Eazy Login Logo Security & Risk Analysis

wordpress.org/plugins/eazy-login-logo

Eazy Login Logo changes the default logo on the login screen.

400 active installs v1.0.0 PHP + WP 4.2+ Updated Jan 2, 2018
activeadd-client-logo-to-login-pageadmin-custom-loginadmin-loginadmin-login-form
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Eazy Login Logo Safe to Use in 2026?

Generally Safe

Score 85/100

Eazy Login Logo has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The eazy-login-logo plugin v1.0.0 exhibits a seemingly secure static analysis profile, with no identified entry points, dangerous functions, file operations, or external HTTP requests. The absence of SQL queries without prepared statements and the lack of known historical vulnerabilities are positive indicators. However, a significant concern arises from the complete lack of output escaping, meaning any data rendered by the plugin is not sanitized, potentially leading to cross-site scripting (XSS) vulnerabilities if user-supplied data is ever incorporated into output. Furthermore, the absence of any nonce or capability checks, while not directly exploitable given the current lack of entry points, indicates a lack of fundamental security hygiene that could become a risk if the plugin's functionality expands or if new entry points are introduced in future versions. The plugin's vulnerability history is clean, suggesting good development practices or a lack of focus from attackers, but this cannot offset the present risk of unescaped output.

In conclusion, while the plugin currently presents a low attack surface and has no history of vulnerabilities, the critical oversight in output escaping represents a direct and present risk. The lack of protective measures like nonce and capability checks, although not currently exploitable, points to a potential weakness in future development. Developers should prioritize implementing proper output escaping mechanisms to mitigate the XSS risk and consider incorporating security checks for any future expansion of functionality.

Key Concerns

  • Unescaped output detected
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Eazy Login Logo Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Eazy Login Logo Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

Eazy Login Logo Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
filterlogin_headerurleazy_login_logo.php:14
filterlogin_headertitleeazy_login_logo.php:20
actionlogin_enqueue_scriptseazy_login_logo.php:26
Maintenance & Trust

Eazy Login Logo Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedJan 2, 2018
PHP min version
Downloads11K

Community Trust

Rating84/100
Number of ratings5
Active installs400
Developer Profile

Eazy Login Logo Developer Profile

Rob Scott

8 plugins · 2K total installs

71
trust score
Avg Security Score
88/100
Avg Patch Time
99 days
View full developer profile
Detection Fingerprints

How We Detect Eazy Login Logo

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/eazy-login-logo/images/login-logo.png

HTML / DOM Fingerprints

CSS Classes
logindiv#loginh1 a
FAQ

Frequently Asked Questions about Eazy Login Logo