WP Telegram Login & Register Security & Risk Analysis

wordpress.org/plugins/wptelegram-login

Let your users login and register via Telegram, making it easier form them to get started on your website.

1K active installs v1.11.16 PHP 8.0+ WP 6.6+ Updated Feb 17, 2026
loginregistersignupsocialtelegram
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Telegram Login & Register Safe to Use in 2026?

Generally Safe

Score 100/100

WP Telegram Login & Register has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The wptelegram-login plugin, version 1.11.16, exhibits a generally good security posture due to its diligent use of prepared statements for SQL queries and a high percentage of properly escaped outputs. The absence of known CVEs and a clean vulnerability history further reinforces this positive impression, suggesting a well-maintained and secure codebase. However, the static analysis reveals a potential area of concern related to taint analysis. One flow with unsanitized paths was identified as high severity, indicating a possible vulnerability where user-supplied data might not be adequately validated or sanitized before being used in a sensitive operation. This warrants further investigation, as even a single high-severity taint flow can pose a significant risk to the application's security.

Key Concerns

  • High severity taint flow with unsanitized path
Vulnerabilities
None known

WP Telegram Login & Register Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP Telegram Login & Register Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
109 escaped
Nonce Checks
0
Capability Checks
7
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

94% escaped116 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<LoginHandler> (shared\LoginHandler.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

WP Telegram Login & Register Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[wptelegram-login] includes\Main.php:383
WordPress Hooks 31
actionplugins_loadedincludes\Main.php:175
actionplugins_loadedincludes\Main.php:178
actionadmin_menuincludes\Main.php:203
actionadmin_menuincludes\Main.php:204
actioninitincludes\Main.php:329
actionrest_api_initincludes\Main.php:343
actionrest_api_initincludes\Main.php:345
actionwidgets_initincludes\Main.php:347
actionshow_user_profileincludes\Main.php:350
actionedit_user_profileincludes\Main.php:351
filteruser_profile_update_errorsincludes\Main.php:352
actionpersonal_options_updateincludes\Main.php:353
actionedit_user_profile_updateincludes\Main.php:354
filtermanage_users_columnsincludes\Main.php:355
filtermanage_users_custom_columnincludes\Main.php:356
actionwoocommerce_edit_account_formincludes\Main.php:359
actionwoocommerce_save_account_details_errorsincludes\Main.php:360
actionwoocommerce_save_account_detailsincludes\Main.php:361
filterblock_categories_allincludes\Main.php:363
filterrest_user_collection_paramsincludes\Main.php:365
filterrest_user_queryincludes\Main.php:367
actionregister_formincludes\Main.php:380
actionlogin_formincludes\Main.php:381
filterrender_block_wptelegram/loginincludes\Main.php:385
filterget_avatar_urlincludes\Main.php:387
actioninitincludes\Main.php:398
actionadmin_enqueue_scriptsincludes\Main.php:400
actionenqueue_block_assetsincludes\Main.php:402
actionlogin_enqueue_scriptsincludes\Main.php:404
actionwp_enqueue_scriptsincludes\Main.php:406
actionadmin_menuincludes\Utils.php:43
Maintenance & Trust

WP Telegram Login & Register Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 17, 2026
PHP min version8.0
Downloads71K

Community Trust

Rating98/100
Number of ratings37
Active installs1K
Developer Profile

WP Telegram Login & Register Developer Profile

WP Socio

4 plugins · 35K total installs

93
trust score
Avg Security Score
99/100
Avg Patch Time
11 days
View full developer profile
Detection Fingerprints

How We Detect WP Telegram Login & Register

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wptelegram-login/assets/build/js/blocks.js/wp-content/plugins/wptelegram-login/assets/build/js/settings/index.js/wp-content/plugins/wptelegram-login/assets/build/js/wp-login/index.js/wp-content/plugins/wptelegram-login/assets/build/js/web-app-login/index.js/wp-content/plugins/wptelegram-login/assets/static/css/admin-menu.css
Script Paths
https://telegram.org/js/telegram-web-app.js
Version Parameters
wptelegram-login/assets/build/js/blocks.js?ver=wptelegram-login/assets/build/js/settings/index.js?ver=wptelegram-login/assets/build/js/wp-login/index.js?ver=wptelegram-login/assets/build/js/web-app-login/index.js?ver=wptelegram-login/assets/static/css/admin-menu.css?ver=

HTML / DOM Fingerprints

CSS Classes
wptelegram-login-settings-wrapper
HTML Comments
Currently plugin version.The code that runs during plugin activation.The code that runs during plugin deactivation.If this file is called directly, abort.+1 more
Data Attributes
data-wptelegram-login-form
JS Globals
WPTELEGRAM_LOGIN_VERWPTELEGRAM_LOGIN_MAIN_FILEWPTELEGRAM_LOGIN_BASENAMEWPTELEGRAM_LOGIN_DIRWPTELEGRAM_LOGIN_URLWPTELEGRAM_USER_ID_META_KEY+3 more
FAQ

Frequently Asked Questions about WP Telegram Login & Register