
Admin login URL Change Security & Risk Analysis
wordpress.org/plugins/admin-login-url-changeAllows you to Change your WordPress WebSite Login URL Slug.
Is Admin login URL Change Safe to Use in 2026?
Mostly Safe
Score 78/100Admin login URL Change is generally safe to use. 1 past CVE were resolved. Keep it updated.
The "admin-login-url-change" plugin v1.1.5 exhibits a generally strong security posture based on the provided static analysis. It demonstrates excellent adherence to secure coding practices, with 100% of its outputs being properly escaped, all SQL queries utilizing prepared statements, and no file operations or external HTTP requests detected. The presence of nonce and capability checks on its sole AJAX entry point further reinforces its secure design. Taint analysis also reveals no critical or high-severity issues, indicating no immediate risks from unsanitized data flows.
However, the plugin is not without concern due to its vulnerability history. The presence of one known medium-severity CVE, which is currently unpatched, is a significant risk. The fact that this vulnerability is listed as "Missing Authorization" and its last reported date is in the future (2026-01-20) suggests a potential issue with the reporting or a forward-looking vulnerability disclosure that needs immediate attention. While the code itself appears robust, this unaddressed historical vulnerability represents a tangible threat.
In conclusion, the plugin's static code analysis paints a picture of a well-developed and secure component. The lack of detected vulnerabilities within the code's current state is commendable. Nevertheless, the existence of an unpatched medium-severity CVE, even if dated in the future, is a critical weakness that overshadows the otherwise positive static analysis findings and demands immediate remediation or a thorough investigation.
Key Concerns
- Unpatched CVE present
- Medium severity CVE
Admin login URL Change Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Admin login URL Change <= 1.1.5 - Missing Authorization
Admin login URL Change Code Analysis
Output Escaping
Data Flow Analysis
Admin login URL Change Attack Surface
AJAX Handlers 1
WordPress Hooks 19
Maintenance & Trust
Admin login URL Change Maintenance & Trust
Maintenance Signals
Community Trust
Admin login URL Change Alternatives
LoginPress | wp-login Custom Login Page Customizer
loginpress
LoginPress is a Custom Login Page Customizer plugin allows you to easily customize the layout of login, admin login, client login, register pages.
Custom Login Page Customizer – Login Designer
login-designer
Login Designer is the best way to style a custom login page for your WordPress login, register and forgot password forms, right from the live-action W …
Admin Custom Login
admin-custom-login
Customize Your WordPress Login Screen Amazingly - Add Own Logo, Add Social Profiles, Login Form Positions, Background Image Slide Show
Rename wp-admin login
rename-wp-admin-login
Rename wp-admin login* is a plugin that allows us to rename wp-admin login URL to anything you want
YITH Custom Login
yith-custom-login
YITH Custom Login give you the ability to customize the login page of wordpress.
Admin login URL Change Developer Profile
4 plugins · 11K total installs
How We Detect Admin login URL Change
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/admin-login-url-change/assets/images/jh-custom-service.png/wp-content/plugins/admin-login-url-change/assets/images/jh-mail.pngHTML / DOM Fingerprints
wp-admin-change-titlejh-admin-setting-boxjh-admin-setting-formaluc-successaluc-erroradmin_url_noteswp-admin-change-boxjh-link-boxs+1 moredata-id="aluc-new-login-url"ALUC_PLUGIN_URL