Authentication WordPress Plugins with Most Issues

37 indexed plugins

Plugins

37

Active Installs

662k+

Average Score

54

Audited

37

RankPluginScoreErrorsWarningsInstallsAddedUpdatedTop Issue
#1WP-Members Membership Plugin2466938250k+Output is not escaped
#2Next Active Directory Integration236832842k+Exception output is not escaped
#3Keyring352332031k+Output is not escaped
#4Login by Auth0373078210k+Text Domain Mismatch
#5wpDirAuth32250135600wp function not compatible with requires wp
#6IP Based Login35179146600Output is not escaped
#7Sessions33196103900Output is not escaped
#8WP Cassify35106143800Missing nonce verification
#9WPS Limit Login3915276100k+Output is not escaped
#10Login for Google Apps271398510k+Exception output is not escaped
#11WP 2-step verification32154651k+Output is not escaped
#12Limit Login Attempts408138300k+Output is not escaped
#13Duo Two-Factor Authentication3744613k+Missing nonce verification
#14Google Authenticator41396520k+Output is not escaped
#15Simple LDAP Login3865331k+Output is not escaped
#16yubikey-plugin406433400Text Domain Mismatch
#17WP Limit Login Attempts39266710k+Direct Query
#18Two Factor421870100k+Nonce verification recommended
#19authLdap3647305k+Exception output is not escaped
#20Authorizer653545k+Nonce verification recommended
#21JSON API User5717341k+Non-prefixed hook name
#22Protect Login952619600Missing direct file access protection
#23Passwords Evolved4526171k+Output is not escaped
#24Easy Basic Authentication – Add basic auth to site or admin area461428600Input is not sanitized
#25Two Factor (2FA) Authentication via Email6112279k+Request data is not unslashed
#26WP SAML Auth767258k+Nonce verification recommended
#27Duo Universal806252k+Nonce verification recommended
#28Whitelist IP For Limit Login Attempts481812600Output is not escaped
#29HTTP Authentication35236600Output is not escaped
#30Log in with Google355176k+Non-prefixed global variable
#31Maestro Connector9774500Missing direct file access protection
#32HivePress Authentication98151k+Missing Version
#33WP Basic Authentication10032k+trademarked term
#34Active Directory Integration / LDAP Integration10024k+Non-prefixed constant
#35Logged-in-only1001700trademarked term
#36Firebase Authentication1000500No open findings
#37Shibboleth10003k+No open findings