WP One Login Security & Risk Analysis

wordpress.org/plugins/wp-one-login

WP One Login , to prevent users from login to your site from different devices at a time.

30 active installs v1.0 PHP + WP 3.4+ Updated Sep 23, 2021
concurrent-loginprevent-multiple-loginsingle-loginwp-concurrent-loginwp-single-login
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP One Login Safe to Use in 2026?

Generally Safe

Score 85/100

WP One Login has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the "wp-one-login" v1.0 plugin appears to have a very strong security posture. The absence of any identified entry points like AJAX handlers, REST API routes, shortcodes, or cron events, and the fact that none of these potential entry points are unprotected, significantly reduces the attack surface. The code signals also indicate robust security practices, with no dangerous functions, all SQL queries using prepared statements, and all output being properly escaped. The plugin also demonstrates good security awareness by not performing file operations or external HTTP requests, and notably, the absence of nonce checks and capability checks on the analyzed entry points is not a concern due to the lack of entry points to begin with.

The vulnerability history reinforces this positive assessment, showing zero known CVEs of any severity. This lack of historical vulnerabilities suggests a commitment to security by the developers or a lack of previously discovered flaws. The taint analysis also shows no identified flows with unsanitized paths, further indicating that data is handled securely within the plugin. The overall impression is that of a well-developed and secure plugin, with no immediate red flags raised by the analysis.

While the current analysis shows no weaknesses, it's important to remember that static analysis has its limitations. The plugin's security is heavily reliant on the absence of exploitable code paths. If any new features are added without thorough security review, or if new vulnerabilities are discovered in the future, the security posture could change. However, based on the data for v1.0, the plugin demonstrates excellent security practices and a clean vulnerability record.

Vulnerabilities
None known

WP One Login Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP One Login Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

WP One Login Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actioninitwp-single-login.php:16
Maintenance & Trust

WP One Login Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedSep 23, 2021
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs30
Developer Profile

WP One Login Developer Profile

Mithu A Quayium

16 plugins · 500 total installs

84
trust score
Avg Security Score
86/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP One Login

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about WP One Login