
Login AWP Security & Risk Analysis
wordpress.org/plugins/login-awpCustomize your WordPress login page with themes, logos, and styles. Fast, lightweight, and built for a polished first impression.
Is Login AWP Safe to Use in 2026?
Generally Safe
Score 100/100Login AWP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "login-awp" plugin v3.2.2 exhibits a generally good security posture based on the provided static analysis and vulnerability history. The plugin has a relatively small attack surface, with all identified AJAX handlers protected by authentication checks. The code follows secure coding practices, including the use of prepared statements for all SQL queries and a high percentage of properly escaped output. The absence of critical or high-severity taint flows, dangerous functions, file operations, and a clean vulnerability history further contribute to its positive security profile. The presence of nonce and capability checks on AJAX actions indicates a thoughtful approach to preventing unauthorized actions.
However, there are a few areas that warrant attention. The presence of three "flows with unsanitized paths" in the taint analysis, even without a critical or high severity rating, suggests a potential for path traversal vulnerabilities if these flows are not properly handled within the AJAX actions. While the plugin doesn't make external HTTP requests that are typically a major concern, it does make one, and the nature of this request isn't detailed, which could be a latent risk if it interacts with untrusted data. The overall low number of entry points and the complete lack of historical vulnerabilities are strong indicators of diligent security development and maintenance.
Key Concerns
- Flows with unsanitized paths identified
- External HTTP request made by plugin
Login AWP Security Vulnerabilities
Login AWP Code Analysis
Output Escaping
Data Flow Analysis
Login AWP Attack Surface
AJAX Handlers 6
WordPress Hooks 19
Maintenance & Trust
Login AWP Maintenance & Trust
Maintenance Signals
Community Trust
Login AWP Alternatives
Custom Login Logo and URL
custom-login-logo-and-url
Effortlessly customize your WordPress login page with a custom logo and branded URL to enhance user experience and security.
Gray Login Customizer
gray-login-customizer
Easily customize your WordPress login page with logo, background, styles, and more — no coding needed.
Login Screen Designer
login-screen-designer
Customize WordPress login page branding—logo, background, colors, and messages. A simple and effective tool for personalizing the login experience.
Custom Login Page Customizer
login-customizer
Custom Login Customizer allows you to easily customize your admin login page, straight from your WordPress Customizer!
Custom Login Page Customizer
colorlib-login-customizer
Customize your WordPress login page with live preview. Change logo, background, colors, and form styling without coding.
Login AWP Developer Profile
1 plugin · 0 total installs
How We Detect Login AWP
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/login-awp/assets/css/login-admin-styles.css/wp-content/plugins/login-awp/assets/js/login-admin.js/wp-content/plugins/login-awp/assets/js/login-admin.jslogin-awp/assets/css/login-admin-styles.css?ver=login-awp/assets/js/login-admin.js?ver=HTML / DOM Fingerprints
login-awp-wraplogin-awp-headerlogin-awp-formlogin-awp-input-grouplogin-awp-buttonlogin-awp-image-uploadlogin-awp-image-previewlogin-awp-image-delete+3 more<!-- General Settings --><!-- Appearance Settings --><!-- Advanced Settings --><!-- Login AWP Plugin -->+2 moredata-tabdata-settingdata-nonce-fielddata-nonce-actiondata-nonce-urllogin_text