Update
hexafraction has found a major security flaw, he has registered and activated account with emailid field containing multiple fields separated by comma.
I will wait few more days for someone to report any more major bugs
I cant prove this. you need to try this. just register any gmail account and try. The thing is, that someone, who knows the googleplus email of the victim, can register with the same email of the googleplus account. and the database and information is same
I have checked the database you tried to register
test@test.com, but were not able to activate it because you don't own the email id. So even if you register no harm done. Real owner of
test@test.com can still login with his/her googleplus account
I tried with another email, a gmail.
I successfully registered, but also can login with google plus with that email without the website password. All the informations saved in that account is same as the normal Email account(Wallet-watcher)
Email
jcl051000@gmail.comYou need to try to register an gmail-Email. Then register an account with it on your website.
When you try to use Googleplus to login with that email, without even knowing the password of the website.