
Custom Login URL Security & Risk Analysis
wordpress.org/plugins/custom-login-urlWhitelabel your site by hiding wp-login.php in the login and registration URLs
Is Custom Login URL Safe to Use in 2026?
Generally Safe
Score 99/100Custom Login URL has a strong security track record. Known vulnerabilities have been patched promptly.
The 'custom-login-url' plugin, version 1.0.3, exhibits a generally strong security posture based on the static analysis. It demonstrates excellent adherence to secure coding practices, with no detected dangerous functions, all SQL queries utilizing prepared statements, and all output being properly escaped. The absence of file operations and external HTTP requests further minimizes potential attack vectors. The presence of a nonce check is also a positive sign for input validation.
However, a significant concern arises from the taint analysis, which identified two flows with unsanitized paths. While these are not currently classified as critical or high severity, unsanitized paths can be a precursor to vulnerabilities, especially if they interact with user-supplied input that is not adequately validated. Furthermore, the plugin's vulnerability history indicates a past medium severity vulnerability attributed to missing authorization. Although there are no currently unpatched vulnerabilities, this history suggests a pattern where authorization checks might be overlooked or implemented incorrectly.
In conclusion, while the static code analysis reveals a technically sound implementation with strong defenses against common vulnerabilities, the presence of unsanitized paths in taint analysis and the historical pattern of missing authorization vulnerabilities are notable weaknesses. Future development should prioritize thorough sanitization of all user inputs and robust authorization checks on all functionalities, especially those that modify or expose sensitive data or settings. The plugin's strengths lie in its secure handling of SQL and output, but these must be complemented by vigilant path sanitization and authorization.
Key Concerns
- Flows with unsanitized paths identified
- Past medium vulnerability (Missing Authorization)
Custom Login URL Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Custom Login URL <= 1.0.2 - Missing Authorization
Custom Login URL Code Analysis
Output Escaping
Data Flow Analysis
Custom Login URL Attack Surface
WordPress Hooks 7
Maintenance & Trust
Custom Login URL Maintenance & Trust
Maintenance Signals
Community Trust
Custom Login URL Alternatives
WPS Hide Login
wps-hide-login
Change wp-login.php to anything you want.
Rename wp-admin login
rename-wp-admin-login
Rename wp-admin login* is a plugin that allows us to rename wp-admin login URL to anything you want
Login Page Styler – Custom WordPress Login Page Customizer & Security
login-page-styler
Customize and secure your WordPress login page with logo, backgrounds, templates, custom login URL, reCAPTCHA protection, and login activity logs — no …
Hide WP Admin Login
hide-wp-admin-login
Change WordPress wp-login.php URL to anything you want.
Rename wp-login.php to anything you want
rename-wp-loginphp-to-anything-you-want
This plugin changes the way you login into your website.
Custom Login URL Developer Profile
4 plugins · 6K total installs
How We Detect Custom Login URL
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/custom-login-url/css/style.csscustom-login-url/css/style.css?ver=