
Block wp-login Security & Risk Analysis
wordpress.org/plugins/block-wp-loginThis plugin completely blocks access to wp-login.php and creates a new secret login URL
Is Block wp-login Safe to Use in 2026?
Generally Safe
Score 99/100Block wp-login has a strong security track record. Known vulnerabilities have been patched promptly.
The 'block-wp-login' v1.5.5 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all its SQL queries and shows a high percentage of properly escaped output. The absence of external HTTP requests and the presence of nonce and capability checks are also strengths. However, a significant concern arises from the single unprotected AJAX handler, which presents an immediate attack vector. The plugin's vulnerability history includes one high-severity Cross-Site Request Forgery (CSRF) in the past, although it is currently unpatched. While the current static analysis did not reveal critical or high severity taint flows, the unprotected AJAX endpoint combined with the past CSRF vulnerability suggests a potential for exploitation if new vulnerabilities are introduced or if the existing protection mechanisms are bypassed.
Key Concerns
- Unprotected AJAX handler
- Past high severity CVE (CSRF)
Block wp-login Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Block WP Login <= 1.3.0 - Cross-Site Request Forgery
Block wp-login Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Block wp-login Attack Surface
AJAX Handlers 1
WordPress Hooks 19
Maintenance & Trust
Block wp-login Maintenance & Trust
Maintenance Signals
Community Trust
Block wp-login Alternatives
Virus Finder
virus-finder
Find viruses in your WordPress easily. Virus scan, malware finder.
BulletProof Security
bulletproof-security
WordPress Security Protection: Malware scanner, Firewall, Login Security, DB Backup, Anti-Spam...
SX User Name Security
user-name-security
SX User Name Security prevents WordPress from showing your real Login everywhere. It ovverides the body_class function, User Nicename, Nickname and Di …
Integrity Checker
integrity-checker
The WordPress Integrity Checker checks your WordPress installation by detecting modified files, permissions issues and other common problems.
GuardianKey
guardiankey
GuardianKey is a service to protect systems in real-time against authentication attacks. It implements GK Auth Security for login protection and GKTin …
Block wp-login Developer Profile
12 plugins · 43K total installs
How We Detect Block wp-login
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/block-wp-login/css/bwpl.css/wp-content/plugins/block-wp-login/js/bwpl.jsblock-wp-login/css/bwpl.css?ver=block-wp-login/js/bwpl.js?ver=HTML / DOM Fingerprints
<!-- wp:paragraph --><!-- /wp:paragraph --><!-- wp:image {"id":123,"sizeSlug":"full","linkDestination":"media"} --><!-- /wp:image -->+2 moredata-bwpl-optiondata-bwpl-option-valuebwpl_admin