
WPMS Sidebar Login Widget Security & Risk Analysis
wordpress.org/plugins/wpms-sidebar-login-widgetAdds a sidebar widget to the main site of a WPMU/WPMS install.
Is WPMS Sidebar Login Widget Safe to Use in 2026?
Generally Safe
Score 85/100WPMS Sidebar Login Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'wpms-sidebar-login-widget' v1.9.4 exhibits a mixed security posture. While the static analysis reveals no direct entry points like AJAX handlers, REST API routes, or shortcodes that are unprotected, and there's a complete absence of known vulnerabilities, several concerning code signals warrant attention. The presence of two instances of `preg_replace` with the `/e` modifier is a significant red flag, as this function can be exploited for remote code execution if not handled with extreme care and sanitization. Furthermore, all SQL queries are executed without prepared statements, increasing the risk of SQL injection vulnerabilities. The lack of proper output escaping for all identified outputs means that any user-supplied data that is displayed could be vulnerable to cross-site scripting (XSS) attacks.
Despite the lack of a large attack surface and a clean vulnerability history, the internal code quality indicates potential weaknesses. The heavy reliance on raw SQL queries and the complete absence of output escaping are serious concerns that could be exploited by an attacker, even without obvious external entry points. The absence of taint flows with unsanitized paths is positive, but it does not negate the risks posed by the dangerous function usage and insecure database interactions. Therefore, while the plugin appears to be free of known exploits and has a clean history, the internal code's insecurity is a notable weakness that needs to be addressed.
Key Concerns
- Dangerous function preg_replace(/e) found
- Raw SQL queries without prepared statements
- No output escaping detected
- No nonce checks
WPMS Sidebar Login Widget Security Vulnerabilities
WPMS Sidebar Login Widget Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
WPMS Sidebar Login Widget Attack Surface
WordPress Hooks 14
Maintenance & Trust
WPMS Sidebar Login Widget Maintenance & Trust
Maintenance Signals
Community Trust
WPMS Sidebar Login Widget Alternatives
WPMS Site Maintenance Mode
wpms-site-maintenance-mode
Provides an interface to make a WPMS network unavailable to everyone during maintenance, except the admin.
Limit Blogs Per User
limit-blogs-per-user
This plugin is for WordPress Multisite and/or WordPress Multisite+buddypress based social network.It limits the number of blogs a user can create.
Multisite Dashboard Broadcast
multisite-dashboard-broadcast
Place a widget on top of every site's dashboard under the same Multisite installation, containing whatever content the Super Admin writes.
My Sites Widget
my-sites-widget
A widget that displays a list of sites that the current user has access to.
WP aMember Dashboard Widget
wp-amember-dashboard-widget
Adds aMember account info to your WP/WPMU/WPMS dashboard. Users will be able to have some of their payment account info in their dashboard.
WPMS Sidebar Login Widget Developer Profile
5 plugins · 130 total installs
How We Detect WPMS Sidebar Login Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpms-sidebar-login-widget/wpms_login_widget.css/wpms-sidebar-login-widget/wpms_login_widget.css?ver=HTML / DOM Fingerprints
wpms_login_widget<!-- Custom Sidebar Login CSS : http://www.7mediaws.org/ --><!-- If you are good at CSS, you can style the login widget. --><!-- This is a comment. Comments begin with /* and end with */<!-- Below is example css; uncomment to see how the avatar is affected. -->+21 moreid="wp_sidebarlogin-4"