L7 Login Customizer Security & Risk Analysis

wordpress.org/plugins/l7-login-customizer

Customize your login, logout, and register pages. Add a custom logo and background image easily.

100 active installs v2.4.0 PHP + WP 3.3+ Updated Sep 2, 2017
backgroundbrandingcustomlogin
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is L7 Login Customizer Safe to Use in 2026?

Generally Safe

Score 85/100

L7 Login Customizer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The "l7-login-customizer" v2.4.0 plugin exhibits a generally positive security posture based on the provided static analysis and vulnerability history. The absence of any identified attack surface entry points, dangerous functions, SQL queries without prepared statements, file operations, external HTTP requests, or any recorded vulnerabilities suggests a strong adherence to secure coding practices. The plugin appears to be well-contained and doesn't expose common vectors for attack. However, a significant concern is the complete lack of nonce checks and capability checks. While there are no identified entry points at this moment, this omission represents a critical weakness. If any new entry points were to be introduced in future updates or if existing functionality is discovered to be accessible in unintended ways, the lack of these fundamental security mechanisms would make exploitation much easier and more severe.

The plugin's vulnerability history is spotless, indicating a track record of secure development or a lack of past security scrutiny. The fact that there are no recorded CVEs and no common vulnerability types is a strong positive signal. The static analysis also shows a decent percentage of output escaping, which is good for preventing cross-site scripting vulnerabilities. Despite the strengths, the absence of nonce and capability checks is a notable weakness that could lead to significant security issues if not addressed. Therefore, while the current state appears safe, there's a clear area for improvement to enhance its long-term security resilience.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
  • Low output escaping percentage (68%)
Vulnerabilities
None known

L7 Login Customizer Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

L7 Login Customizer Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
22
46 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

68% escaped68 total outputs
Attack Surface

L7 Login Customizer Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_initincludes\admin-functions.php:26
filtergettextincludes\admin-functions.php:75
actionadmin_menuincludes\options-page.php:22
actionlogin_headl7-login-customizer.php:75
filterlogin_headerurll7-login-customizer.php:76
filterlogin_headertitlel7-login-customizer.php:77
actionadmin_enqueue_scriptsl7-login-customizer.php:78
actionplugins_loadedl7-login-customizer.php:86
Maintenance & Trust

L7 Login Customizer Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedSep 2, 2017
PHP min version
Downloads11K

Community Trust

Rating86/100
Number of ratings6
Active installs100
Developer Profile

L7 Login Customizer Developer Profile

Jeff

4 plugins · 140 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect L7 Login Customizer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/l7-login-customizer/assets/css/custom-login.css/wp-content/plugins/l7-login-customizer/assets/css/bootstrap.min.css/wp-content/plugins/l7-login-customizer/assets/css/bootstrap-colorpicker.css/wp-content/plugins/l7-login-customizer/assets/js/custom-login.min.js

HTML / DOM Fingerprints

CSS Classes
jsm-custom-login-wrapjsm-login-form-wrapjsm-login-form-wrap-alignjsm-login-form-wrap-align-centerjsm-login-form-wrap-align-rightjsm-login-form-wrap-align-leftjsm-login-form-wrap-widthjsm-login-form-wrap-align-center-label+3 more
HTML Comments
Copyright 2015 Jeffrey S. Mattson (email : jeff@layer7web.com)This program is free software; you can redistribute it and/ or modifyit under the terms of the GNU General Public License as published bythe Free Software Foundation; either version 2 of the License, or+37 more
Data Attributes
data-colorpicker-guiddata-colorpicker-guiddata-colorpicker-guid
JS Globals
l7wc_login_options
FAQ

Frequently Asked Questions about L7 Login Customizer