
All In One Login — WP Admin Login Page Security and Customization with Google reCAPTCHA, Social Login, Limit Login Attempt, 2FA, and more. Security & Risk Analysis
wordpress.org/plugins/change-wp-admin-loginDo you want to secure and customize the WordPress login page? Download the All in One Login plugin for login page security and customization.
Is All In One Login — WP Admin Login Page Security and Customization with Google reCAPTCHA, Social Login, Limit Login Attempt, 2FA, and more. Safe to Use in 2026?
Generally Safe
Score 96/100All In One Login — WP Admin Login Page Security and Customization with Google reCAPTCHA, Social Login, Limit Login Attempt, 2FA, and more. has a strong security track record. Known vulnerabilities have been patched promptly.
The "change-wp-admin-login" plugin, version 2.1.1, exhibits a generally strong security posture based on static analysis. A significant positive aspect is the complete absence of unprotected entry points across its REST API routes and AJAX handlers. Furthermore, all SQL queries are secured using prepared statements, and a high percentage of output is properly escaped, indicating good development practices in preventing common web vulnerabilities. The plugin also demonstrates diligent use of nonces and capability checks. However, the presence of two external HTTP requests warrants careful review to ensure these connections are not exploited for data exfiltration or other malicious purposes. The plugin also bundles Freemius and DataTables, which should be monitored for their own security vulnerabilities.
Despite the current static analysis showing no critical or high severity issues, the plugin's vulnerability history is a significant concern. With three previously discovered medium severity vulnerabilities, all of which are now patched, it indicates a pattern of weaknesses that have required remediation. The common vulnerability types of "Protection Mechanism Failure" and "Incorrect Authorization" suggest that the plugin's core security features have been susceptible to bypass or misconfiguration in the past. While the current version has no unpatched vulnerabilities, this historical pattern necessitates ongoing vigilance and a proactive approach to security updates, as past issues can sometimes resurface or be exploited in new ways.
Key Concerns
- Bundled library: Freemius v1.0
- Bundled library: DataTables
- External HTTP requests present
- History of 3 medium severity CVEs
All In One Login — WP Admin Login Page Security and Customization with Google reCAPTCHA, Social Login, Limit Login Attempt, 2FA, and more. Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
WordPress All In One Login Plugin <= 2.0.8 - IP Sooofing to Protection Mechanism Bypass
Change WP Admin Login <= 1.1.3 - Protection Mechanism Failure to Login Page Disclosure
Change WP Admin Login <= 1.0.9 - Missing Authorization Checks
All In One Login — WP Admin Login Page Security and Customization with Google reCAPTCHA, Social Login, Limit Login Attempt, 2FA, and more. Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
All In One Login — WP Admin Login Page Security and Customization with Google reCAPTCHA, Social Login, Limit Login Attempt, 2FA, and more. Attack Surface
REST API Routes 25
WordPress Hooks 64
Maintenance & Trust
All In One Login — WP Admin Login Page Security and Customization with Google reCAPTCHA, Social Login, Limit Login Attempt, 2FA, and more. Maintenance & Trust
Maintenance Signals
Community Trust
All In One Login — WP Admin Login Page Security and Customization with Google reCAPTCHA, Social Login, Limit Login Attempt, 2FA, and more. Alternatives
Rename wp-admin login
rename-wp-admin-login
Rename wp-admin login* is a plugin that allows us to rename wp-admin login URL to anything you want
Admin Login Hide – PTI
admin-login-hide-pti
Easily hide or customize your WordPress login URL to enhance security and prevent unauthorized access.
Secure WordPress Admin – Change & Hide Login URL
change-hide-login-url
Secure and customize your WordPress admin login by changing the default wp-login.php URL to a custom slug and blocking unauthorized access to wp-admin …
WPS Hide Login
wps-hide-login
Change wp-login.php to anything you want.
Hide WP Admin Login
hide-wp-admin-login
Change WordPress wp-login.php URL to anything you want.
All In One Login — WP Admin Login Page Security and Customization with Google reCAPTCHA, Social Login, Limit Login Attempt, 2FA, and more. Developer Profile
84 plugins · 1.4M total installs
How We Detect All In One Login — WP Admin Login Page Security and Customization with Google reCAPTCHA, Social Login, Limit Login Attempt, 2FA, and more.
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/change-wp-admin-login/assets/css/app.css/wp-content/plugins/change-wp-admin-login/assets/js/app.js/wp-content/plugins/change-wp-admin-login/assets/js/app.jschange-wp-admin-login/assets/css/app.css?ver=change-wp-admin-login/assets/js/app.js?ver=HTML / DOM Fingerprints
aio-login__appaio-login__submenu-handler-stylesaio_login__app_object/wp-json/aio-login/