AE Admin Customizer Security & Risk Analysis

wordpress.org/plugins/ae-admin-customizer

Now you can customize the Login/Registration Page with Live Preview using wordpress Customizer feature.

10 active installs v1.0.7 PHP + WP 4.5+ Updated Unknown
brandingcustomizationloginregistrationwp-admin
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is AE Admin Customizer Safe to Use in 2026?

Generally Safe

Score 100/100

AE Admin Customizer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "ae-admin-customizer" plugin v1.0.7 presents a generally good security posture, with a strong emphasis on secure coding practices. The absence of any known CVEs, dangerous functions, or external HTTP requests is commendable. The plugin also demonstrates a commitment to secure data handling by exclusively using prepared statements for all SQL queries. However, a significant concern arises from the static analysis indicating that only 44% of output is properly escaped. This weakness creates a potential vulnerability for Cross-Site Scripting (XSS) attacks, as unsanitized output could be injected into the user interface. While the plugin has zero critical or high severity taint flows, and the single unsanitized path flow is not deemed critical, the general lack of comprehensive output sanitization remains a notable risk. The plugin's vulnerability history is clean, which, coupled with its current secure coding practices, suggests a responsible development approach. Nevertheless, the unescaped output issue requires immediate attention to solidify its security.

Key Concerns

  • Low percentage of properly escaped output
Vulnerabilities
None known

AE Admin Customizer Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

AE Admin Customizer Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
89
69 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

44% escaped158 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
ae_admin_import_export (inc\ae-admin-customizer-settings-class.php:163)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

AE Admin Customizer Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 27
actionplugins_loadedae-admin-customizer.php:62
actionadmin_enqueue_scriptsinc\ae-admin-customizer-settings-class.php:16
actionwp_enqueue_scriptsinc\ae-admin-customizer-settings-class.php:17
actionadmin_menuinc\ae-admin-customizer-settings-class.php:18
actionadmin_initinc\classes\admin-panel-styling-class.php:13
actionadmin_headinc\classes\admin-panel-styling-class.php:14
actionwp_headinc\classes\admin-panel-styling-class.php:18
actionadmin_initinc\classes\custom-css-class.php:14
actionadmin_initinc\classes\general-settings-class.php:13
actionadmin_bar_menuinc\classes\general-settings-class.php:16
filterupdate_footerinc\classes\general-settings-class.php:19
filteradmin_footer_textinc\classes\general-settings-class.php:20
filtercontextual_helpinc\classes\general-settings-class.php:23
filterscreen_options_show_screeninc\classes\general-settings-class.php:24
actionwp_dashboard_setupinc\classes\general-settings-class.php:27
actionwp_dashboard_setupinc\classes\general-settings-class.php:30
filterstyle_loader_srcinc\classes\general-settings-class.php:33
filterscript_loader_srcinc\classes\general-settings-class.php:34
filterthe_generatorinc\classes\general-settings-class.php:37
actionadmin_bar_menuinc\classes\general-settings-class.php:361
actioncustomize_registerinc\classes\live-login-registration-customizer.php:13
actionlogin_headinc\classes\live-login-registration-customizer.php:15
actionadmin_initinc\classes\login-registration-styling-class.php:13
actionlogin_enqueue_scriptsinc\classes\login-registration-styling-class.php:14
actionlogin_headinc\classes\login-registration-styling-class.php:15
filterlogin_headerurlinc\classes\login-registration-styling-class.php:16
filterlogin_headertitleinc\classes\login-registration-styling-class.php:17
Maintenance & Trust

AE Admin Customizer Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedUnknown
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

AE Admin Customizer Developer Profile

allan.empalmado

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect AE Admin Customizer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ae-admin-customizer/assets/css/style.css/wp-content/plugins/ae-admin-customizer/assets/js/ae-admin-customizer.js
Script Paths
/wp-content/plugins/ae-admin-customizer/assets/js/ae-admin-customizer.js
Version Parameters
ae-admin-customizer/assets/css/style.css?ver=ae-admin-customizer/assets/js/ae-admin-customizer.js?ver=

HTML / DOM Fingerprints

CSS Classes
ae-admin-customizer-general-settings-wrapperae-table-cellae-admin-customizer-login-registration-styling-wrapperae-admin-customizer-custom-css-wrapper
Data Attributes
data-ae-admin-customizer-login-urldata-ae-admin-customizer-logo-urldata-ae-admin-customizer-logo-widthdata-ae-admin-customizer-logo-height
JS Globals
AE_Admin_Customizer_Admin_Panel_StylingAE_Admin_Customizer_Live_Login_RegistrationAE_Admin_Customizer_Custom_CSSAE_Admin_Customizer_General_Settings
FAQ

Frequently Asked Questions about AE Admin Customizer