
WP login/out link with login popup Security & Risk Analysis
wordpress.org/plugins/wp-loginout-link-with-login-popupThis plugin adds login/ logout link in the navigation menu accordinng to the user login status and then redirect to page/link set by admin.
Is WP login/out link with login popup Safe to Use in 2026?
Generally Safe
Score 85/100WP login/out link with login popup has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-loginout-link-with-login-popup" v1.0 plugin exhibits a generally good security posture, with no known vulnerabilities or critical taint flows identified. The plugin effectively utilizes prepared statements for SQL queries and implements nonce and capability checks on its entry points, indicating a conscious effort to secure its functionality. The absence of file operations and external HTTP requests further reduces potential attack vectors.
However, a significant concern arises from the output escaping analysis. With only 36% of the 25 identified outputs properly escaped, there is a substantial risk of cross-site scripting (XSS) vulnerabilities. This means user-supplied data or other potentially malicious content could be rendered directly in the browser without proper sanitization, allowing attackers to inject harmful scripts. The presence of AJAX handlers without explicit authentication checks, although only one is present and it's not explicitly stated as unprotected by the data, warrants caution and further inspection to ensure it is adequately secured.
While the plugin's vulnerability history is clean, suggesting competent development so far, the current state of output escaping is a pressing issue. The strengths lie in its use of secure coding practices for data handling and authorization. The primary weakness is the insufficient output escaping, which could be a critical security flaw if exploited. A thorough review of how all outputs are handled is recommended.
Key Concerns
- Insufficient output escaping
- Potential unprotected AJAX handler
WP login/out link with login popup Security Vulnerabilities
WP login/out link with login popup Release Timeline
WP login/out link with login popup Code Analysis
Output Escaping
Data Flow Analysis
WP login/out link with login popup Attack Surface
AJAX Handlers 1
WordPress Hooks 6
Maintenance & Trust
WP login/out link with login popup Maintenance & Trust
Maintenance Signals
Community Trust
WP login/out link with login popup Alternatives
Inactive Logout
inactive-logout
Automatically logout idle user sessions, with logout redirections and concurrent limit logins all in one place.
BP Login Redirect
buddypress-login-redirect
Allows to decide buddypress website admins where their users should land after log in.
Redirect Homepage After Logout
redirect-homepage-after-logout
This plugin will enable to redirect user homepage after login.
BP Profile as Homepage Fork
bp-profile-as-homepage-fork
This plugin lets you have a normal site Homepage for visitors while logged-in users have their BP Profile as Homepage. This is similar to Facebook.
Login Logout Redirect – Redirects users after login/logout to a specific URL or page
login-logout-redirect
A simple WordPress plugin that redirects users after login/logout.
WP login/out link with login popup Developer Profile
2 plugins · 110 total installs
How We Detect WP login/out link with login popup
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-loginout-link-with-login-popup/js/login.js/wp-content/plugins/wp-loginout-link-with-login-popup/css/style.css/wp-content/plugins/wp-loginout-link-with-login-popup/js/login.jswp-loginout-link-with-login-popup/js/login.js?ver=wp-loginout-link-with-login-popup/css/style.css?ver=HTML / DOM Fingerprints
wlog_labelwlog_inputwlog_select_pagesettings_divfn_redirect_settingsettings_tableid="select_login_subscriber"/wp-json/wlog/v1/login