
Customize Login Image Security & Risk Analysis
wordpress.org/plugins/customize-login-imageThis plugin allows you to customize the image and the appearance of the WordPress Login Screen.
Is Customize Login Image Safe to Use in 2026?
Generally Safe
Score 85/100Customize Login Image has a strong security track record. Known vulnerabilities have been patched promptly.
The "customize-login-image" plugin version 3.5.3 exhibits a mixed security posture. On the positive side, static analysis reveals no apparent attack surface through typical entry points like AJAX handlers, REST API routes, shortcodes, or cron events, and all SQL queries are properly prepared. This suggests a well-contained plugin with regard to direct external manipulation. However, the taint analysis indicates two flows with unsanitized paths, although none were classified as critical or high severity. The plugin also has a history of vulnerabilities, with one medium severity Cross-Site Scripting (XSS) vulnerability reported in the past. While there are no currently unpatched CVEs, this history and the presence of unsanitized paths are areas of concern.
The overall security is moderately good due to the absence of an exposed attack surface and proper SQL handling. Nevertheless, the identified unsanitized paths, even if not leading to high-severity issues in this analysis, represent potential weaknesses that could be exploited. The past XSS vulnerability also serves as a reminder that input sanitization and output escaping need continuous vigilance. For a more robust security assessment, understanding the nature of the unsanitized flows and ensuring all outputs are properly escaped would be crucial.
Key Concerns
- Unsanitized path in taint analysis (x2)
- Past medium severity CVE (XSS)
- Unescaped output (25% of total outputs)
Customize Login Image Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Customize Login Image <= 3.4 - Cross-Site Scripting
Customize Login Image Code Analysis
Output Escaping
Data Flow Analysis
Customize Login Image Attack Surface
WordPress Hooks 12
Maintenance & Trust
Customize Login Image Maintenance & Trust
Maintenance Signals
Community Trust
Customize Login Image Alternatives
Super Custom Login
super-custom-login
This plugin enables users to personalize their WordPress login screen by replacing the default WordPress logo with their own custom logo.
Secure Admin Login With Customize
secure-admin-login-with-customize
Secure admin login with customize allows you to customize your WordPress admin login page within WordPress customizer.
WP Customize
wp-customize
This plugin allows you to set up a custom login page, and set a custom footer message in the WordPress Admin.
Rebrander – White Label WordPress
rebrander-white-label-wp
Rebrander customizes login logo & background, admin area, dashboard, and all the WordPress logo and links.
Login Logo
login-logo
Customize the logo on the WP login screen by simply dropping a file named login-logo.png into your WP content directory. CSS is automatic!
Customize Login Image Developer Profile
28 plugins · 61K total installs
How We Detect Customize Login Image
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/customize-login-image/customize-login-image.jsHTML / DOM Fingerprints
id="apa_cli_logo_url"name="apa_cli_logo_url"id="apa_cli_logo_file"name="apa_cli_logo_file"id="apa_cli_login_background_color"name="apa_cli_login_background_color"+4 moreWP_PLUGIN_URL