Are oAuth login plugins that match on e-mail accounts really secure?

Standard

I’ve been playing with the oneall social login plugin for WordPress, to ensure it works well with WP-United. So far it seems to be excellent… but…

By default, the plugin’s settings are such that, after you’ve created an account via a social network login, it tries to link your login to an account that already exists on your site.

This sounds like a nice idea… it means that you don’t end up with two accounts. However, it does this by matching to existing accounts on your e-mail address. And it does it silently — if it finds a match, it doesn’t ask for a password for the existing account.
Continue reading