Change WordPress Login Logo Security & Risk Analysis

wordpress.org/plugins/change-login-logo

Upload your logo for WordPress login page instead of the usual WordPress logo with simple settings.

20K active installs v1.3 PHP 5.2.4+ WP 4.3+ Updated Jul 31, 2024
change-default-logocustom-logologin-logowordpress-logo-changewp-admin-logo
91
A · Safe
CVEs total1
Unpatched0
Last CVEAug 15, 2020
Download
Safety Verdict

Is Change WordPress Login Logo Safe to Use in 2026?

Generally Safe

Score 91/100

Change WordPress Login Logo has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Aug 15, 2020Updated 1yr ago
Risk Assessment

The 'change-login-logo' plugin, version 1.3, exhibits a generally positive security posture based on the static analysis. There is no identified attack surface with unprotected entry points, and the code utilizes prepared statements for all SQL queries, which is a strong security practice. Furthermore, the absence of dangerous functions, file operations, and external HTTP requests indicates a limited scope of potential harm. However, a significant concern arises from the lack of explicit capability checks and nonce checks. While the plugin's entry points appear protected, the absence of these fundamental WordPress security mechanisms leaves room for privilege escalation or unauthorized actions if an attacker can find a way to trigger the plugin's functionality without proper authorization. The vulnerability history shows a past high-severity Cross-Site Scripting (XSS) vulnerability. Although it is currently patched, this indicates a historical weakness in input sanitization and output escaping that warrants continued vigilance. The plugin's strengths lie in its well-contained functionality and secure SQL handling, but the lack of robust authorization checks is a notable weakness.

Key Concerns

  • No nonce checks implemented
  • No capability checks implemented
  • Past high severity XSS vulnerability (2020-08-15)
  • 86% of output escaping is not a perfect score
Vulnerabilities
1

Change WordPress Login Logo Security Vulnerabilities

CVEs by Year

1 CVE in 2020
2020
Patched Has unpatched

Severity Breakdown

High
1

1 total CVE

WF-9d1e8703-4ad3-42c5-a20d-f1bd31522a8b-change-login-logohigh · 7.2Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Change WordPress Login Logo <= 1.1.4 - Stored Cross-Site Scripting

Aug 15, 2020 Patched in 1.1.5 (1256d)
Code Analysis
Analyzed Mar 16, 2026

Change WordPress Login Logo Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
6 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

86% escaped7 total outputs
Attack Surface

Change WordPress Login Logo Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_initchange-wordpress-login-logo.php:24
actionadmin_menuchange-wordpress-login-logo.php:30
actionlogin_headchange-wordpress-login-logo.php:122
filterlogin_headerurlchange-wordpress-login-logo.php:134
actionadmin_noticeschange-wordpress-login-logo.php:147
Maintenance & Trust

Change WordPress Login Logo Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedJul 31, 2024
PHP min version5.2.4
Downloads185K

Community Trust

Rating92/100
Number of ratings17
Active installs20K
Developer Profile

Change WordPress Login Logo Developer Profile

Boopathi Rajan

13 plugins · 44K total installs

70
trust score
Avg Security Score
87/100
Avg Patch Time
419 days
View full developer profile
Detection Fingerprints

How We Detect Change WordPress Login Logo

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
wrapform-table
Data Attributes
id="wp_logo_url"name="wp_logo_url"id="upload-btn"name="upload-btn"class="button-secondary"name="wp_logo_height"+1 more
JS Globals
jQuerywp
FAQ

Frequently Asked Questions about Change WordPress Login Logo