Login Customizer Plus Security & Risk Analysis

wordpress.org/plugins/login-customizer-plus

Login Customizer Plus plugin allows you to easily customize your wordpress login page.

0 active installs v1.3.0 PHP 8.0+ WP 5.8+ Updated Unknown
customizerloginlogin-customizerlogin-logologo
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Login Customizer Plus Safe to Use in 2026?

Generally Safe

Score 100/100

Login Customizer Plus has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The plugin "login-customizer-plus" v1.3.0 demonstrates a generally strong security posture based on the provided static analysis. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events with potential for direct code execution or unauthorized access significantly limits the attack surface. The code also shows good practices in database interaction, with 100% of SQL queries utilizing prepared statements, and a decent number of nonce and capability checks are present. However, the 56% proper output escaping rate is a concern, indicating that a notable portion of output might be vulnerable to cross-site scripting (XSS) attacks. The lack of any recorded vulnerabilities in its history is a positive sign, suggesting a history of secure development, but this should not lead to complacency, especially given the identified output escaping issues.

While the static analysis found no critical or high severity taint flows and no dangerous functions, the unescaped output represents a tangible risk. The limited number of entry points is a strength, but the insecurity in handling output can still be exploited. The absence of file operations and external HTTP requests further reduces the potential for remote code execution or information disclosure. Overall, the plugin is built on a secure foundation with minimal direct attack vectors, but the identified weakness in output escaping requires attention.

Key Concerns

  • Inadequate output escaping
Vulnerabilities
None known

Login Customizer Plus Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Login Customizer Plus Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
36
46 escaped
Nonce Checks
2
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

jQuery

Output Escaping

56% escaped82 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
<admin> (templates\admin.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Login Customizer Plus Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_enqueue_scriptslogin-customizer-plus.php:67
actionadmin_menulogin-customizer-plus.php:68
actionlogin_enqueue_scriptslogin-customizer-plus.php:70
filterlogin_headerurllogin-customizer-plus.php:71
actionlogin_footerlogin-customizer-plus.php:72
Maintenance & Trust

Login Customizer Plus Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedUnknown
PHP min version8.0
Downloads9K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Login Customizer Plus Developer Profile

techuptodate

2 plugins · 10 total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Login Customizer Plus

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/login-customizer-plus/css/mystyle.css/wp-content/plugins/login-customizer-plus/js/myscript.js/wp-content/plugins/login-customizer-plus/js/bootstrap.min.js/wp-content/plugins/login-customizer-plus/js/custom.js/wp-content/plugins/login-customizer-plus/vendor/font-awesome/css/font-awesome.css
Version Parameters
login-customizer-plus/css/mystyle.css?ver=login-customizer-plus/js/myscript.js?ver=login-customizer-plus/js/bootstrap.min.js?ver=login-customizer-plus/js/custom.js?ver=login-customizer-plus/vendor/font-awesome/css/font-awesome.css?ver=

HTML / DOM Fingerprints

CSS Classes
lcp-fa-iconlcp-footer-tag
FAQ

Frequently Asked Questions about Login Customizer Plus