Fortress Login Pro – Secure, Hide & Rename Login URL Security & Risk Analysis

wordpress.org/plugins/fortress-login-pro

Hide and rotate your WordPress login URL. Track access, export logs, and prevent brute-force attacks with real-time visibility.

10 active installs v1.1.3 PHP 7.2+ WP 5.0+ Updated May 9, 2025
brute-force-protectioncustom-login-urllogin-securitysecuritywp-admin
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Fortress Login Pro – Secure, Hide & Rename Login URL Safe to Use in 2026?

Generally Safe

Score 100/100

Fortress Login Pro – Secure, Hide & Rename Login URL has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10mo ago
Risk Assessment

The "fortress-login-pro" v1.1.3 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for SQL queries and having a high percentage of properly escaped output. The absence of known CVEs and dangerous functions is also a strong indicator of a well-maintained and secure codebase. However, a significant concern arises from the attack surface. With 14 AJAX handlers, 13 of which lack authentication checks, this presents a substantial risk. The taint analysis also shows 4 flows with unsanitized paths, although none were flagged as critical or high severity, this still warrants attention as it indicates potential for unintended data handling.

The lack of vulnerability history suggests the plugin has been stable, but this does not negate the risks identified in the static analysis. The 13 unprotected AJAX handlers are the most critical finding, as they can be exploited by unauthenticated users to perform actions within the plugin that might have unintended consequences, ranging from information disclosure to privilege escalation depending on the specific handler's functionality. While the plugin has strengths in its handling of database queries and output, the unprotected entry points are a clear weakness that needs to be addressed to improve its overall security.

Key Concerns

  • Unprotected AJAX handlers
  • Flows with unsanitized paths
Vulnerabilities
None known

Fortress Login Pro – Secure, Hide & Rename Login URL Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Fortress Login Pro – Secure, Hide & Rename Login URL Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
9
190 escaped
Nonce Checks
24
Capability Checks
16
File Operations
2
External Requests
0
Bundled Libraries
0

Output Escaping

95% escaped199 total outputs
Data Flows
4 unsanitized

Data Flow Analysis

4 flows4 with unsanitized paths
fortlopr_ajax_save_slug (core\ajax\save-slug.php:16)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
13 unprotected

Fortress Login Pro – Secure, Hide & Rename Login URL Attack Surface

Entry Points14
Unprotected13

AJAX Handlers 14

authwp_ajax_fortress_send_test_emailcore\ajax\send-verification-email.php:87
authwp_ajax_fortress_generate_slugcore\ajax-handler.php:23
authwp_ajax_fortress_save_slugcore\ajax-handler.php:26
authwp_ajax_fortress_send_test_emailcore\ajax-handler.php:29
authwp_ajax_fortress_export_logscore\ajax-handler.php:32
authwp_ajax_fortress_clear_logscore\ajax-handler.php:35
authwp_ajax_fortress_get_slug_historycore\ajax-handler.php:38
authwp_ajax_fortress_restore_slugcore\ajax-handler.php:39
authwp_ajax_fortress_delete_slugcore\ajax-handler.php:40
authwp_ajax_fortress_clear_slug_historycore\ajax-handler.php:41
authwp_ajax_fortress_export_slug_historycore\ajax-handler.php:42
authwp_ajax_fortress_email_me_slugcore\ajax-handler.php:43
authwp_ajax_fortress_promote_pending_slugcore\ajax-handler.php:46
authwp_ajax_fortress_debug_rotationcore\ajax-handler.php:49
WordPress Hooks 67
actionphpmailer_initcore\ajax\email-me-slug.php:57
actionphpmailer_initcore\ajax\send-verification-email.php:50
actioninitcore\ajax-handler.php:54
actionfortress_daily_rotation_checkcore\rotation-engine.php:14
actionfortress_check_pending_slugcore\rotation-engine.php:19
actionfortress_plugin_activatedcore\rotation-engine.php:29
actionfortress_plugin_deactivatedcore\rotation-engine.php:37
actionphpmailer_initcore\rotation-engine.php:186
actionphpmailer_initcore\rotation-engine.php:304
actionfortress_delayed_flush_rulescore\rotation-engine.php:378
actionphpmailer_initcore\smtp-handler.php:90
actionwp_mail_failedcore\smtp-handler.php:135
actionadmin_menufortress-login-pro.php:32
actionadmin_enqueue_scriptsfortress-login-pro.php:145
actionlogin_enqueue_scriptsfortress-login-pro.php:148
filteradmin_footer_textincludes\admin-footer.php:28
filterupdate_footerincludes\admin-footer.php:46
filterwp_mail_content_typeincludes\email-utils.php:22
actionadmin_initincludes\filters-hooks.php:88
actioninitincludes\filters-hooks.php:89
actionadmin_initincludes\filters-hooks.php:266
filterpre_update_option_fortress_smtp_hostincludes\filters-hooks.php:269
filterpre_update_option_fortress_smtp_portincludes\filters-hooks.php:270
filterpre_update_option_fortress_smtp_encryptionincludes\filters-hooks.php:271
filterpre_update_option_fortress_smtp_usernameincludes\filters-hooks.php:272
filterpre_update_option_fortress_smtp_passwordincludes\filters-hooks.php:273
filterpre_update_option_fortress_smtp_from_emailincludes\filters-hooks.php:274
filterpre_update_option_fortress_smtp_from_nameincludes\filters-hooks.php:275
filterpre_update_option_fortress_smtp_recipient_emailincludes\filters-hooks.php:276
filterpre_update_option_fortress_smtp_from_emailincludes\filters-hooks.php:279
filterpre_update_option_fortress_smtp_recipient_emailincludes\filters-hooks.php:280
actionadmin_initincludes\filters-hooks.php:357
actionfortress_plugin_activatedincludes\filters-hooks.php:454
actionfortress_plugin_deactivatedincludes\filters-hooks.php:463
actionupdate_option_fortress_auto_rotation_enabledincludes\filters-hooks.php:472
actionadmin_noticesincludes\filters-hooks.php:517
filterquery_varsincludes\filters-hooks.php:528
actioninitincludes\filters-hooks.php:534
actioninitincludes\filters-hooks.php:546
actiontemplate_redirectincludes\filters-hooks.php:557
actiontemplate_redirectincludes\filters-hooks.php:560
actionwpincludes\filters-hooks.php:563
actionlogin_initincludes\filters-hooks.php:574
actioninitincludes\filters-hooks.php:577
actioninitincludes\filters-hooks.php:682
filterlogin_form_actionincludes\filters-hooks.php:821
actionlogin_formincludes\filters-hooks.php:832
actionwp_loginincludes\filters-hooks.php:949
actionfortress_plugin_activatedincludes\filters-hooks.php:1255
actionupdate_option_fortress_active_slugincludes\filters-hooks.php:1258
filtersite_urlincludes\filters-hooks.php:1263
actioninitincludes\filters-hooks.php:1314
filterlogin_redirectincludes\filters-hooks.php:1322
filterlogin_redirectincludes\filters-hooks.php:1345
actionwpincludes\filters-hooks.php:1378
actionwp_loadedincludes\filters-hooks.php:1422
filterlogout_urlincludes\filters-hooks.php:1498
actionfortress_pending_slug_setincludes\filters-hooks.php:1521
actionfortress_active_slug_changedincludes\filters-hooks.php:1543
actionfortress_delayed_flush_rulesincludes\filters-hooks.php:1565
actionfortress_pending_slug_promotedincludes\filters-hooks.php:1568
actionadmin_noticesincludes\filters-hooks.php:1619
actionadmin_noticesincludes\filters-hooks.php:1638
actionadmin_noticesincludes\filters-hooks.php:1654
actionupdate_option_fortress_block_install_filesincludes\filters-hooks.php:1664
actionadmin_initincludes\filters-hooks.php:1677
actionadmin_noticesincludes\filters-hooks.php:1697

