Logged-in-only Security & Risk Analysis

wordpress.org/plugins/wp-logged-in-only

A Plugin to lock down the whole site to prevent public access.

700 active installs v2.1.4 PHP 5.3+ WP 3.0.1+ Updated May 8, 2025
authenticationloginrest-apisimpleuser
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Logged-in-only Safe to Use in 2026?

Generally Safe

Score 100/100

Logged-in-only has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11mo ago
Risk Assessment

The "wp-logged-in-only" v2.1.4 plugin exhibits a strong static security posture based on the provided analysis. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits its attack surface. Furthermore, the code signals indicate no dangerous functions are used, all SQL queries are properly prepared, and all output is correctly escaped. The lack of file operations and external HTTP requests further reduces potential exposure. The absence of any recorded vulnerabilities, including critical or high severity issues, suggests a history of secure development and maintenance for this plugin. However, the lack of any nonce checks or capability checks across all entry points, while currently having zero entry points, represents a potential weakness if the plugin were to be extended or modified in the future without these security measures being implemented. Overall, the plugin appears to be very secure in its current state, with no identified vulnerabilities in the provided analysis or history, but the lack of fundamental security checks on potential future entry points is a minor area of concern.

Key Concerns

  • Missing nonce checks on potential entry points
  • Missing capability checks on potential entry points
Vulnerabilities
None known

Logged-in-only Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Logged-in-only Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Logged-in-only Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actiontemplate_redirectloggedinonly.php:20
filterrest_authentication_errorsloggedinonly.php:37
actionplugins_loadedloggedinonly.php:45
Maintenance & Trust

Logged-in-only Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMay 8, 2025
PHP min version5.3
Downloads21K

Community Trust

Rating100/100
Number of ratings7
Active installs700
Developer Profile

Logged-in-only Developer Profile

Drivingralle

2 plugins · 800 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Logged-in-only

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Logged-in-only