
EM Custom Login Security & Risk Analysis
wordpress.org/plugins/em-custom-loginEnables a completely customizable WordPress login, registration and password form.
Is EM Custom Login Safe to Use in 2026?
Generally Safe
Score 85/100EM Custom Login has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The em-custom-login plugin v0.1.5 exhibits a mixed security posture. While it demonstrates good practices by having no known vulnerabilities (CVEs) and generally implementing nonce and capability checks on its entry points, there are several areas of concern within the static analysis results. The most significant issue is the presence of SQL queries that are not using prepared statements. This lack of sanitization in database interactions can lead to SQL injection vulnerabilities if user-supplied data is directly incorporated into these queries. Additionally, a notable percentage of output is not properly escaped, creating a risk of Cross-Site Scripting (XSS) vulnerabilities. The taint analysis also reveals flows with unsanitized paths, which, while not flagged as critical or high severity in this specific scan, warrants attention as it indicates potential pathways for malicious data to be processed without adequate cleaning. The plugin's vulnerability history is clean, which is a positive indicator of past development and maintenance, but it doesn't mitigate the risks identified in the current static analysis. In conclusion, while the plugin has a strong foundation with minimal known exploitable flaws and some security checks in place, the identified issues with SQL query preparation and output escaping, along with unsanitized data flows, present tangible security risks that need to be addressed.
Key Concerns
- SQL queries not using prepared statements
- Low percentage of properly escaped output
- Flows with unsanitized paths found
- File operations detected
EM Custom Login Security Vulnerabilities
EM Custom Login Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
EM Custom Login Attack Surface
Shortcodes 5
WordPress Hooks 25
Maintenance & Trust
EM Custom Login Maintenance & Trust
Maintenance Signals
Community Trust
EM Custom Login Alternatives
Register Modal
modal-register
Register Modal provides a modal Ajax-ify box to register for WordPress!
All In One Login — WP Admin Login Page Security and Customization with Google reCAPTCHA, Social Login, Limit Login Attempt, 2FA, and more.
change-wp-admin-login
Do you want to secure and customize the WordPress login page? Download the All in One Login plugin for login page security and customization.
Theme My Login
theme-my-login
The ultimate login branding solution! Theme My Login offers matchless customization of your WordPress user experience!
Ultimate Dashboard – Custom WordPress Dashboard
ultimate-dashboard
The #1 Plugin to Customize the WordPress Dashboard!
Admin Custom Login
admin-custom-login
Customize Your WordPress Login Screen Amazingly - Add Own Logo, Add Social Profiles, Login Form Positions, Background Image Slide Show
EM Custom Login Developer Profile
5 plugins · 50 total installs
How We Detect EM Custom Login
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/em-custom-login/css/admin.css/wp-content/plugins/em-custom-login/js/admin.js/wp-content/plugins/em-custom-login/js/admin.jsem-custom-login/css/admin.css?ver=em-custom-login/js/admin.js?ver=HTML / DOM Fingerprints
emcl-login-formemcl-registration-formemcl-forgot-password-formemcl-reset-password-formemcl-user-activationdata-emcl-nonce[emcl-login-form][emcl-registration-form][emcl-forgot-password-form][emcl-reset-password-form]