Scheduled Events 7

fortress_check_pending_slug
fortress_delayed_flush_rules
fortress_delayed_flush_rules
fortress_daily_rotation_check
fortress_delayed_flush_rules
fortress_delayed_flush_rules
fortress_delayed_flush_rules
Maintenance & Trust

Fortress Login Pro – Secure, Hide & Rename Login URL Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMay 9, 2025
PHP min version7.2
Downloads612

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Fortress Login Pro – Secure, Hide & Rename Login URL Developer Profile

Hamdi Saidani

2 plugins · 110 total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Fortress Login Pro – Secure, Hide & Rename Login URL

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/fortress-login-pro/assets/css/base.css/wp-content/plugins/fortress-login-pro/assets/js/vendor/chart.min.js/wp-content/plugins/fortress-login-pro/assets/js/logs.js/wp-content/plugins/fortress-login-pro/assets/js/history.js/wp-content/plugins/fortress-login-pro/assets/js/slug-manager.js/wp-content/plugins/fortress-login-pro/assets/js/settings.js/wp-content/plugins/fortress-login-pro/assets/js/rotation-timer.js/wp-content/plugins/fortress-login-pro/assets/js/admin.js+1 more
Script Paths
/wp-content/plugins/fortress-login-pro/assets/js/vendor/chart.min.js/wp-content/plugins/fortress-login-pro/assets/js/logs.js/wp-content/plugins/fortress-login-pro/assets/js/history.js/wp-content/plugins/fortress-login-pro/assets/js/slug-manager.js/wp-content/plugins/fortress-login-pro/assets/js/settings.js/wp-content/plugins/fortress-login-pro/assets/js/rotation-timer.js+1 more
Version Parameters
fortress-login-pro/assets/css/base.css?ver=1.1.3fortress-login-pro/assets/js/vendor/chart.min.js?ver=4.4.0fortress-login-pro/assets/js/logs.js?ver=1.1.3fortress-login-pro/assets/js/history.js?ver=1.1.3fortress-login-pro/assets/js/slug-manager.js?ver=1.1.3fortress-login-pro/assets/js/settings.js?ver=1.1.3fortress-login-pro/assets/js/rotation-timer.js?ver=1.1.3fortress-login-pro/assets/js/admin.js?ver=1.1.3fortress-login-pro/assets/css/template-access.css?ver=1.1.3

HTML / DOM Fingerprints

CSS Classes
fortress-login-pro-wrapfortress-login-pro-headingfortlopr-login-form-wrapper
HTML Comments
<!-- Fortress Login Pro: Admin Footer --><!-- Fortress Login Pro: Logs Section Start --><!-- Fortress Login Pro: History Section Start --><!-- Fortress Login Pro: Slug Manager Section Start -->+2 more
Data Attributes
data-fortress-ajax-urldata-fortress-noncedata-fortress-login-url
JS Globals
fortressLogsDatafortressRotationDatafortressData
FAQ

Frequently Asked Questions about Fortress Login Pro – Secure, Hide & Rename Login URL