Custom Login Page Customizer Security & Risk Analysis

wordpress.org/plugins/colorlib-login-customizer

Customize your WordPress login page with live preview. Change logo, background, colors, and form styling without coding.

50K active installs v2.1.0 PHP 8.0+ WP 6.0+ Updated Jan 16, 2026
custom-login-pagelogin-customizerlogin-formlogin-pagewhite-label-login
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Custom Login Page Customizer Safe to Use in 2026?

Generally Safe

Score 100/100

Custom Login Page Customizer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "colorlib-login-customizer" v2.1.0 plugin exhibits a strong security posture based on the provided static analysis and vulnerability history. The plugin demonstrates good practices by not exposing a large attack surface with no unprotected entry points. All SQL queries are properly handled with prepared statements, and the vast majority of output is correctly escaped, indicating a good understanding of preventing cross-site scripting vulnerabilities. Furthermore, the presence of nonce and capability checks on its single AJAX handler further reinforces its secure design. The lack of any recorded vulnerabilities, including critical or high-severity issues, and no history of common vulnerability types, is a significant positive indicator. This suggests the plugin is either very well-developed and maintained, or that it hasn't been a target for in-depth security research or exploitation. While the static analysis doesn't reveal any immediate critical flaws, the presence of two instances of `preg_replace(/e)` warrants careful review, as this function can be a source of vulnerabilities if not used judiciously with properly sanitized input. However, without evidence of actual exploitability through taint analysis, it remains a theoretical concern.

Key Concerns

  • Use of dangerous function preg_replace(/e)
Vulnerabilities
None known

Custom Login Page Customizer Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Custom Login Page Customizer Code Analysis

Dangerous Functions
2
Raw SQL Queries
0
0 prepared
Unescaped Output
9
48 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

preg_replace(/e)preg_replace( '/eincludes\class-colorlib-login-customizer-sanitization.php:101
preg_replace(/e)preg_replace( '/eincludes\class-colorlib-login-customizer-sanitization.php:214

Output Escaping

84% escaped57 total outputs
Attack Surface

Custom Login Page Customizer Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_clc_epsilon_reviewincludes\class-colorlib-login-customizer-review.php:49
WordPress Hooks 14
actionadmin_noticescolorlib-login-customizer.php:38
actionadmin_initcolorlib-login-customizer.php:97
actionadmin_initincludes\class-colorlib-login-customizer-backwards-compatibility.php:16
filterclc_backwards_compatibility_frontincludes\class-colorlib-login-customizer-backwards-compatibility.php:17
actionadmin_noticesincludes\class-colorlib-login-customizer-review.php:52
actionadmin_enqueue_scriptsincludes\class-colorlib-login-customizer-review.php:53
actionadmin_print_footer_scriptsincludes\class-colorlib-login-customizer-review.php:54
actionadmin_initincludes\class-colorlib-login-customizer.php:111
actioncustomize_registerincludes\class-colorlib-login-customizer.php:114
filtertemplate_includeincludes\class-colorlib-login-customizer.php:116
actioninitincludes\class-colorlib-login-customizer.php:119
actioninitincludes\class-colorlib-login-customizer.php:122
actioninitincludes\class-colorlib-login-customizer.php:125
filteroption_aio_wp_security_configsincludes\class-colorlib-login-customizer.php:386
Maintenance & Trust

Custom Login Page Customizer Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 16, 2026
PHP min version8.0
Downloads1.1M

Community Trust

Rating98/100
Number of ratings469
Active installs50K
Developer Profile

Custom Login Page Customizer Developer Profile

colorlibplugins

11 plugins · 420K total installs

75
trust score
Avg Security Score
94/100
Avg Patch Time
747 days
View full developer profile
Detection Fingerprints

How We Detect Custom Login Page Customizer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/colorlib-login-customizer/assets/css/colorlib-login-customizer.css/wp-content/plugins/colorlib-login-customizer/assets/js/colorlib-login-customizer.js/wp-content/plugins/colorlib-login-customizer/assets/css/style.css
Script Paths
/wp-content/plugins/colorlib-login-customizer/assets/js/colorlib-login-customizer.js
Version Parameters
colorlib-login-customizer/assets/css/colorlib-login-customizer.css?ver=colorlib-login-customizer/assets/js/colorlib-login-customizer.js?ver=colorlib-login-customizer/assets/css/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
clc-epsilon-review-noticeepsilon-review-button
HTML Comments
<!-- Colorlib Login Customizer -->
Data Attributes
id="colorlib-login-customizer-form-wrapper"
JS Globals
CLC_Review
FAQ

Frequently Asked Questions about Custom Login Page Customizer