
Logged-in-only Security & Risk Analysis
wordpress.org/plugins/wp-logged-in-onlyA Plugin to lock down the whole site to prevent public access.
Is Logged-in-only Safe to Use in 2026?
Generally Safe
Score 100/100Logged-in-only has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-logged-in-only" v2.1.4 plugin exhibits a strong static security posture based on the provided analysis. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits its attack surface. Furthermore, the code signals indicate no dangerous functions are used, all SQL queries are properly prepared, and all output is correctly escaped. The lack of file operations and external HTTP requests further reduces potential exposure. The absence of any recorded vulnerabilities, including critical or high severity issues, suggests a history of secure development and maintenance for this plugin. However, the lack of any nonce checks or capability checks across all entry points, while currently having zero entry points, represents a potential weakness if the plugin were to be extended or modified in the future without these security measures being implemented. Overall, the plugin appears to be very secure in its current state, with no identified vulnerabilities in the provided analysis or history, but the lack of fundamental security checks on potential future entry points is a minor area of concern.
Key Concerns
- Missing nonce checks on potential entry points
- Missing capability checks on potential entry points
Logged-in-only Security Vulnerabilities
Logged-in-only Code Analysis
Logged-in-only Attack Surface
WordPress Hooks 3
Maintenance & Trust
Logged-in-only Maintenance & Trust
Maintenance Signals
Community Trust
Logged-in-only Alternatives
Duo Two-Factor Authentication
duo-wordpress
Easily add Duo Security two-factor authentication to your WordPress website. Enable two-factor authentication for your admins and/or users.
JSON API User
json-api-user
Extends the JSON API Plugin to allow RESTful user registration, authentication & many other User Meta, BP functions. A Pro version is also available.
Force Login With Email
force-login-with-email
Enable login in WordPress only with user e-mail address.
Private Website – Login Required
private-website
This plugin requires users to be logged in to view the website. Activate the plugin to enforce login, and deactivate it to remove the restriction.
Memberstack – Member Management & Content Protection
memberstack
Transform your WordPress site into a premium membership platform. Create members-only content and manage subscriptions with ease.
Logged-in-only Developer Profile
2 plugins · 800 total installs
How We Detect Logged-in-only
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.