized paths detected
- No capability checks on entry points
WP Direct Login Link Security Vulnerabilities
WP Direct Login Link Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Direct Login Link Attack Surface
WordPress Hooks 11
Maintenance & Trust
WP Direct Login Link Maintenance & Trust
Maintenance Signals
Community Trust
WP Direct Login Link Alternatives
WPS Hide Login
wps-hide-login
Change wp-login.php to anything you want.
LoginPress | wp-login Custom Login Page Customizer
loginpress
LoginPress is a Custom Login Page Customizer plugin allows you to easily customize the layout of login, admin login, client login, register pages.
Custom Login Page Customizer
login-customizer
Custom Login Customizer allows you to easily customize your admin login page, straight from your WordPress Customizer!
All In One Login — WP Admin Login Page Security and Customization with Google reCAPTCHA, Social Login, Limit Login Attempt, 2FA, and more.
change-wp-admin-login
Do you want to secure and customize the WordPress login page? Download the All in One Login plugin for login page security and customization.
Easy Hide Login
easy-hide-login
Hide wp-login.php file, prevent attacks on login form, hide login & increase security. No files are changed.
WP Direct Login Link Developer Profile
1 plugin · 10 total installs
How We Detect WP Direct Login Link
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-direct-login-link/assets/css/wpmll-be-style.css/wp-content/plugins/wp-direct-login-link/assets/js/be-scripts.js/wp-content/plugins/wp-direct-login-link/assets/css/wpmll-form.css/wp-content/plugins/wp-direct-login-link/assets/js/be-scripts.jswp-direct-login-link/assets/css/wpmll-be-style.css?ver=1.0wp-direct-login-link/assets/js/be-scripts.js?ver=1.0wp-direct-login-link/assets/css/wpmll-form.css?ver=1.0HTML / DOM Fingerprints
wpmll-magic-formwpmll_magic_form