
wpDirAuth Security & Risk Analysis
wordpress.org/plugins/wpdirauthWordPress directory authentication plugin through LDAP and LDAPS (SSL).
Is wpDirAuth Safe to Use in 2026?
Generally Safe
Score 85/100wpDirAuth has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wpdirauth" v1.10.7 plugin exhibits a mixed security posture. On the positive side, the plugin has a remarkably small attack surface with no exposed AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, there is no vulnerability history, suggesting a potentially stable and well-maintained codebase. However, the code analysis reveals significant concerns, including the use of dangerous functions like `unserialize` and `create_function`, and the absence of prepared statements for all SQL queries. The taint analysis shows one flow with unsanitized paths, which, while not classified as critical or high, still represents a potential risk. The lack of capability checks for any entry points, though the attack surface is zero, indicates a potential weakness if any new entry points are introduced in the future without proper authorization checks. The plugin has some strengths in its limited attack surface and clean vulnerability history, but the presence of dangerous functions and un-prepared SQL queries, along with the unsanitized taint flow, warrants caution.
Key Concerns
- Use of dangerous function: unserialize
- Use of dangerous function: create_function
- SQL queries not using prepared statements
- Taint flow with unsanitized paths
- No capability checks for entry points
- Output escaping not fully implemented
wpDirAuth Security Vulnerabilities
wpDirAuth Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
wpDirAuth Attack Surface
WordPress Hooks 16
Maintenance & Trust
wpDirAuth Maintenance & Trust
Maintenance Signals
Community Trust
wpDirAuth Alternatives
Simple LDAP Login
simple-ldap-login
Integrating WordPress with LDAP shouldn't be difficult. Now it isn't. Simple LDAP Login provides all of the features, none of the hassles.
Active Directory Authentication Integration
active-directory-authentication-integration
Allows WordPress to authenticate, authorize, create and update users through Active Directory
authLdap
authldap
Use your existing LDAP flexible as authentication backend for WordPress
Authorizer
authorizer
Authorizer limits login attempts, restricts access to specific users, and authenticates against external sources (OAuth2, Google, LDAP, or CAS).
Active Directory Integration / LDAP Integration
ldap-login-for-intranet-sites
Active Directory Integration/LDAP Integration enables login & sync in WordPress with Active Directory/LDAP Directory credentials, 24/7 ACTIVE SUPPORT
wpDirAuth Developer Profile
1 plugin · 600 total installs
How We Detect wpDirAuth
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpdirauth/css/wpdirauth-settings.css/wp-content/plugins/wpdirauth/css/wpdirauth.css/wp-content/plugins/wpdirauth/js/wpdirauth.js/wp-content/plugins/wpdirauth/js/wpdirauth.jswpdirauth/css/wpdirauth-settings.css?ver=wpdirauth/css/wpdirauth.css?ver=wpdirauth/js/wpdirauth.js?ver=HTML / DOM Fingerprints
wpdirauth-settingsSAFE MODESAFE MODE: wpDirAuth plugin configuration panel.data-wpdirauth-ajax-urlwpdirauth_ajax_object