Zodan One-time Login Link Security & Risk Analysis

wordpress.org/plugins/zodan-one-time-login-link

Allow users to securely log in once without a password.

0 active installs v0.0.10 PHP + WP 5.5+ Updated Jan 18, 2026
developmentdirect-loginfast-loginno-passwordtheme-development
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Zodan One-time Login Link Safe to Use in 2026?

Generally Safe

Score 100/100

Zodan One-time Login Link has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "zodan-one-time-login-link" plugin v0.0.10 exhibits a strong security posture based on the provided static analysis. The absence of direct entry points like AJAX handlers, REST API routes, and shortcodes, along with a complete lack of unprotected entry points, significantly reduces its attack surface. The code also demonstrates good security practices by exclusively using prepared statements for SQL queries and by implementing nonce and capability checks where appropriate. Furthermore, a high percentage of output escaping indicates a good effort to prevent cross-site scripting vulnerabilities. The clean vulnerability history with no recorded CVEs further supports a positive security assessment.

However, it is important to note that the analysis did not reveal any taint flows, which doesn't necessarily mean they don't exist, but rather that none were identified by the analysis tools. The fact that 17% of outputs are not properly escaped, while not critical, represents a potential weakness that could be exploited in specific scenarios. The presence of cron events, while not directly indicating a vulnerability, does represent background processes that should be reviewed for any potential logic flaws. Overall, the plugin appears to be developed with security in mind, but the minor unescaped output issue warrants attention.

Key Concerns

  • Outputs not properly escaped
Vulnerabilities
None known

Zodan One-time Login Link Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Zodan One-time Login Link Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
13
63 escaped
Nonce Checks
4
Capability Checks
4
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

83% escaped76 total outputs
Attack Surface

Zodan One-time Login Link Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 23
actionadmin_initadmin.php:19
actionadmin_menuadmin.php:419
filteradmin_footer_textadmin.php:424
actionplugins_loadedzodan-one-time-login-link.php:43
actionlogin_enqueue_scriptszodan-one-time-login-link.php:93
actionlogin_enqueue_scriptszodan-one-time-login-link.php:94
actionlogin_form_zodanloginoncezodan-one-time-login-link.php:95
actioninitzodan-one-time-login-link.php:100
actionzodanloginonce_process_batchzodan-one-time-login-link.php:105
actioninitzodan-one-time-login-link.php:111
filteruser_row_actionszodan-one-time-login-link.php:121
actionadmin_initzodan-one-time-login-link.php:126
actionadmin_initzodan-one-time-login-link.php:127
actionadmin_initzodan-one-time-login-link.php:128
filterbulk_actions-userszodan-one-time-login-link.php:133
filterhandle_bulk_actions-userszodan-one-time-login-link.php:134
actionadmin_noticeszodan-one-time-login-link.php:139
actionadmin_enqueue_scriptszodan-one-time-login-link.php:144
actionadmin_enqueue_scriptszodan-one-time-login-link.php:145
actionadmin_noticeszodan-one-time-login-link.php:150
actionadmin_noticeszodan-one-time-login-link.php:155
actionadmin_noticeszodan-one-time-login-link.php:173
actionadmin_noticeszodan-one-time-login-link.php:207

Scheduled Events 3

zodanloginonce_process_batch
zodanloginonce_process_batch
zodanloginonce_process_batch
Maintenance & Trust

Zodan One-time Login Link Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 18, 2026
PHP min version
Downloads203

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Zodan One-time Login Link Developer Profile

martenmoolenaar

6 plugins · 80 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Zodan One-time Login Link

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/zodan-one-time-login-link/js/zodan-onetime-login-link-login.js/wp-content/plugins/zodan-one-time-login-link/css/zodan-onetime-login-link-login.css/wp-content/plugins/zodan-one-time-login-link/js/zodan-onetime-login-link-admin.js/wp-content/plugins/zodan-one-time-login-link/css/zodan-onetime-login-link-admin.css/wp-content/plugins/zodan-one-time-login-link/js/zodan-onetime-login-link-bulk-confirm.js
Script Paths
/wp-content/plugins/zodan-one-time-login-link/js/zodan-onetime-login-link-login.js/wp-content/plugins/zodan-one-time-login-link/js/zodan-onetime-login-link-admin.js/wp-content/plugins/zodan-one-time-login-link/js/zodan-onetime-login-link-bulk-confirm.js
Version Parameters
zodan-one-time-login-link/js/zodan-onetime-login-link-login.js?ver=zodan-one-time-login-link/css/zodan-onetime-login-link-login.css?ver=zodan-one-time-login-link/js/zodan-onetime-login-link-admin.js?ver=zodan-one-time-login-link/css/zodan-onetime-login-link-admin.css?ver=zodan-one-time-login-link/js/zodan-onetime-login-link-bulk-confirm.js?ver=

HTML / DOM Fingerprints

CSS Classes
zodan-login-once-formzodan-login-once-inputzodan-request-link-buttonzodan-onetime-login-link-admin-notice
HTML Comments
<!-- Zodan One-time Login Link plugin by Zodan -->
Data Attributes
data-plugin-version="0.0.10"
JS Globals
zodanOnetimeLoginLink
FAQ

Frequently Asked Questions about Zodan One-time Login Link