Ciusan Register Login Security & Risk Analysis

wordpress.org/plugins/ciusan-register-login

Showing login, register or lost password form modal popup with ajax.

30 active installs v2.1 PHP + WP 3.2+ Updated Mar 29, 2015
ciusanloginlostpasswordregister
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Ciusan Register Login Safe to Use in 2026?

Generally Safe

Score 85/100

Ciusan Register Login has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The 'ciusan-register-login' plugin v2.1 exhibits a mixed security posture. On the positive side, there are no known vulnerabilities, no dangerous functions, all SQL queries use prepared statements, and there are nonce checks present on its entry points. The absence of file operations and external HTTP requests also reduces potential attack vectors. However, significant concerns arise from the low percentage of properly escaped output (6%). This indicates a substantial risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data is likely being rendered directly in the browser without sufficient sanitization. The plugin also lacks capability checks on its AJAX handlers, meaning any authenticated user could potentially trigger these actions, regardless of their role or permissions. While the vulnerability history is clean, the presence of unescaped output and missing capability checks on AJAX handlers suggests potential weaknesses that could be exploited if an attacker were to find a way to inject malicious scripts or leverage these unprotected AJAX actions. The overall security is moderate, with a need for immediate attention to output escaping and capability checks.

Key Concerns

  • Low output escaping percentage (6%)
  • 0 capability checks on AJAX handlers
Vulnerabilities
None known

Ciusan Register Login Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Ciusan Register Login Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
33
2 escaped
Nonce Checks
3
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

6% escaped35 total outputs
Attack Surface

Ciusan Register Login Attack Surface

Entry Points5
Unprotected0

AJAX Handlers 2

noprivwp_ajax_ajaxloginciusan-register-login.php:95
noprivwp_ajax_ajaxregisterciusan-register-login.php:97

Shortcodes 3

[ciusan_login] ciusan-register-login.php:327
[ciusan_register] ciusan-register-login.php:333
[ciusan_logout] ciusan-register-login.php:353
WordPress Hooks 6
actionadmin_menuciusan-register-login.php:48
actionadmin_enqueue_scriptsciusan-register-login.php:51
actioninitciusan-register-login.php:53
actioninitciusan-register-login.php:101
actioninitciusan-register-login.php:105
actionwp_footerciusan-register-login.php:320
Maintenance & Trust

Ciusan Register Login Maintenance & Trust

Maintenance Signals

WordPress version tested4.1.42
Last updatedMar 29, 2015
PHP min version
Downloads18K

Community Trust

Rating74/100
Number of ratings6
Active installs30
Developer Profile

Ciusan Register Login Developer Profile

Dannie Herdyawan

6 plugins · 60 total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Ciusan Register Login

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ciusan-register-login/assets/css/ciusan.css/wp-content/plugins/ciusan-register-login/assets/js/ciusan.js/wp-content/plugins/ciusan-register-login/assets/css/ciusan-register-login.css/wp-content/plugins/ciusan-register-login/assets/js/jquery.validate.js/wp-content/plugins/ciusan-register-login/assets/js/ciusan-register-login.js
Script Paths
https://www.google.com/recaptcha/api.js

HTML / DOM Fingerprints

CSS Classes
ciusan-success-messages
HTML Comments
<!-- Add menu -->
Data Attributes
data-sitekey
JS Globals
ajax_auth_object
REST Endpoints
/wp-json/
FAQ

Frequently Asked Questions about Ciusan Register Login