F4 Simple White Label Security & Risk Analysis

wordpress.org/plugins/f4-simple-whitelabel

Allows you to to change the login image, admin bar logo and admin footer text.

200 active installs v1.0.12 PHP 7.0+ WP 5.2+ Updated Dec 15, 2025
faviconloginlogin-pagewhite-labelwhitelabel
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is F4 Simple White Label Safe to Use in 2026?

Generally Safe

Score 100/100

F4 Simple White Label has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The "f4-simple-whitelabel" plugin, version 1.0.12, exhibits a generally positive security posture based on the provided static analysis. The absence of any recorded CVEs, combined with a complete lack of identified dangerous functions, raw SQL queries, file operations, or external HTTP requests, suggests a well-written and secure codebase. The attack surface is also reported as zero, indicating no discoverable entry points like AJAX handlers, REST API routes, shortcodes, or cron events that could be exploited.

However, a significant concern arises from the output escaping signal. With one total output and 0% properly escaped, this indicates a critical weakness. Any user-supplied data that is outputted without proper sanitization could lead to cross-site scripting (XSS) vulnerabilities. While the taint analysis shows no specific flows with unsanitized paths, the general lack of output escaping is a red flag that requires immediate attention. The absence of capability checks and nonce checks is also noteworthy, though less concerning given the zero attack surface reported. This plugin appears to be designed with security in mind, but the unescaped output presents a clear and present danger.

Key Concerns

  • 100% of outputs are not properly escaped
Vulnerabilities
None known

F4 Simple White Label Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

F4 Simple White Label Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

F4 Simple White Label Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 14
actionplugins_loadedmodules\Core\Hooks.php:22
actionF4/SWL/set_constantsmodules\Core\Hooks.php:23
actioninitmodules\Core\Hooks.php:48
actionF4/SWL/set_constantsmodules\WhiteLabel\Hooks.php:24
actionF4/SWL/loadedmodules\WhiteLabel\Hooks.php:25
actionlogin_headmodules\WhiteLabel\Hooks.php:48
filterlogin_headertextmodules\WhiteLabel\Hooks.php:49
filterlogin_headerurlmodules\WhiteLabel\Hooks.php:50
actionlogin_headmodules\WhiteLabel\Hooks.php:53
actionadmin_headmodules\WhiteLabel\Hooks.php:54
actionadmin_bar_menumodules\WhiteLabel\Hooks.php:57
actionadmin_bar_menumodules\WhiteLabel\Hooks.php:58
filteradmin_footer_textmodules\WhiteLabel\Hooks.php:61
filterupdate_footermodules\WhiteLabel\Hooks.php:62
Maintenance & Trust

F4 Simple White Label Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 15, 2025
PHP min version7.0
Downloads4K

Community Trust

Rating100/100
Number of ratings1
Active installs200
Developer Profile

F4 Simple White Label Developer Profile

FAKTOR VIER

7 plugins · 4K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
8 days
View full developer profile
Detection Fingerprints

How We Detect F4 Simple White Label

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
loginlogin h1 alogin h1 a imglogin h1 a span
Data Attributes
altstylesrchref
FAQ

Frequently Asked Questions about F4 Simple White Label