
Ajax BootModal Login Security & Risk Analysis
wordpress.org/plugins/ajax-bootmodal-loginAjax BootModal Login is a WordPress plugin that is powered by bootstrap and ajax for better login, registration or lost password.
Is Ajax BootModal Login Safe to Use in 2026?
Use With Caution
Score 64/100Ajax BootModal Login has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The ajax-bootmodal-login plugin v1.4.3 exhibits a mixed security posture. On the positive side, the static analysis reveals a lack of dangerous functions, no direct SQL injection vulnerabilities due to prepared statements, and no file operations or external HTTP requests, which are common attack vectors. The presence of nonce checks and the fact that all identified AJAX handlers and REST API routes are protected by authentication checks are strong indicators of good development practices in these areas. However, a significant concern is the extremely low percentage of properly escaped output (6%), indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. While taint analysis showed no specific flows, the unescaped output is a glaring weakness. Furthermore, the plugin has a history of vulnerabilities, with one currently unpatched medium severity CVE from 2018 (Protection Mechanism Failure), suggesting potential recurring issues or a lack of ongoing maintenance and security patching. The absence of capability checks on entry points, despite nonce checks being present, is another area for improvement, as it relies solely on nonces for authorization on AJAX handlers.
Key Concerns
- Unpatched CVE
- Low output escaping percentage
- No capability checks on AJAX handlers
Ajax BootModal Login Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Ajax BootModal Login <= 1.4.3 - CAPTCHA Reuse
Ajax BootModal Login Code Analysis
SQL Query Safety
Output Escaping
Ajax BootModal Login Attack Surface
AJAX Handlers 3
Shortcodes 1
WordPress Hooks 8
Maintenance & Trust
Ajax BootModal Login Maintenance & Trust
Maintenance Signals
Community Trust
Ajax BootModal Login Alternatives
LoginPress | wp-login Custom Login Page Customizer
loginpress
LoginPress is a Custom Login Page Customizer plugin allows you to easily customize the layout of login, admin login, client login, register pages.
Custom Login Page Customizer – Login Designer
login-designer
Login Designer is the best way to style a custom login page for your WordPress login, register and forgot password forms, right from the live-action W …
Admin Custom Login
admin-custom-login
Customize Your WordPress Login Screen Amazingly - Add Own Logo, Add Social Profiles, Login Form Positions, Background Image Slide Show
My WordPress Login Logo
my-wp-login-logo
My WordPress Login Logo lets you to add a custom logo in your wordpress login page instead of the usual wordpress logo and customize your login page.
WP Login and Logout Redirect
wp-login-and-logout-redirect
This plugin enable simple and easy way to redirect user to your chosen page URL after login or logout or both.
Ajax BootModal Login Developer Profile
4 plugins · 70K total installs
How We Detect Ajax BootModal Login
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ajax-bootmodal-login/assets/css/bootmodal.css/wp-content/plugins/ajax-bootmodal-login/assets/css/bootstrap.min.css/wp-content/plugins/ajax-bootmodal-login/assets/js/scripts.jsajax-login-scriptajax-bootmodal-login/assets/css/bootmodal.css?ver=ajax-bootmodal-login/assets/css/bootstrap.min.css?ver=ajax-bootmodal-login/assets/js/scripts.js?ver=HTML / DOM Fingerprints
bootmodal-loginbootmodal-registerbootmodal-lostpassworddata-alimir-login-modaldata-alimir-register-modaldata-alimir-lostpass-modalajax_login_object[alimir_login_form][alimir_register_form][alimir_lostpass_form]