User Login Notifier for WordPress Security & Risk Analysis

wordpress.org/plugins/wp-user-login-notifier

User Login Notifier plugin notifies WordPress site admin and users of the successful and failed login attempts via email.

1K active installs v1.0.7 PHP + WP 5.0+ Updated Sep 23, 2025
admin-notificationfailed-loginloginlogin-notificationuser
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is User Login Notifier for WordPress Safe to Use in 2026?

Generally Safe

Score 100/100

User Login Notifier for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7mo ago
Risk Assessment

The wp-user-login-notifier v1.0.7 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of identified AJAX handlers, REST API routes, shortcodes, and cron events, particularly those lacking authentication, indicates a minimal attack surface. Furthermore, the code's reliance on prepared statements for all SQL queries and the absence of dangerous functions or file operations are positive indicators of secure coding practices. The limited external HTTP request and lack of critical or high severity taint flows also contribute to its good security standing. The plugin's vulnerability history is clean, with no recorded CVEs, suggesting a well-maintained codebase over time. However, the relatively low percentage of properly escaped output (71%) represents a potential weakness, as unescaped output can lead to Cross-Site Scripting (XSS) vulnerabilities. While the current analysis doesn't reveal specific instances, this area warrants attention for future development or auditing. The complete absence of nonce and capability checks across all entry points is a significant concern, as it leaves the plugin vulnerable to unauthorized actions if any new entry points are introduced or if existing, undocumented ones are discovered.

Key Concerns

  • Missing nonce checks on all entry points
  • Missing capability checks on all entry points
  • Significant portion of output not properly escaped
Vulnerabilities
None known

User Login Notifier for WordPress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

User Login Notifier for WordPress Release Timeline

v1.0.7Current
v1.0.6
v1.0.5
v1.0.4
v1.0.3
v1.0.2
v1.0.1
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

User Login Notifier for WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
13
32 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

71% escaped45 total outputs
Attack Surface

User Login Notifier for WordPress Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_initadmin\admin.php:37
actionadmin_menuadmin\admin.php:38
actionadmin_footeradmin\admin.php:39
actionadmin_enqueue_scriptsadmin\options-buddy\core\class-ob-helper.php:54
actionwp_login_failednotifier\class-user-login-notifier.php:96
actionwp_loginnotifier\class-user-login-notifier.php:97
actioninitwp-user-login-notifier.php:51
actioninitwp-user-login-notifier.php:52
Maintenance & Trust

User Login Notifier for WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 23, 2025
PHP min version
Downloads25K

Community Trust

Rating84/100
Number of ratings5
Active installs1K
Developer Profile

User Login Notifier for WordPress Developer Profile

BuddyDev

15 plugins · 15K total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
17 days
View full developer profile
Detection Fingerprints

How We Detect User Login Notifier for WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-user-login-notifier/notifier/css/style.css/wp-content/plugins/wp-user-login-notifier/admin/css/admin.css/wp-content/plugins/wp-user-login-notifier/admin/js/admin.js/wp-content/plugins/wp-user-login-notifier/admin/options-buddy/core/_inc/uploader.js
Script Paths
/wp-content/plugins/wp-user-login-notifier/admin/js/admin.js/wp-content/plugins/wp-user-login-notifier/admin/options-buddy/core/_inc/uploader.js
Version Parameters
wp-user-login-notifier/notifier/css/style.css?ver=wp-user-login-notifier/admin/css/admin.css?ver=wp-user-login-notifier/admin/js/admin.js?ver=wp-user-login-notifier/admin/options-buddy/core/_inc/uploader.js?ver=

HTML / DOM Fingerprints

CSS Classes
buddydev-wpuln-settings
Data Attributes
data-buddydev-wpuln-settings
JS Globals
OptionsBuddy_Helper
FAQ

Frequently Asked Questions about User Login Notifier for WordPress