
Custom Login Form and Logout Redirect Security & Risk Analysis
wordpress.org/plugins/custom-login-form-and-logout-redirectWith Custom Login Form and Logout Redirect, allows you create a login form for use anywhere (Post, Page, Custom Post Type, Widget,…) and Logout Redire …
Is Custom Login Form and Logout Redirect Safe to Use in 2026?
Generally Safe
Score 100/100Custom Login Form and Logout Redirect has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The custom-login-form-and-logout-redirect plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding SQL query handling, utilizing prepared statements exclusively, and has no recorded vulnerability history, suggesting a potentially well-maintained codebase. However, significant concerns arise from the attack surface analysis. The presence of an unprotected AJAX handler presents a clear entry point for potential attacks if not properly secured at the application level. Furthermore, the taint analysis reveals flows with unsanitized paths, indicating a risk of improper data handling. While no critical or high-severity taint flows were identified, the existence of these unsanitized paths is a weakness that could be exploited in conjunction with other vulnerabilities or overlooked security checks. The plugin lacks general capability checks for its entry points, relying solely on a single nonce check, which might not be sufficient for all AJAX operations. The relatively low percentage of properly escaped output also adds to the concern, as it could lead to cross-site scripting (XSS) vulnerabilities if the data is not handled with care downstream.
Key Concerns
- Unprotected AJAX handler
- Flows with unsanitized paths
- Insufficient output escaping
- Missing capability checks
Custom Login Form and Logout Redirect Security Vulnerabilities
Custom Login Form and Logout Redirect Code Analysis
Output Escaping
Data Flow Analysis
Custom Login Form and Logout Redirect Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 8
Maintenance & Trust
Custom Login Form and Logout Redirect Maintenance & Trust
Maintenance Signals
Community Trust
Custom Login Form and Logout Redirect Alternatives
Passwordless Login
passwordless-login
Passwordless login form via a simple to use shortcode: [passwordless-login]
Login Links – Passwordless Login, Temporary Access Links & Custom Login Form
login-links
Create secure self-expiring login links for temporary access and guest users, and enable passwordless login for registered ones.
Custom Login Form
custom-login-form
Customize the WordPress Login Form.
TsDev PressLogin
tsdev-presslogin
Fully customize the default WordPress login page with easy-to-use options.
Custom Login Page Customizer
colorlib-login-customizer
Customize your WordPress login page with live preview. Change logo, background, colors, and form styling without coding.
Custom Login Form and Logout Redirect Developer Profile
1 plugin · 50 total installs
How We Detect Custom Login Form and Logout Redirect
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/custom-login-form-and-logout-redirect/assets/css/settings.css/wp-content/plugins/custom-login-form-and-logout-redirect/assets/js/settings.js/wp-content/plugins/custom-login-form-and-logout-redirect/assets/css/frontend.css/wp-content/plugins/custom-login-form-and-logout-redirect/assets/js/frontend.jsmst-login-form-and-logout-redirect/assets/css/settings.css?ver=mst-login-form-and-logout-redirect/assets/js/settings.js?ver=mst-login-form-and-logout-redirect/assets/css/frontend.css?ver=mst-login-form-and-logout-redirect/assets/js/frontend.js?ver=HTML / DOM Fingerprints
mstteam-login-formmstteam-testmstteam-lost-password-linkmstteam_data<p>Hello <strong></strong> (not Login?