
Erident Custom Login and Dashboard Security & Risk Analysis
wordpress.org/plugins/erident-custom-login-and-dashboardFully customize the WordPress Login Screen.
Is Erident Custom Login and Dashboard Safe to Use in 2026?
Mostly Safe
Score 83/100Erident Custom Login and Dashboard is generally safe to use though it hasn't been updated recently. 3 past CVEs were resolved.
The 'erident-custom-login-and-dashboard' plugin v4.3 exhibits a mixed security posture. On the positive side, it demonstrates strong practices regarding SQL queries and output escaping, with 100% prepared statements and 98% properly escaped outputs, respectively. The presence of 6 nonce checks and 4 capability checks also indicates an effort to secure certain functionalities. However, significant concerns arise from the static analysis, specifically the presence of one AJAX handler without authentication checks, representing a direct, unprotected entry point. The taint analysis revealing two flows with unsanitized paths, while not classified as critical or high severity, still suggests potential avenues for exploitation if these paths lead to sensitive operations. The plugin's vulnerability history is a major red flag. With a total of three known CVEs, including two high-severity and one medium-severity, and the last one being in April 2021, it suggests a pattern of past security weaknesses. The common vulnerability types (XSS and CSRF) point to historical issues with input handling and request verification. While there are currently no unpatched CVEs, the track record indicates a higher likelihood of future vulnerabilities if the development practices don't evolve to address these historical patterns more proactively. In conclusion, while the plugin has some good security foundations, the unprotected AJAX handler, unsanitized taint flows, and a history of high and medium severity vulnerabilities present considerable risks that require attention.
Key Concerns
- Unprotected AJAX handler
- Flows with unsanitized paths
- High severity historical CVEs
- Medium severity historical CVE
Erident Custom Login and Dashboard Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Erident Custom Login and Dashboard <= 3.5.8 - Authenticated Stored Cross-Site Scripting
Erident Custom Login and Dashboard <= 3.4.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting
Erident Custom Login & Dashboard <= 3.4.1 - Cross-Site Request Forgery
Erident Custom Login and Dashboard Release Timeline
Erident Custom Login and Dashboard Code Analysis
Output Escaping
Data Flow Analysis
Erident Custom Login and Dashboard Attack Surface
AJAX Handlers 4
WordPress Hooks 16
Maintenance & Trust
Erident Custom Login and Dashboard Maintenance & Trust
Maintenance Signals
Community Trust
Erident Custom Login and Dashboard Alternatives
Ultimate Dashboard – Custom WordPress Dashboard
ultimate-dashboard
The #1 Plugin to Customize the WordPress Dashboard!
Remove Dashboard Access
remove-dashboard-access-for-non-admins
Disable Dashboard access for users of a specific role or capability. Disallowed users are redirected to a chosen URL. Get set up in seconds.
AGCA – Custom Dashboard & Login Page
ag-custom-admin
CHANGE: admin menu, login page, admin bar, dashboard widgets, custom colors, custom CSS & JS, logo & images
Uber Login Logo
uber-login-logo
A simple, lightweight WordPress plugin to change your login logo.
White Label – WordPress Custom Admin, Custom Login Page, and Custom Dashboard
white-label
Our White Label WordPress plugin lets you make a custom admin experience. Create a custom login page, a custom dashboard, and much more.
Erident Custom Login and Dashboard Developer Profile
10 plugins · 120K total installs
How We Detect Erident Custom Login and Dashboard
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/erident-custom-login-and-dashboard/assets/css/admin.css/wp-content/plugins/erident-custom-login-and-dashboard/assets/css/heatbox.css/wp-content/plugins/erident-custom-login-and-dashboard/assets/js/settings-page.js/wp-content/plugins/erident-custom-login-and-dashboard/assets/js/wp-color-picker-alpha.js/wp-content/plugins/erident-custom-login-and-dashboard/assets/js/settings-page.js/wp-content/plugins/erident-custom-login-and-dashboard/assets/js/wp-color-picker-alpha.js/wp-content/plugins/erident-custom-login-and-dashboard/assets/css/admin.css?ver=/wp-content/plugins/erident-custom-login-and-dashboard/assets/css/heatbox.css?ver=/wp-content/plugins/erident-custom-login-and-dashboard/assets/js/settings-page.js?ver=/wp-content/plugins/erident-custom-login-and-dashboard/assets/js/wp-color-picker-alpha.js?ver=HTML / DOM Fingerprints
erident-custom-login-dashboard-settingsdata-nonce-save-settingsdata-nonce-reset-settingsdata-nonce-load-default-settingsCustomLoginDashboard