
WPS Limit Login Security & Risk Analysis
wordpress.org/plugins/wps-limit-loginWPS Limit login limit connection attempts by IP address
Is WPS Limit Login Safe to Use in 2026?
Generally Safe
Score 96/100WPS Limit Login has a strong security track record. Known vulnerabilities have been patched promptly.
The wps-limit-login plugin v1.5.9.2 presents a mixed security posture. While the static analysis indicates a small attack surface with no immediate unprotected entry points and a reasonable number of capability and nonce checks for its AJAX handlers, several concerns arise from the code analysis and historical vulnerability data. The significant percentage of improperly escaped output (74%) is a major red flag, suggesting a high risk of Cross-Site Scripting (XSS) vulnerabilities. Furthermore, all SQL queries lack prepared statements, which can lead to SQL injection vulnerabilities, especially when combined with potentially unsanitized input. The single taint flow with an unsanitized path, although not classified as critical or high, warrants attention as it could represent a localized security weakness. The plugin's history of three documented CVEs, including one critical and two high-severity vulnerabilities, particularly related to XSS, excessive authentication attempts, and CSRF, indicates a past struggle with robust security implementation. The last vulnerability being in 2019 also suggests potential stagnation in security updates. While the lack of critical taint flows in the current analysis and the presence of some security checks are positive, the high rate of unescaped output and the historical vulnerability pattern, coupled with raw SQL queries, indicate a substantial risk that needs careful consideration and mitigation.
Key Concerns
- High percentage of unescaped output
- All SQL queries lack prepared statements
- Taint flow with unsanitized path
- History of 1 critical CVE
- History of 2 high CVEs
WPS Limit Login Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
WPS Limit Login < 1.4.6.1 - Stored Cross-Site Scripting
WPS Limit Login < 1.4.6.1 - Authorization Bypass via IP Spoofing
WPS Limit Login < 1.4.6.1 - Cross-Site Request Forgery
WPS Limit Login Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WPS Limit Login Attack Surface
AJAX Handlers 2
WordPress Hooks 24
Maintenance & Trust
WPS Limit Login Maintenance & Trust
Maintenance Signals
Community Trust
WPS Limit Login Alternatives
Titan Anti-spam & Security
anti-spam
Block spam comments, defend against login attempts, and strengthen site security with anti-spam, brute-force protection, and two-factor authentication …
GhostGate
ghostgate
Invisible, intelligent protection for WordPress. GhostGate hides your login page, blocks bots, and turns your site into a ghost fortress.
Orbisius Limit Logins
orbisius-limit-logins
Protect your site from automated logins efficiently!
All-In-One Security (AIOS) – Security and Firewall
all-in-one-wp-security-and-firewall
Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plugin designed especially for WordPress.
Limit Login Attempts
limit-login-attempts
Limit rate of login attempts, including by way of cookies, for each IP. Fully customizable.
WPS Limit Login Developer Profile
9 plugins · 149K total installs
How We Detect WPS Limit Login
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wps-limit-login/assets/css/wps-limit-login.css/wp-content/plugins/wps-limit-login/assets/js/wps-limit-login.js/wp-content/plugins/wps-limit-login/assets/js/wps-limit-login.jswps-limit-login/assets/css/wps-limit-login.css?ver=wps-limit-login/assets/js/wps-limit-login.js?ver=HTML / DOM Fingerprints
wps-limit-login-admin-notice<!-- WPS Limit Login --><!-- WPS Limit Login : DO NOT MODIFY THIS FILE -->data-wps-limit-login-optionswpsLimitLoginOptions