
Custom Login Security & Risk Analysis
wordpress.org/plugins/custom-loginCustom Login allows you to easily customize your admin login page, works great for client sites!
Is Custom Login Safe to Use in 2026?
Generally Safe
Score 100/100Custom Login has a strong security track record. Known vulnerabilities have been patched promptly.
The "custom-login" plugin v5.1.2.2 exhibits a generally positive security posture based on the provided static analysis. There are no identified dangerous functions, all SQL queries utilize prepared statements, and a high percentage of output is properly escaped, indicating good development practices for preventing common vulnerabilities like XSS and SQL injection. The absence of file operations and external HTTP requests further reduces the attack surface. Furthermore, the presence of nonce checks is a positive sign for securing actions within the WordPress environment. However, the complete lack of capability checks and REST API permission callbacks across all entry points is a significant concern, as it suggests that any functionality exposed could potentially be accessed by any logged-in user, regardless of their role or privileges. The vulnerability history shows one known CVE, though it is currently patched. This past vulnerability, specifically related to 'Missing Authorization,' aligns with the static analysis finding of absent capability checks, reinforcing the risk of unauthorized access if new vulnerabilities arise or if previously patched issues are re-introduced.
While the current version appears to have addressed past security issues and implements some good coding practices, the absence of robust authorization checks across its entire attack surface remains a substantial weakness. The plugin effectively minimizes direct code execution risks but leaves broader access control as a potential point of failure. A balanced conclusion would be that the plugin is technically well-built regarding input sanitization and output escaping, but it lacks critical authorization mechanisms that could lead to privilege escalation or unauthorized data manipulation if exploited, especially considering its past authorization-related vulnerability.
Key Concerns
- No capability checks for entry points
- Past CVE related to Missing Authorization
- Limited output escaping (91%)
Custom Login Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Custom Login <= 4.1.0 - Missing Authorization
Custom Login Code Analysis
Output Escaping
Custom Login Attack Surface
WordPress Hooks 7
Maintenance & Trust
Custom Login Maintenance & Trust
Maintenance Signals
Community Trust
Custom Login Alternatives
GS Custom Login
gs-custom-login
A simple, lightweight Plugin to Customize Your WordPress Login Screen Amazingly.
PWD WP Login
pwd-wp-login
This plugin allows you to easy customize your login WordPress Dashboard using API customizer.
Super Custom Login
super-custom-login
This plugin enables users to personalize their WordPress login screen by replacing the default WordPress logo with their own custom logo.
Really Simple Login Logo
really-simple-login-logo
A lightweight, secure, and user-friendly plugin to customize your WordPress login page logo.
Stylish Login Pro
stylish-login-pro
Stylish Login Pro is a simple modern plugin I made so that I could customize the login screen on my own websit.
Custom Login Developer Profile
5 plugins · 25K total installs
How We Detect Custom Login
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/custom-login/resources/css/extensions.csscustom-login/resources/css/extensions.css?ver=