
Login Customiser Security & Risk Analysis
wordpress.org/plugins/login-customiserA Simple plugin to customise WP-Login, allowing you to change where users are redirected to upon successful login.
Is Login Customiser Safe to Use in 2026?
Generally Safe
Score 85/100Login Customiser has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "login-customiser" v0.1 plugin exhibits a generally positive security posture based on the provided static analysis. The absence of any reported vulnerabilities in its history, coupled with the lack of identified dangerous functions, SQL injection risks (all queries use prepared statements), and file operations, suggests a developer mindful of secure coding practices. Furthermore, the complete lack of external HTTP requests and taint analysis findings is encouraging. However, the analysis does highlight some areas for improvement. The presence of unescaped output for 50% of the identified outputs is a concern, as this could potentially lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled correctly. The complete lack of nonce and capability checks, while currently not exposing a direct attack surface according to the analysis, represents a potential weakness. If new entry points were introduced in future versions, these would immediately become exploitable without these fundamental security checks.
Key Concerns
- Unescaped output (50% of 4 total)
- No nonce checks
- No capability checks
Login Customiser Security Vulnerabilities
Login Customiser Code Analysis
Output Escaping
Login Customiser Attack Surface
WordPress Hooks 3
Maintenance & Trust
Login Customiser Maintenance & Trust
Maintenance Signals
Community Trust
Login Customiser Alternatives
Private Website – Login Required
private-website
This plugin requires users to be logged in to view the website. Activate the plugin to enforce login, and deactivate it to remove the restriction.
Simple Members Area
simple-members-area
A simple way to create and manage a members area in WordPress.
BuddyForms Custom Login
buddyforms-custom-login-page
Custom Login, Custom Login Redirect, Custom Registartion Link, Registation Forms
TR Register Only
tr-register-only
Restrict your WordPress site to registered/logged-in users only. Perfect for private communities, staging sites, and intranet portals.
CFB Must Login
cfb-must-login
Require users to log in before viewing your site with easy admin toggle controls. Includes REST API protection and automatic cache clearing.
Login Customiser Developer Profile
2 plugins · 20 total installs
How We Detect Login Customiser
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.