
Awesome Custom Login URL Security & Risk Analysis
wordpress.org/plugins/awesome-custom-login-urlCustom Login URL (CLU) is a lightweight plugin that allows to customize default WP login, registration and password
Is Awesome Custom Login URL Safe to Use in 2026?
Generally Safe
Score 85/100Awesome Custom Login URL has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of the "awesome-custom-login-url" v1.0 plugin reveals a generally good security posture concerning common WordPress vulnerabilities. The plugin demonstrates an absence of dangerous functions, SQL queries (all using prepared statements), and external HTTP requests. Crucially, it also shows no instances of unescaped output and no file operations, all of which are positive indicators. The lack of any reported CVEs or past vulnerabilities further reinforces this impression of a secure plugin.
However, a significant concern arises from the taint analysis, which identified two flows with unsanitized paths. While reported as not critical or high severity, unsanitized paths are a potential entry point for various attacks if not handled properly within the plugin's logic. Furthermore, the complete absence of nonce checks and capability checks across all entry points, including AJAX and REST API routes (even though there are none currently), indicates a potential weakness. If future versions introduce new entry points, these checks will be essential to prevent unauthorized access and actions.
In conclusion, "awesome-custom-login-url" v1.0 exhibits strengths in its handling of direct database interactions and output, and its lack of vulnerability history is commendable. The primary areas for improvement lie in addressing the identified unsanitized path flows and establishing a robust security framework with nonce and capability checks, especially in anticipation of potential future feature additions that might expand the attack surface.
Key Concerns
- Unsanitized paths in taint analysis
- No nonce checks on entry points
- No capability checks on entry points
Awesome Custom Login URL Security Vulnerabilities
Awesome Custom Login URL Code Analysis
Data Flow Analysis
Awesome Custom Login URL Attack Surface
WordPress Hooks 7
Maintenance & Trust
Awesome Custom Login URL Maintenance & Trust
Maintenance Signals
Community Trust
Awesome Custom Login URL Alternatives
Akismet Anti-spam: Spam Protection
akismet
The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam solution for WordPress and WooCommerce.
Disable Comments – Remove Comments & Stop Spam [Multi-Site Support]
disable-comments
Allows administrators to globally disable comments on their site. Comments can be disabled according to post type. Multisite friendly.
Antispam Bee
antispam-bee
Sophisticated antispam plugin for effective daily comment and trackback spam-fighting. Built with data protection and privacy in mind.
Spam protection, Honeypot, Anti-Spam by CleanTalk
cleantalk-spam-protect
Blocks spam comments, fake users, contact form spam and more. No impact on SEO. Privacy focused. CAPTCHA free, premium Antispam plugin.
Captcha Code
captcha-code-authentication
GDPR compatible captcha anti-spam protection for login form, comments form, registration form & lost password form. Eliminate spam with captcha.
Awesome Custom Login URL Developer Profile
13 plugins · 370 total installs
How We Detect Awesome Custom Login URL
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/awesome-custom-login-url/css/style.cssawesome-custom-login-url/css/style.css?ver=