IndieAuth

Explore IndieAuth vulnerabilities across all versions. Currently tracking 1 known vulnerabilities, including severity, impact, and patch status.

Strategic Overview

Avg CVSSHigh
8.8/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all IndieAuth vulnerabilities before they are exploited.

Vulnerability Records

1 records
IndieAuth banner
Latestv4.7.1
5.0(4)
100/100
Last Updated
2026-07-14 (16d ago)
Active Installs
400+
Downloads
32,897
Requires WP
6.2+
Requires PHP
7.4+
Tested up to
WP 7.0.2
Created
2013-09-16 (13y ago)

The plugin turns WordPress into an IndieAuth endpoint. This can be used to act as an authentication mechanism for WordPress and its REST API, as well as an identity mechanism for other sites. It uses the URL from the profile page to identify the blog user or your author url. We recommend your site be served over https to use this. You can also install this plugin to enable web sign-in for your site using your domain.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C