
Custom Welcome Messages Security & Risk Analysis
wordpress.org/plugins/custom-welcome-messagesThis plugin will allow you to add a custom welcome message to your login/register screens. It will also allow you to add a separate custom message fo …
Is Custom Welcome Messages Safe to Use in 2026?
Generally Safe
Score 85/100Custom Welcome Messages has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "custom-welcome-messages" plugin v1.1 exhibits a mixed security posture. On one hand, the static analysis shows no identified dangerous functions, SQL queries are all prepared, and there are no file operations or external HTTP requests. The absence of any recorded vulnerabilities, past or present, is a strong positive indicator. However, a significant concern arises from the complete lack of output escaping, with 0% of 22 identified outputs being properly escaped. This presents a substantial risk of Cross-Site Scripting (XSS) vulnerabilities, as any user-provided data that is displayed on the frontend without proper sanitization can be exploited. Additionally, the complete absence of capability checks and nonce checks on all identified entry points (though there are zero in this case) means that if any new entry points were introduced in future versions, they would likely be unprotected by default.
Key Concerns
- Unescaped output on all entry points
- No capability checks on any entry points
- No nonce checks on any entry points
Custom Welcome Messages Security Vulnerabilities
Custom Welcome Messages Code Analysis
Output Escaping
Custom Welcome Messages Attack Surface
WordPress Hooks 12
Maintenance & Trust
Custom Welcome Messages Maintenance & Trust
Maintenance Signals
Community Trust
Custom Welcome Messages Alternatives
Login Logout Menu
login-logout-menu
Login Logout Menu is a handy plugin which allows you to add login, logout, register and profile menu items in your selected menu.
Easy Login Logout
easy-login-logout
Easy Login Logout Menus is the perfect plugin for websites which have login user or logout user.
StranoWeb Ajax Login
stranoweb-ajax-login
Stranoweb Ajax Login replaces default Wordpress login, register and lost password forms with a beautiful ajax modal popup and comes with a lot of amaz …
Floating Login
floating-login
Floating login/ register element that sticks to the top of the screen and changes depending on user login state.
LoginWP (Formerly Peter's Login Redirect)
peters-login-redirect
Redirect users to different locations after they log in, log out and register based on different conditions.
Custom Welcome Messages Developer Profile
5 plugins · 41K total installs
How We Detect Custom Welcome Messages
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/custom-welcome-messages/css/admin_panel.cssHTML / DOM Fingerprints
postbox2donateinside2donatepostbox2resourcesinside2resourcesdata-options