OneLogin SAML SSO

onelogin-saml-sso · by sixtomartin · wordpress.org ↗ · SVN ↗
Active installs
7k+
Current version
3.6.0
Added
2011-01-10
Last updated
2026-07-01 (1d ago)
First seen by beacon
2mo ago
Total downloads
202,539

Statistics

2024-06-17 → 2026-07-01 · 745 days
Downloads today
334
7-day total 804
Week over week
▲ +68%
vs prior 7 days
30-day trend
flat
▲ +21% MoM
Abandonment
●○○○○
install base on one version
Downloads/day Linear trend
3342511678402024-062024-102025-022025-062025-102026-022026-07
3342511678402026-042026-042026-052026-052026-062026-06
3342511678402026-062026-062026-062026-062026-062026-06

Active versions

3.4
3.4 · 94.4%other · 5.6%

Ratings

5★
11
4★
0
3★
0
2★
0
1★
2

Support: 0/0 resolved

Alerts (0)

No open alerts.

Show 1 resolved alert
Medium code_scan_delta Resolved · fp_base64_saml_encoding 2026-07-02 03:54:23 (1d ago)
Slugonelogin-saml-sso
Previous version3.4.0
Current version3.6.0
New findings
PatternKindFileLineSnippetConfidence
base64_decodebuiltinphp/lib/Saml2/Auth.php142$inResponseTo = OneLogin_Saml2_LogoutRequest::getID(gzinflate(base64_decode($_GET['SAMLRequest'])));medium
gzinflatebuiltinphp/lib/Saml2/Auth.php142$inResponseTo = OneLogin_Saml2_LogoutRequest::getID(gzinflate(base64_decode($_GET['SAMLRequest'])));medium
base64_decodebuiltinphp/lib/Saml2/LogoutResponse.php174if (!$objKey->verifySignature($signedQuery, base64_decode($_GET['Signature']))) {medium
base64_decodebuiltinphp/lib/Saml2/LogoutRequest.php330if (!$objKey->verifySignature($signedQuery, base64_decode($_GET['Signature']))) {medium
New finding count4
View raw JSON
{
    "slug": "onelogin-saml-sso",
    "previous_version": "3.4.0",
    "current_version": "3.6.0",
    "new_findings": [
        {
            "pattern": "base64_decode",
            "kind": "builtin",
            "file": "php/lib/Saml2/Auth.php",
            "line": 142,
            "snippet": "$inResponseTo = OneLogin_Saml2_LogoutRequest::getID(gzinflate(base64_decode($_GET['SAMLRequest'])));",
            "confidence": "medium"
        },
        {
            "pattern": "gzinflate",
            "kind": "builtin",
            "file": "php/lib/Saml2/Auth.php",
            "line": 142,
            "snippet": "$inResponseTo = OneLogin_Saml2_LogoutRequest::getID(gzinflate(base64_decode($_GET['SAMLRequest'])));",
            "confidence": "medium"
        },
        {
            "pattern": "base64_decode",
            "kind": "builtin",
            "file": "php/lib/Saml2/LogoutResponse.php",
            "line": 174,
            "snippet": "if (!$objKey->verifySignature($signedQuery, base64_decode($_GET['Signature']))) {",
            "confidence": "medium"
        },
        {
            "pattern": "base64_decode",
            "kind": "builtin",
            "file": "php/lib/Saml2/LogoutRequest.php",
            "line": 330,
            "snippet": "if (!$objKey->verifySignature($signedQuery, base64_decode($_GET['Signature']))) {",
            "confidence": "medium"
        }
    ],
    "new_finding_count": 4
}

SVN committers (3)

Accounts with actual commit access to onelogin-saml-sso on plugins.svn.wordpress.org, reconstructed from svn log. This is the list that matters for ownership changes — not the readme contributors.

Committer Member since Commits First commit Latest commit
onelogin 2010-05-08 54 2011-01-10 · r331008 2021-01-13 · r2455811
sixtomartin 2013-04-14 2 2022-02-04 · r2673178 2025-12-09 · r3415854
plugin-master 2007-03-09 1 2011-01-10 · r330701 2011-01-10 · r330701

Readme contributors (2)

Names the plugin's readme declares as contributors. A soft signal — anyone can be listed. The SVN access column is the ground-truth cross-reference: does this contributor actually commit code?

Contributor Member since SVN access Status
onelogin 2010-05-08 54 commits Active
sixtomartin 2013-04-14 2 commits Active

Versions (3 most recent)

Version Released Download
2.1.5 2014-10-14 · 11y ago zip
2.0.2b 2014-10-14 · 11y ago zip
1.0.1 2014-08-13 · 11y ago zip