
User Login Notifier for WordPress Security & Risk Analysis
wordpress.org/plugins/wp-user-login-notifierUser Login Notifier plugin notifies WordPress site admin and users of the successful and failed login attempts via email.
Is User Login Notifier for WordPress Safe to Use in 2026?
Generally Safe
Score 100/100User Login Notifier for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-user-login-notifier v1.0.7 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of identified AJAX handlers, REST API routes, shortcodes, and cron events, particularly those lacking authentication, indicates a minimal attack surface. Furthermore, the code's reliance on prepared statements for all SQL queries and the absence of dangerous functions or file operations are positive indicators of secure coding practices. The limited external HTTP request and lack of critical or high severity taint flows also contribute to its good security standing. The plugin's vulnerability history is clean, with no recorded CVEs, suggesting a well-maintained codebase over time. However, the relatively low percentage of properly escaped output (71%) represents a potential weakness, as unescaped output can lead to Cross-Site Scripting (XSS) vulnerabilities. While the current analysis doesn't reveal specific instances, this area warrants attention for future development or auditing. The complete absence of nonce and capability checks across all entry points is a significant concern, as it leaves the plugin vulnerable to unauthorized actions if any new entry points are introduced or if existing, undocumented ones are discovered.
Key Concerns
- Missing nonce checks on all entry points
- Missing capability checks on all entry points
- Significant portion of output not properly escaped
User Login Notifier for WordPress Security Vulnerabilities
User Login Notifier for WordPress Release Timeline
User Login Notifier for WordPress Code Analysis
Output Escaping
User Login Notifier for WordPress Attack Surface
WordPress Hooks 8
Maintenance & Trust
User Login Notifier for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
User Login Notifier for WordPress Alternatives
TW Login Alert & Tracker
tw-login-alert-tracker
Track who logs in and when — and receive instant email alerts for every login event.
Secure Dashboard Login Notifier
secure-dashboard-login-notifier
Notify the main admin when any user logs in to the dashboard. Track logins, and securely manage users with logout/delete options.
When Last Login
when-last-login
Show a users last login date by creating a sortable column in your WordPress users list.
Username Changer
username-changer
Unlock the power to change WordPress usernames with complete security and data integrity.
Login as User
login-as-user
Login as User is a free WordPress plugin that helps admins switch user accounts instantly to check data.
User Login Notifier for WordPress Developer Profile
15 plugins · 15K total installs
How We Detect User Login Notifier for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-user-login-notifier/notifier/css/style.css/wp-content/plugins/wp-user-login-notifier/admin/css/admin.css/wp-content/plugins/wp-user-login-notifier/admin/js/admin.js/wp-content/plugins/wp-user-login-notifier/admin/options-buddy/core/_inc/uploader.js/wp-content/plugins/wp-user-login-notifier/admin/js/admin.js/wp-content/plugins/wp-user-login-notifier/admin/options-buddy/core/_inc/uploader.jswp-user-login-notifier/notifier/css/style.css?ver=wp-user-login-notifier/admin/css/admin.css?ver=wp-user-login-notifier/admin/js/admin.js?ver=wp-user-login-notifier/admin/options-buddy/core/_inc/uploader.js?ver=HTML / DOM Fingerprints
buddydev-wpuln-settingsdata-buddydev-wpuln-settingsOptionsBuddy_Helper