
WP SAML Auth Security & Risk Analysis
wordpress.org/plugins/wp-saml-authSAML authentication for WordPress.
Is WP SAML Auth Safe to Use in 2026?
Generally Safe
Score 100/100WP SAML Auth has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-saml-auth" v2.3.1 plugin exhibits a strong security posture based on the provided static analysis. The complete absence of unprotected entry points across AJAX, REST API, shortcodes, and cron events is a significant strength. Furthermore, the code adheres to best practices by using prepared statements for all SQL queries and ensuring proper output escaping for all detected outputs. The lack of identified dangerous functions and external HTTP requests also contributes to a reduced attack surface.
However, the analysis does reveal a couple of areas that warrant attention. The presence of 0 nonce checks across the entire plugin is a notable weakness, especially since nonce checks are crucial for preventing Cross-Site Request Forgery (CSRF) attacks on any functionality that modifies data. While the current data shows no specific vulnerabilities or taint flows, the absence of nonce checks represents a potential gap that could be exploited if any user-facing functionality were to be added or modified in the future. The single capability check, while present, doesn't fully mitigate the risk posed by the missing nonces.
Given the clean vulnerability history with no known CVEs or past issues, the plugin appears to have been developed with security in mind. The lack of critical or high severity taint flows further reinforces this. The overall conclusion is that the plugin is currently in a good security state, with its primary weakness being the absence of nonce checks for its entry points, a fundamental security mechanism.
Key Concerns
- Missing nonce checks
WP SAML Auth Security Vulnerabilities
WP SAML Auth Code Analysis
Output Escaping
WP SAML Auth Attack Surface
WordPress Hooks 16
Maintenance & Trust
WP SAML Auth Maintenance & Trust
Maintenance Signals
Community Trust
WP SAML Auth Alternatives
Shibboleth
shibboleth
Allows WordPress to externalize user authentication and account creation to a Shibboleth Service Provider.
Shibboleth With LDAP Authorization
ugrm
This plugin extends the Shibboleth plugin to work with UFAD & Shibboleth at the University of Florida. Developed at the Florida Museum of Natural …
Frontegg SAML SSO
frontegg-saml-sso
Replace the WordPress login and logout flows with secure SAML-based authentication via Frontegg. Easily configure your SSO app from the admin panel.
SSO JumpCloud – Enterprise SAML & SCIM
sso-connector-for-jumpcloud
Securely connect WordPress with JumpCloud for Enterprise SSO via SAML 2.0 and automated user provisioning via SCIM.
All-In-One Security (AIOS) – Security and Firewall
all-in-one-wp-security-and-firewall
Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plugin designed especially for WordPress.
WP SAML Auth Developer Profile
8 plugins · 39K total installs
How We Detect WP SAML Auth
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-saml-auth/css/wp-saml-auth.css/wp-content/plugins/wp-saml-auth/js/wp-saml-auth.js/wp-content/plugins/wp-saml-auth/js/wp-saml-auth.jswp-saml-auth/css/wp-saml-auth.css?ver=wp-saml-auth/js/wp-saml-auth.js?ver=