
AC Change Login Image Security & Risk Analysis
wordpress.org/plugins/ac-change-login-logoThis plugin changes the image in the login page (wp-login.php), you can choose any image from your gallery and use it as login logo.
Is AC Change Login Image Safe to Use in 2026?
Generally Safe
Score 92/100AC Change Login Image has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "ac-change-login-logo" plugin version 1.0.1 exhibits a generally good security posture based on the static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points is a significant strength, indicating a very limited attack surface. Furthermore, the code signals show no dangerous functions, no direct SQL queries (all are prepared), and no external HTTP requests, all of which are positive security indicators. However, a notable concern arises from the output escaping analysis, where only 56% of outputs are properly escaped. This suggests a potential for cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled with care before being displayed. The taint analysis revealing two flows with unsanitized paths, while not critical or high severity, further reinforces this concern, indicating that data might be flowing into potentially unsafe operations without adequate sanitization.
The plugin's vulnerability history is clean, with zero known CVEs. This is a strong positive, suggesting the developers have a good track record or the plugin's functionality is simple enough to avoid common vulnerabilities. The lack of historical vulnerabilities, combined with the limited attack surface, paints a picture of a plugin that, while functional, has a few specific areas requiring attention regarding output sanitization. In conclusion, the plugin is architecturally sound with a minimal attack surface and good practices in areas like SQL and external requests. The primary weakness lies in the incomplete output escaping and the identified unsanitized taint flows, which, although not yet exploited or leading to severe vulnerabilities, represent a clear risk of XSS or similar injection attacks. Addressing these output and sanitization issues would significantly bolster the plugin's security.
Key Concerns
- Insufficient output escaping
- Flows with unsanitized paths
AC Change Login Image Security Vulnerabilities
AC Change Login Image Code Analysis
Output Escaping
Data Flow Analysis
AC Change Login Image Attack Surface
WordPress Hooks 6
Maintenance & Trust
AC Change Login Image Maintenance & Trust
Maintenance Signals
Community Trust
AC Change Login Image Alternatives
Change WordPress Login Logo
change-login-logo
Upload your logo for WordPress login page instead of the usual WordPress logo with simple settings.
Custom Login
custom-login
Custom Login allows you to easily customize your admin login page, works great for client sites!
Uber Login Logo
uber-login-logo
A simple, lightweight WordPress plugin to change your login logo.
Add Logo to Admin
add-logo-to-admin
Add a custom logo to your wp-admin and login page.
Customize Login Image
customize-login-image
This plugin allows you to customize the image and the appearance of the WordPress Login Screen.
AC Change Login Image Developer Profile
1 plugin · 10 total installs
How We Detect AC Change Login Image
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ac-change-login-logo/ac-change-login-logo.phpHTML / DOM Fingerprints
image-preview-wrapperid="image-preview"id="upload_image_button"id="image_attachment_id"wp.media.frames.file_framewp.media.model.settings.post.id