
WP Google Plus Connect Security & Risk Analysis
wordpress.org/plugins/wp-google-plus-connectAdd Google+ Direct Connect Badge & allow your WordPress/BuddyPress users to register or login via their Google+ account & import their stream …
Is WP Google Plus Connect Safe to Use in 2026?
Generally Safe
Score 85/100WP Google Plus Connect has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-google-plus-connect plugin v1.0.5.1 exhibits a mixed security posture. While it demonstrates good practices by using prepared statements for all its SQL queries and avoiding bundled libraries, significant concerns arise from the presence of dangerous functions and a lack of robust security checks. The use of `unserialize` is a critical vulnerability vector, especially when coupled with a complete absence of nonce and capability checks. This means that any user, regardless of their privilege level, could potentially trigger deserialization attacks if an attacker can control the data being unserialized. Although the taint analysis shows no critical or high severity flows, the inherent risk of `unserialize` remains, and the lack of authentication checks on entry points is a major red flag. The plugin's history of zero known CVEs is a positive indicator, suggesting past stability, but it does not mitigate the immediate risks identified in the static analysis. Overall, the plugin has strengths in its SQL handling but significant weaknesses in input validation and authorization, making it a moderate to high risk without further hardening.
Key Concerns
- Dangerous function 'unserialize' used
- No nonce checks found
- No capability checks found
- Unescaped output percentage is low (54%)
- Flows with unsanitized paths
WP Google Plus Connect Security Vulnerabilities
WP Google Plus Connect Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Google Plus Connect Attack Surface
Shortcodes 2
WordPress Hooks 18
Scheduled Events 1
Maintenance & Trust
WP Google Plus Connect Maintenance & Trust
Maintenance Signals
Community Trust
WP Google Plus Connect Alternatives
GP – GeePress
gp
All the tools you need to integrate your WordPress and Google+.
Metronet Embed Google Plus
metronet-embed-google-plus
Easily embed Google+ posts into your pages
Advanced Google reCAPTCHA
advanced-google-recaptcha
Captcha protection against spam comments & brute force login attacks using Google reCAPTCHA.
Nextend Social Login and Register
nextend-facebook-connect
One click registration & login plugin for Facebook, Google, X (formerly Twitter) and more. Quick setup and easy configuration.
Login No Captcha reCAPTCHA
login-recaptcha
Adds a Google No Captcha ReCaptcha checkbox to your Wordpress and Woocommerce login, forgot password, and user registration pages.
WP Google Plus Connect Developer Profile
2 plugins · 1K total installs
How We Detect WP Google Plus Connect
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-google-plus-connect/css/wds-google-connect.css/wp-content/plugins/wp-google-plus-connect/css/gplus-badge.css/wp-content/plugins/wp-google-plus-connect/js/wds-google-connect.jshttps://apis.google.com/js/plusone.jsHTML / DOM Fingerprints
wds-google-connect-loginwds-gplus-button<!-- Direct Connect & Badge --><!-- Google+ Direct Connect & Badge Header --><!-- Google+ Badge Short Code --><!-- Google+ Badge Function -->+8 moredata-clientiddata-redirecturidata-appnamedata-scopedata-callbackwindow.___gcfg<g:plus<a href="https://plus.google.com/