Admin login URL Change Security & Risk Analysis

wordpress.org/plugins/admin-login-url-change

Allows you to Change your WordPress WebSite Login URL Slug.

1K active installs v1.1.5 PHP 5.3+ WP 4.7+ Updated Dec 21, 2025
change-wp-logincustom-loginloginremove-wp-loginwordpress-login
78
B · Generally Safe
CVEs total1
Unpatched1
Last CVEJan 20, 2026
Safety Verdict

Is Admin login URL Change Safe to Use in 2026?

Mostly Safe

Score 78/100

Admin login URL Change is generally safe to use. 1 past CVE were resolved. Keep it updated.

1 known CVE 1 unpatched Last CVE: Jan 20, 2026Updated 3mo ago
Risk Assessment

The "admin-login-url-change" plugin v1.1.5 exhibits a generally strong security posture based on the provided static analysis. It demonstrates excellent adherence to secure coding practices, with 100% of its outputs being properly escaped, all SQL queries utilizing prepared statements, and no file operations or external HTTP requests detected. The presence of nonce and capability checks on its sole AJAX entry point further reinforces its secure design. Taint analysis also reveals no critical or high-severity issues, indicating no immediate risks from unsanitized data flows.

However, the plugin is not without concern due to its vulnerability history. The presence of one known medium-severity CVE, which is currently unpatched, is a significant risk. The fact that this vulnerability is listed as "Missing Authorization" and its last reported date is in the future (2026-01-20) suggests a potential issue with the reporting or a forward-looking vulnerability disclosure that needs immediate attention. While the code itself appears robust, this unaddressed historical vulnerability represents a tangible threat.

In conclusion, the plugin's static code analysis paints a picture of a well-developed and secure component. The lack of detected vulnerabilities within the code's current state is commendable. Nevertheless, the existence of an unpatched medium-severity CVE, even if dated in the future, is a critical weakness that overshadows the otherwise positive static analysis findings and demands immediate remediation or a thorough investigation.

Key Concerns

  • Unpatched CVE present
  • Medium severity CVE
Vulnerabilities
1

Admin login URL Change Security Vulnerabilities

CVEs by Year

1 CVE in 2026 · unpatched
2026
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2026-24578medium · 4.3Missing Authorization

Admin login URL Change <= 1.1.5 - Missing Authorization

Jan 20, 2026Unpatched
Code Analysis
Analyzed Mar 16, 2026

Admin login URL Change Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
11 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped11 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
aluc_save_slug_ajax (includes\class-aluc-login-handler.php:127)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Admin login URL Change Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_aluc_save_slugincludes\class-aluc-login-handler.php:35
WordPress Hooks 19
actionplugins_loadedadmin-login-url-change.php:55
actionactivated_pluginadmin-login-url-change.php:56
actionadmin_menuincludes\class-aluc-login-handler.php:12
actionadmin_enqueue_scriptsincludes\class-aluc-login-handler.php:14
actioninitincludes\class-aluc-login-handler.php:16
filterlogin_redirectincludes\class-aluc-login-handler.php:17
filterwp_redirectincludes\class-aluc-login-handler.php:18
actioninitincludes\class-aluc-login-handler.php:20
filterquery_varsincludes\class-aluc-login-handler.php:21
actiontemplate_redirectincludes\class-aluc-login-handler.php:22
actionplugins_loadedincludes\class-aluc-login-handler.php:24
actionadmin_initincludes\class-aluc-login-handler.php:25
actioninitincludes\class-aluc-login-handler.php:26
actionwp_logoutincludes\class-aluc-login-handler.php:28
filterlogout_urlincludes\class-aluc-login-handler.php:29
filterlostpassword_urlincludes\class-aluc-login-handler.php:30
filterlogin_urlincludes\class-aluc-login-handler.php:31
filterrobots_txtincludes\class-aluc-login-handler.php:32
filterretrieve_password_messageincludes\class-aluc-login-handler.php:33
Maintenance & Trust

Admin login URL Change Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 21, 2025
PHP min version5.3
Downloads15K

Community Trust

Rating100/100
Number of ratings4
Active installs1K
Developer Profile

Admin login URL Change Developer Profile

Jahid Hasan

4 plugins · 11K total installs

91
trust score
Avg Security Score
95/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Admin login URL Change

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/admin-login-url-change/assets/images/jh-custom-service.png/wp-content/plugins/admin-login-url-change/assets/images/jh-mail.png

HTML / DOM Fingerprints

CSS Classes
wp-admin-change-titlejh-admin-setting-boxjh-admin-setting-formaluc-successaluc-erroradmin_url_noteswp-admin-change-boxjh-link-boxs+1 more
Data Attributes
data-id="aluc-new-login-url"
JS Globals
ALUC_PLUGIN_URL
FAQ

Frequently Asked Questions about Admin login URL Change