
Custom Login Page Customizer | admin login, client login and forgot password forms/pages Security & Risk Analysis
wordpress.org/plugins/arrow-login-pageCustom Login Page Customizer plugin allows you to easily build and customize the layout of login page, admin login page, client login page from start …
Is Custom Login Page Customizer | admin login, client login and forgot password forms/pages Safe to Use in 2026?
Generally Safe
Score 85/100Custom Login Page Customizer | admin login, client login and forgot password forms/pages has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "arrow-login-page" plugin version 1.0.2 exhibits significant security concerns primarily due to its exposed attack surface. All four identified AJAX entry points lack any authentication checks, creating a direct pathway for unauthenticated attackers to interact with the plugin's backend functionality. While the plugin demonstrates good practice by using prepared statements for all SQL queries and avoids dangerous functions, file operations, and external HTTP requests, the absence of proper authorization on AJAX handlers is a critical flaw.
Despite a clean vulnerability history with no recorded CVEs, this does not negate the immediate risks identified in the static analysis. The taint analysis, while limited to a single flow, identified an unsanitized path, which could potentially lead to vulnerabilities if exploited in conjunction with the unprotected AJAX endpoints. The low percentage of properly escaped output (31%) further amplifies the risk, suggesting that reflected or stored cross-site scripting (XSS) vulnerabilities are likely.
In conclusion, the plugin's adherence to secure SQL practices is a positive attribute. However, the critical deficiency in securing its AJAX handlers, coupled with insufficient output escaping and a potentially problematic taint flow, results in a poor overall security posture. The lack of recorded vulnerabilities may be due to the plugin's limited usage or the effectiveness of other, unanalyzed, security mechanisms. Nevertheless, the identified weaknesses require immediate attention to mitigate potential security breaches.
Key Concerns
- AJAX handlers without auth checks
- Unescaped output (low percentage)
- Flow with unsanitized paths
- AJAX handlers without nonce checks
- AJAX handlers without capability checks
Custom Login Page Customizer | admin login, client login and forgot password forms/pages Security Vulnerabilities
Custom Login Page Customizer | admin login, client login and forgot password forms/pages Release Timeline
Custom Login Page Customizer | admin login, client login and forgot password forms/pages Code Analysis
Output Escaping
Data Flow Analysis
Custom Login Page Customizer | admin login, client login and forgot password forms/pages Attack Surface
AJAX Handlers 4
WordPress Hooks 10
Maintenance & Trust
Custom Login Page Customizer | admin login, client login and forgot password forms/pages Maintenance & Trust
Maintenance Signals
Community Trust
Custom Login Page Customizer | admin login, client login and forgot password forms/pages Alternatives
Branda – White Label & Branding, Free Login Page Customizer
branda-white-labeling
White label & rebrand your login page & WordPress dashboard. Customize system emails & get everything to rebrand WordPress with Branda.
Login Page Styler – Custom WordPress Login Page Customizer & Security
login-page-styler
Customize and secure your WordPress login page with logo, backgrounds, templates, custom login URL, reCAPTCHA protection, and login activity logs — no …
Loginfy – Custom Login Page Customizer plugin
loginfy
Custom login page customizer for WordPress. 16+ templates, live preview, white-label options. Perfect for agencies, businesses & freelancers brand …
Custom Login Page by SeedProd
custom-login-page-wp
Custom Login Page made easy! Customize the logo, background image, colors, fonts and more on your login page and see your changes in realtime!
Custom Login Page | WebHunt Infotech
wp-login-page-customizer
Plugin allows you to easily customize Login Screen. You can design beautiful and eye catching login page in few minutes.
Custom Login Page Customizer | admin login, client login and forgot password forms/pages Developer Profile
5 plugins · 530 total installs
How We Detect Custom Login Page Customizer | admin login, client login and forgot password forms/pages
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/arrow-login-page/assets/css/color.css/wp-content/plugins/arrow-login-page/assets/css/main.css/wp-content/plugins/arrow-login-page/assets/css/responsive.css/wp-content/plugins/arrow-login-page/assets/js/custom.js/wp-content/plugins/arrow-login-page/assets/js/frontend.js/wp-content/plugins/arrow-login-page/assets/js/custom.js/wp-content/plugins/arrow-login-page/assets/js/frontend.jsarrow-login-page/assets/css/color.css?ver=arrow-login-page/assets/css/main.css?ver=arrow-login-page/assets/css/responsive.css?ver=arrow-login-page/assets/js/custom.js?ver=arrow-login-page/assets/js/frontend.js?ver=HTML / DOM Fingerprints
arrowlogin_logo_sectionarrowlogin_theme_sectionarrowlogin_custom_css_sectionarrowlogin_panelid="accordion-panel-arrowlogin_panel"id="customize-theme-controls"window.onloadajaxurl