Antispam Login Form Security & Risk Analysis

wordpress.org/plugins/antispam-login-form

Antispam Login Form is easy to use. Antispam Login Form WordPress plugin allows you to Antispam Login Form fields in your theme.

20 active installs v1.0 PHP + WP 4.6+ Updated Sep 12, 2016
antispamantispam-login-formfieldsfiledspam
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Antispam Login Form Safe to Use in 2026?

Generally Safe

Score 85/100

Antispam Login Form has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The antispam-login-form v1.0 plugin exhibits a generally positive security posture from a static analysis perspective, with no detected dangerous functions, external HTTP requests, or file operations. The absence of SQL queries that are not prepared statements is also a strong indicator of good coding practices in that area.

However, a significant concern arises from the complete lack of output escaping. With 3 total outputs identified and 0% properly escaped, this presents a direct risk of cross-site scripting (XSS) vulnerabilities. The absence of nonce checks, capability checks, and any authentication checks on potential entry points (though currently limited) also means that if new entry points were introduced or discovered, they would likely be unprotected, opening the door for unauthorized actions or information disclosure. The plugin's history of no known vulnerabilities is a positive sign, suggesting a proactive approach to security or a lack of past issues, but it does not negate the identified risks in the current version's code.

In conclusion, while the plugin avoids common pitfalls like raw SQL and external requests, the critical issue of unescaped output poses a tangible threat. Coupled with the lack of robust security checks on its limited attack surface, this plugin requires careful consideration. Addressing the output escaping is paramount to improving its security.

Key Concerns

  • All outputs are unescaped
  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

Antispam Login Form Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Antispam Login Form Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped3 total outputs
Attack Surface

Antispam Login Form Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_menuantispam-login-form.php:12
actionadmin_initantispam-login-form.php:17
actionadmin_enqueue_scriptsantispam-login-form.php:27
actionlogin_formantispam-login-form.php:38
filterwp_authenticate_userantispam-login-form.php:39
actionregister_formantispam-login-form.php:71
filterregistration_errorsantispam-login-form.php:72
actioninitantispam-login-form.php:115
Maintenance & Trust

Antispam Login Form Maintenance & Trust

Maintenance Signals

WordPress version tested4.6.30
Last updatedSep 12, 2016
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Antispam Login Form Developer Profile

seosbg

74 plugins · 10K total installs

97
trust score
Avg Security Score
95/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect Antispam Login Form

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/antispam-login-form/css/antispam-login-form.css

HTML / DOM Fingerprints

CSS Classes
antispam-login-formnoselects-redss-logo
Data Attributes
name="rand"name="text"
FAQ

Frequently Asked Questions about Antispam Login Form