
Custom WP-Admin URL Security & Risk Analysis
wordpress.org/plugins/custom-admin-urlThis is a plugin to give your authority to change wordpress admin url with your demand.
Is Custom WP-Admin URL Safe to Use in 2026?
Generally Safe
Score 85/100Custom WP-Admin URL has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'custom-admin-url' vtest plugin exhibits a generally good security posture in its static analysis, with no identified dangerous functions, SQL injection vulnerabilities due to prepared statements, or external HTTP requests. The absence of known CVEs and a clean vulnerability history is also a positive indicator. However, the analysis reveals critical areas of concern that significantly increase its risk profile. The presence of unsanitized paths in taint analysis suggests potential for directory traversal or arbitrary file read/write vulnerabilities, especially given the two identified file operations. Furthermore, the complete lack of nonce checks and capability checks across all entry points is a major weakness, leaving any functionality exposed to unauthorized access and manipulation. While the attack surface appears small in terms of listed entry points, the unprotected nature of these potential entry points is a significant oversight.
Key Concerns
- Unsanitized paths in taint flows
- Missing nonce checks
- Missing capability checks
- File operations without clear security context
- Output escaping not fully implemented
Custom WP-Admin URL Security Vulnerabilities
Custom WP-Admin URL Code Analysis
Output Escaping
Data Flow Analysis
Custom WP-Admin URL Attack Surface
WordPress Hooks 3
Maintenance & Trust
Custom WP-Admin URL Maintenance & Trust
Maintenance Signals
Community Trust
Custom WP-Admin URL Alternatives
EchBay Admin Security
echbay-admin-security
Protect Your Website Admin Against Hackers & Modify Login Page Design ( Nhiệm vụ: chặn mọi truy cập trực tiếp vào trang quản trị wordpress dưới dạ …
Sumedia Urlify
sumedia-urlify
Makes /wp-admin/ and /wp-login.php pathes configurable using mod_rewrite.
WPS Hide Login
wps-hide-login
Change wp-login.php to anything you want.
All In One Login — WP Admin Login Page Security and Customization with Google reCAPTCHA, Social Login, Limit Login Attempt, 2FA, and more.
change-wp-admin-login
Do you want to secure and customize the WordPress login page? Download the All in One Login plugin for login page security and customization.
Protect WP Admin
protect-wp-admin
Protect your WP site by changing the default wp-admin URL and customizing the login page for enhanced security.
Custom WP-Admin URL Developer Profile
1 plugin · 100 total installs
How We Detect Custom WP-Admin URL
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
regular-textcodehowtoBEGIN WPAdminURLEND WPAdminURLid="custom_wpadmin_slug"name="custom_wpadmin_slug"label_for="custom_wpadmin_slug"