
CLP – Custom Login Page by NiteoThemes Security & Risk Analysis
wordpress.org/plugins/clp-custom-login-pageCustom Login Page plugin allows you to customize any essential element on WordPress login page. It utilizes powerful customizer to implement changes i …
Is CLP – Custom Login Page by NiteoThemes Safe to Use in 2026?
Use With Caution
Score 64/100CLP – Custom Login Page by NiteoThemes has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The clp-custom-login-page plugin exhibits a mixed security posture. While it demonstrates good practices such as using prepared statements for SQL queries and performing capability checks on its AJAX handlers, significant security concerns remain. The plugin exposes a considerable attack surface with all 5 AJAX handlers lacking authentication checks, making them vulnerable to unauthorized access and manipulation. Furthermore, the presence of the `unserialize` function is a critical red flag, as it can be exploited to execute arbitrary code if not handled with extreme caution and proper sanitization, which is not explicitly detailed in the provided static analysis.
The vulnerability history indicates a past medium-severity Cross-Site Request Forgery (CSRF) vulnerability, which, while patched, points to a potential for insecure handling of user actions. The fact that there is still one unpatched CVE, even if medium, signifies a lack of diligence in addressing known security flaws. The plugin's strengths lie in its use of prepared statements and some capability checks, but these are overshadowed by the unprotected AJAX endpoints and the dangerous `unserialize` function. The limited taint analysis showing no unsanitized paths is positive, but it does not negate the inherent risks of the identified code signals and attack surface.
Key Concerns
- Unprotected AJAX handlers (5)
- Dangerous function: unserialize
- Unpatched CVE (medium)
- Output escaping (73% proper)
CLP – Custom Login Page by NiteoThemes Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
CLP – Custom Login Page by NiteoThemes <= 1.5.5 - Cross-Site Request Forgery
CLP – Custom Login Page by NiteoThemes Code Analysis
Dangerous Functions Found
Bundled Libraries
Output Escaping
Data Flow Analysis
CLP – Custom Login Page by NiteoThemes Attack Surface
AJAX Handlers 5
WordPress Hooks 27
Maintenance & Trust
CLP – Custom Login Page by NiteoThemes Maintenance & Trust
Maintenance Signals
Community Trust
CLP – Custom Login Page by NiteoThemes Alternatives
Admin Custom Login
admin-custom-login
Customize Your WordPress Login Screen Amazingly - Add Own Logo, Add Social Profiles, Login Form Positions, Background Image Slide Show
Loginfy – Custom Login Page Customizer plugin
loginfy
Custom login page customizer for WordPress. 16+ templates, live preview, white-label options. Perfect for agencies, businesses & freelancers brand …
Login Page UI Customizer
login-page-ui-customizer
With Login Page UI Customizer customize your login page to make it look as beautiful as your website. Start your creative engine and get started now!
WP Custom Admin Login Lite – Free WordPress plugin to make a customized admin login page
wp-custom-admin-login-lite
WP Custom Admin Login - WordPress Plugin to make a Customized Admin Login Page allow you to beautify your wp-login page with quick easy templates.
Secure Admin Login With Customize
secure-admin-login-with-customize
Secure admin login with customize allows you to customize your WordPress admin login page within WordPress customizer.
CLP – Custom Login Page by NiteoThemes Developer Profile
9 plugins · 221K total installs
How We Detect CLP – Custom Login Page by NiteoThemes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/clp-custom-login-page/assets/css/admin-settings.cssclp-custom-login-page/assets/css/admin-settings.css?ver=HTML / DOM Fingerprints
autofocus[panel]=clp_panelCLP_CustomizerCLP_Authorization_ExpirationCLP_CompatibilityCLP_Helper_FunctionsCLP_Unsplash_ApiCLP_Import_Export/wp-json/clp-custom-login-page/v1/settings