WPForce Logout – WordPress User Login Logout Management Plugin Security & Risk Analysis

wordpress.org/plugins/wp-force-logout

Forcefully log out users from your WordPress site, manage online status, and track last login activity.

8K active installs v2.3.0 PHP 7.0+ WP 4.0+ Updated Dec 18, 2025
forcelast-loginlast-seenlogoutonline-status
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is WPForce Logout – WordPress User Login Logout Management Plugin Safe to Use in 2026?

Generally Safe

Score 100/100

WPForce Logout – WordPress User Login Logout Management Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The wp-force-logout plugin v2.3.0 exhibits a generally good security posture, particularly in its limited attack surface and robust use of nonce and capability checks. The static analysis reveals only one AJAX handler, and importantly, this entry point appears to be protected by authentication checks, suggesting an effort to mitigate direct unauthorized access. The absence of known CVEs in its vulnerability history further supports a perception of a relatively secure plugin. The code signals also show no dangerous functions or file operations, and no external HTTP requests, all positive indicators. However, a significant concern arises from the presence of a SQL query that is not using prepared statements. While the impact of this single, unescaped SQL query is unknown without further taint analysis, it represents a potential avenue for SQL injection if user-supplied data is not meticulously handled. Additionally, the output escaping is only partially effective, with 43% of outputs being properly escaped, leaving a potential for cross-site scripting (XSS) vulnerabilities in the unescaped portions. The bundled Freemius library, while common, should be monitored for potential vulnerabilities in future analyses. Overall, the plugin is strong on access control but shows weaknesses in data sanitization and escaping, requiring careful attention to prevent data-related vulnerabilities.

Key Concerns

  • Raw SQL query without prepared statements
  • Low percentage of properly escaped output
  • Bundled library (Freemius v1.0) may be outdated
Vulnerabilities
None known

WPForce Logout – WordPress User Login Logout Management Plugin Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

WPForce Logout – WordPress User Login Logout Management Plugin Release Timeline

v2.3.0Current
v2.2.3
v2.2.2
v1.5.0
v1.4.5
v1.4.4.1
v1.4.4
v1.4.2
Code Analysis
Analyzed Mar 16, 2026

WPForce Logout – WordPress User Login Logout Management Plugin Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
4
3 escaped
Nonce Checks
3
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0

SQL Query Safety

0% prepared1 total queries

Output Escaping

43% escaped7 total outputs
Attack Surface

WPForce Logout – WordPress User Login Logout Management Plugin Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_wp_force_logout_dismiss_review_noticeincludes\class-wp-force-logout-process.php:34
WordPress Hooks 16
actionadmin_menuincludes\class-wp-force-logout-menu.php:29
actioninitincludes\class-wp-force-logout-process.php:32
actioninitincludes\class-wp-force-logout-process.php:33
actionadmin_enqueue_scriptsincludes\class-wp-force-logout-process.php:41
filtermanage_users_columnsincludes\class-wp-force-logout-process.php:42
filtermanage_users_custom_columnincludes\class-wp-force-logout-process.php:43
filtermanage_users_sortable_columnsincludes\class-wp-force-logout-process.php:44
filterusers_list_table_query_argsincludes\class-wp-force-logout-process.php:45
actionload-users.phpincludes\class-wp-force-logout-process.php:48
actionload-users.phpincludes\class-wp-force-logout-process.php:49
filterbulk_actions-usersincludes\class-wp-force-logout-process.php:50
actionrestrict_manage_usersincludes\class-wp-force-logout-process.php:51
actionin_admin_headerincludes\class-wp-force-logout-process.php:52
actioninitincludes\class-wp-force-logout.php:76
actioncli_initsrc\WPForce_Logout_CLI.php:72
actionplugins_loadedwp-force-logout.php:71
Maintenance & Trust

WPForce Logout – WordPress User Login Logout Management Plugin Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 18, 2025
PHP min version7.0
Downloads162K

Community Trust

Rating96/100
Number of ratings66
Active installs8K
Developer Profile

WPForce Logout – WordPress User Login Logout Management Plugin Developer Profile

Sanjeev Aryal

10 plugins · 12K total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WPForce Logout – WordPress User Login Logout Management Plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-force-logout/assets/css/wp-force-logout.css/wp-content/plugins/wp-force-logout/assets/js/script.js
Script Paths
assets/js/script.js
Version Parameters
wp-force-logout/assets/css/wp-force-logout.css?ver=wp-force-logout/assets/js/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
online-circleoffline-circle
Data Attributes
data-nonce="review-notice"
JS Globals
wpfl_plugins_params
FAQ

Frequently Asked Questions about WPForce Logout – WordPress User Login Logout Management Plugin