WPSPX Login Security & Risk Analysis

wordpress.org/plugins/wpspx-login

This add-on enables the login model for the WPSPX plugin

0 active installs v1.0.3 PHP 7.0+ WP 4.3+ Updated Unknown
apibookingspektrixtheatretickets
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WPSPX Login Safe to Use in 2026?

Generally Safe

Score 100/100

WPSPX Login has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "wpspx-login" plugin v1.0.3 exhibits a seemingly strong security posture based on the provided static analysis. The absence of any identified dangerous functions, SQL queries without prepared statements, unescaped output, file operations, external HTTP requests, or vulnerabilities in the history is highly commendable. The plugin also correctly implements nonce and capability checks, indicating a good understanding of WordPress security best practices.

However, the analysis also reveals a complete lack of any identified attack surface. With zero AJAX handlers, REST API routes, shortcodes, or cron events, it's unclear what functionality this plugin provides or how it integrates with WordPress. This lack of discernible entry points, while superficially secure, could indicate a very limited scope of functionality or, conversely, a potential for hidden or improperly exposed functionality that wasn't detected. The absence of any taint analysis results also suggests either a very small codebase or a lack of comprehensive analysis.

Given the clean bill of health from the static analysis and vulnerability history, the plugin appears secure for the functionality it exposes. The primary concern stems from the minimal attack surface, which makes it difficult to fully assess its security without understanding its intended purpose and integration points. As it stands, the plugin's reported security is excellent, but the lack of exposed functionality raises questions.

Vulnerabilities
None known

WPSPX Login Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

WPSPX Login Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

WPSPX Login Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionwp_enqueue_scriptswp-spektrix-login.php:49
actionadmin_enqueue_scriptswp-spektrix-login.php:50
Maintenance & Trust

WPSPX Login Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedUnknown
PHP min version7.0
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

WPSPX Login Developer Profile

Martin Greenwood

3 plugins · 10 total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WPSPX Login

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wpspx-login/lib/assets/css/wpspx-login.css/wp-content/plugins/wpspx-login/lib/assets/js/wpspx-login-model.js/wp-content/plugins/wpspx-login/lib/assets/js/wpspx-login-min.js
Script Paths
/wp-content/plugins/wpspx-login/lib/assets/js/wpspx-login-model.js/wp-content/plugins/wpspx-login/lib/assets/js/wpspx-login-min.js
Version Parameters
wpspx-login/lib/assets/css/wpspx-login.css?ver=

HTML / DOM Fingerprints

CSS Classes
wpspx-login-widget
HTML Comments
<!-- WPSPX Login Widget -->
FAQ

Frequently Asked Questions about WPSPX Login