
WP Users Login History Security & Risk Analysis
wordpress.org/plugins/wp-users-login-historyTrack website's users by their login related information like Last login Date/Time, Environment/Server IP address,Country/City/Continent/Timezone …
Is WP Users Login History Safe to Use in 2026?
Generally Safe
Score 92/100WP Users Login History has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-users-login-history plugin version 1.2 presents a moderate security risk primarily due to its unprotected AJAX endpoints. While the plugin exhibits good practices like using prepared statements for SQL queries and avoiding dangerous functions, the lack of authentication checks on all four of its AJAX handlers creates a significant attack surface. This means that any user, potentially even unauthenticated ones, could trigger these handlers, leading to unintended actions or information disclosure if vulnerabilities exist within them. The taint analysis did identify one flow with an unsanitized path, which, while not classified as critical or high severity in this analysis, warrants further investigation in conjunction with the unprotected AJAX endpoints. The absence of any recorded vulnerability history suggests a generally stable past, but this should not overshadow the immediate concerns raised by the static analysis. Overall, while the plugin has some positive security attributes, the unprotected AJAX endpoints represent a critical weakness that needs to be addressed.
Key Concerns
- AJAX handlers without auth checks
- Unsanitized path in taint flow
- Outputs not properly escaped
- File operations without detailed context
WP Users Login History Security Vulnerabilities
WP Users Login History Code Analysis
Output Escaping
Data Flow Analysis
WP Users Login History Attack Surface
AJAX Handlers 4
WordPress Hooks 14
Maintenance & Trust
WP Users Login History Maintenance & Trust
Maintenance Signals
Community Trust
WP Users Login History Alternatives
When Last Login
when-last-login
Show a users last login date by creating a sortable column in your WordPress users list.
Change WordPress Login Logo
change-login-logo
Upload your logo for WordPress login page instead of the usual WordPress logo with simple settings.
WP Custom Login
bm-custom-login
Customize the WordPress login screen with your own colors, logo, backgrounds, and form styles.
FluentAuth – The Ultimate Authorization & Security Plugin for WordPress
fluent-security
Enhance the Security and User Experience of Your Site with Login/Signup Security, Two-Factor Email Authentication, Social Logins and more...
My WordPress Login Logo
my-wp-login-logo
My WordPress Login Logo lets you to add a custom logo in your wordpress login page instead of the usual wordpress logo and customize your login page.
WP Users Login History Developer Profile
11 plugins · 580 total installs
How We Detect WP Users Login History
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-users-login-history/admin/css/wp-users-login-history-admin.css/wp-content/plugins/wp-users-login-history/admin/js/wp-users-login-history-admin.js/wp-content/plugins/wp-users-login-history/admin/js/wp-users-login-history-admin.jswp-users-login-history-admin.css?ver=wp-users-login-history-admin.js?ver=HTML / DOM Fingerprints
user-login-history-title-wrapdata-wpulh-idwpulh_ajax_object