
AS login Security & Risk Analysis
wordpress.org/plugins/as-loginAS login you can fully customize wordpress login page.
Is AS login Safe to Use in 2026?
Generally Safe
Score 100/100AS login has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "as-login" plugin version 1.1 exhibits a strong security posture based on the provided static analysis. The absence of any identified entry points, such as AJAX handlers, REST API routes, shortcodes, or cron events, significantly limits the plugin's attack surface. Furthermore, the complete lack of dangerous functions, file operations, and external HTTP requests suggests a controlled and secure implementation. The fact that all SQL queries utilize prepared statements is a significant positive indicator of secure database interaction.
However, a notable concern arises from the very low percentage (6%) of properly escaped output. This indicates a high likelihood of cross-site scripting (XSS) vulnerabilities, as user-supplied data or dynamic content is likely being rendered without adequate sanitization, making the plugin susceptible to malicious input injection. The complete absence of nonce and capability checks, while not directly exploitable due to the lack of entry points, represents a missed opportunity for robust authorization and security layering should new entry points be introduced in future versions.
The vulnerability history showing zero known CVEs and no recorded past issues is a positive sign, suggesting a development team that may prioritize security or has not yet encountered significant security flaws. Nevertheless, this should not overshadow the critical finding regarding output escaping. While the plugin currently has a minimal attack surface and good practices in other areas, the unescaped output presents a tangible risk that needs immediate attention.
Key Concerns
- Low percentage of properly escaped output
- No nonce checks implemented
- No capability checks implemented
AS login Security Vulnerabilities
AS login Code Analysis
Output Escaping
AS login Attack Surface
WordPress Hooks 6
Maintenance & Trust
AS login Maintenance & Trust
Maintenance Signals
Community Trust
AS login Alternatives
Branda – White Label & Branding, Free Login Page Customizer
branda-white-labeling
White label & rebrand your login page & WordPress dashboard. Customize system emails & get everything to rebrand WordPress with Branda.
BrandNestor
brandnestor
Customize the WordPress dashboard, admin pages, login and register pages, and more.
White Label CMS
white-label-cms
Customise dashboard panels and branding, hide menus plus lots more.
Theme My Login
theme-my-login
The ultimate login branding solution! Theme My Login offers matchless customization of your WordPress user experience!
Ultimate Dashboard – Custom WordPress Dashboard
ultimate-dashboard
The #1 Plugin to Customize the WordPress Dashboard!
AS login Developer Profile
5 plugins · 70 total installs
How We Detect AS login
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/as-login/css/as-admin-login.css/wp-content/plugins/as-login/js/as_login_js.js/wp-content/plugins/as-login/inc/admin-ico.png/wp-content/plugins/as-login/inc/right.png/wp-content/plugins/as-login/inc/wordpress.png/wp-content/plugins/as-login/inc/fiverr.png/wp-content/plugins/as-login/inc/People.png/wp-content/plugins/as-login/inc/github.png/wp-content/plugins/as-login/js/as_login_js.jsHTML / DOM Fingerprints
as_click_hideas_click_showas_urlmy_status_mainmy_status_main_inner