
Login Logout Menu & Redirect Security & Risk Analysis
wordpress.org/plugins/lmscrafter-user-menu-redirectsDynamic login menus, 7-level smart redirect engine, role-based menu visibility, and login analytics. All in one plugin.
Is Login Logout Menu & Redirect Safe to Use in 2026?
Generally Safe
Score 100/100Login Logout Menu & Redirect has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "lmscrafter-user-menu-redirects" v3.9.0 plugin exhibits a generally good security posture, with a strong emphasis on secure coding practices. The static analysis reveals excellent output escaping (99%) and a high percentage of SQL queries utilizing prepared statements (87%). The absence of dangerous functions, file operations, and critical or high-severity taint flows further bolster its security. Furthermore, the plugin has no recorded vulnerabilities, indicating a history of stable and secure development. However, a significant concern arises from the large attack surface exposed by AJAX handlers. Out of 13 AJAX handlers, all 13 lack authentication checks, presenting a considerable risk. This means any unauthenticated user can potentially trigger these handlers, leading to unintended consequences or information disclosure if these handlers perform sensitive actions. While capability checks are present for all entry points, the lack of authentication on AJAX handlers is a critical oversight that needs immediate attention. The presence of nonces on most AJAX actions (14 nonces for 13 handlers, suggesting one handler might have multiple nonces or one handler lacks one) is a positive sign for those that do have them, but it doesn't mitigate the fundamental issue of missing authentication.
Key Concerns
- Unprotected AJAX handlers
Login Logout Menu & Redirect Security Vulnerabilities
Login Logout Menu & Redirect Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Login Logout Menu & Redirect Attack Surface
AJAX Handlers 13
Shortcodes 5
WordPress Hooks 37
Maintenance & Trust
Login Logout Menu & Redirect Maintenance & Trust
Maintenance Signals
Community Trust
Login Logout Menu & Redirect Alternatives
LoginWP (Formerly Peter's Login Redirect)
peters-login-redirect
Redirect users to different locations after they log in, log out and register based on different conditions.
WP Login and Logout Redirect
wp-login-and-logout-redirect
This plugin enable simple and easy way to redirect user to your chosen page URL after login or logout or both.
Sky Login Redirect
sky-login-redirect
Control where users land after login/logout. Redirect by role, user, or previous page. Includes a powerful login customizer and WooCommerce support.
PowerUp – Admin Tools (Login/Logout Redirects, Scripts & Comments Control)
powerup
Simplify site management with Login/Logout Redirect, Hide Admin Bar, Disable Comments, Header Footer Scripts and Remove Footer Credit.
WC Quick Customer Redirects
wc-quick-customer-redirects
This plugin lets you set custom page redirects for customers after registration, login, logout actions.
Login Logout Menu & Redirect Developer Profile
2 plugins · 0 total installs
How We Detect Login Logout Menu & Redirect
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lmscrafter-user-menu-redirects/assets/css/admin.css/wp-content/plugins/lmscrafter-user-menu-redirects/assets/css/public.css/wp-content/plugins/lmscrafter-user-menu-redirects/assets/js/admin.js/wp-content/plugins/lmscrafter-user-menu-redirects/assets/js/admin.jslmscrafter-user-menu-redirects/assets/css/admin.css?ver=lmscrafter-user-menu-redirects/assets/css/public.css?ver=lmscrafter-user-menu-redirects/assets/js/admin.js?ver=HTML / DOM Fingerprints
lmsc-rsum-diagnostics-noticedata-nonce-urldata-nonce-actiondata-nonce-fieldLMSC_RSUM_Admin/wp-json/lmsc-rsum/v1/options