ALD Login Page Security & Risk Analysis

wordpress.org/plugins/ald-login-page

Just another Login page customization plugin. Simple but flexible.

20 active installs v1.3 PHP + WP 4.4.2+ Updated Apr 8, 2025
change-login-pageformloginlogin-form
99
A · Safe
CVEs total1
Unpatched0
Last CVEApr 9, 2025
Safety Verdict

Is ALD Login Page Safe to Use in 2026?

Generally Safe

Score 99/100

ALD Login Page has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Apr 9, 2025Updated 12mo ago
Risk Assessment

The "ald-login-page" v1.3 plugin exhibits a generally good security posture based on the static analysis. The absence of dangerous functions, properly escaped output, and the use of prepared statements for SQL queries are all positive indicators. Crucially, the lack of identified taint flows and a clean slate for critical and high-severity vulnerabilities in the code analysis suggest robust development practices in these areas. However, the plugin does have a history of vulnerabilities, specifically a medium-severity Cross-Site Request Forgery (CSRF) issue, even though it is currently patched. This past vulnerability, combined with the absence of any nonce checks and only one capability check noted in the code signals, indicates potential areas for improvement in input validation and authorization for any future entry points that might be introduced or were present in past versions.

While the current static analysis reveals no direct vulnerabilities within the code for version 1.3, the historical CVE for CSRF serves as a caution. The lack of explicit nonce checks on any potential (though currently zero) AJAX handlers or shortcodes is a concern, as is the single capability check, which might not be comprehensive for all functionalities. The absence of a broad attack surface in this version is a strength. Nonetheless, the past vulnerability pattern warrants vigilance and suggests that while the current version appears clean, the plugin's history requires a degree of ongoing monitoring and potentially more rigorous input validation in future development.

Key Concerns

  • Past medium severity CVE (CSRF)
  • No nonce checks found
  • Only one capability check found
Vulnerabilities
1

ALD Login Page Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-32518medium · 6.1Cross-Site Request Forgery (CSRF)

ALD Login Page <= 1.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting

Apr 9, 2025 Patched in 1.3 (7d)
Code Analysis
Analyzed Mar 16, 2026

ALD Login Page Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
29 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped29 total outputs
Attack Surface

ALD Login Page Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actioninitald-login-page.php:38
actionadmin_menuald-login-page.php:40
actionadmin_enqueue_scriptsald-login-page.php:58
actionadmin_initald-login-page.php:140
actionlogin_enqueue_scriptsald-login-page.php:275
filterlogin_headerurlald-login-page.php:280
filterlogin_headertitleald-login-page.php:285
Maintenance & Trust

ALD Login Page Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedApr 8, 2025
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs20
Developer Profile

ALD Login Page Developer Profile

hossainawlad

2 plugins · 30 total installs

100
trust score
Avg Security Score
100/100
Avg Patch Time
7 days
View full developer profile
Detection Fingerprints

How We Detect ALD Login Page

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ald-login-page/js/ald-login-page.admin.js
Version Parameters
ald-login-page-admin-script?ver=

HTML / DOM Fingerprints

CSS Classes
color-pick
Data Attributes
id="logo-image"id="upload-btn"id="logo-image-preview"id="logo-width"id="logo-height"id="logo-padding"+2 more
FAQ

Frequently Asked Questions about ALD Login Page