
WP One Tap Google Sign In Security & Risk Analysis
wordpress.org/plugins/wp-one-tap-google-sign-inSecure Google One Tap sign-in for WordPress login pages, with account linking and admin activity logs.
Is WP One Tap Google Sign In Safe to Use in 2026?
Generally Safe
Score 100/100WP One Tap Google Sign In has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-one-tap-google-sign-in plugin v1.0.1 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by utilizing prepared statements for all its SQL queries and showing a high percentage of properly escaped outputs. The absence of known vulnerabilities in its history is also a positive indicator, suggesting a generally well-maintained codebase. Furthermore, the lack of file operations, external HTTP requests, and dangerous functions are all commendable security characteristics.
However, significant concerns arise from the attack surface analysis. The plugin exposes two AJAX handlers, both of which lack any authentication checks. This is a critical security weakness, as any unauthenticated user could potentially trigger these handlers, leading to unintended actions or data exposure. The absence of nonce checks on these AJAX endpoints further exacerbates this risk, as it provides no mechanism to verify the legitimacy of the requests. While taint analysis did not reveal any specific vulnerabilities in this version, the uncovered attack surface is substantial enough to warrant serious attention.
In conclusion, while the plugin benefits from secure SQL handling and output escaping, the lack of authentication and nonce checks on its AJAX endpoints presents a significant and immediate security risk. The vulnerability history is clean, which is encouraging, but does not mitigate the direct exploitable paths identified in the static analysis. Addressing these unprotected entry points should be the highest priority for improving the plugin's security.
Key Concerns
- AJAX handlers without auth checks
- AJAX handlers without nonce checks
- Unescaped output (33% unescaped)
WP One Tap Google Sign In Security Vulnerabilities
WP One Tap Google Sign In Release Timeline
WP One Tap Google Sign In Code Analysis
Bundled Libraries
Output Escaping
WP One Tap Google Sign In Attack Surface
AJAX Handlers 2
WordPress Hooks 3
Maintenance & Trust
WP One Tap Google Sign In Maintenance & Trust
Maintenance Signals
Community Trust
WP One Tap Google Sign In Alternatives
Log in with Google
login-with-google
Minimal plugin that allows WordPress users to log in using Google.
Edel Auth for Supabase
edel-auth-for-supabase
Connect your WordPress site to Supabase Authentication. Securely manage members with Supabase while keeping WordPress admins separate.
Easy Secure Login – Google One Tap & Sign-In
easy-secure-login
Secure WordPress login with Google Sign-In, Google One Tap, optional passwordless access, user controls, and redirects.
GOAuth
goauth
Go and OAuthenticate plugin for WordPress.
LoginBerry – 2FA, Passwordless & Email Verification
loginberry
Complete login security for WordPress & WooCommerce: LoginBerry adds email-based account verification, optional two-factor authentication (2FA), o …
WP One Tap Google Sign In Developer Profile
3 plugins · 110 total installs
How We Detect WP One Tap Google Sign In
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-one-tap-google-sign-in/assets/css/style-login.css/wp-content/plugins/wp-one-tap-google-sign-in/assets/js/app-gsi.jshttps://accounts.google.com/gsi/clientHTML / DOM Fingerprints
onetapgsi