Login Page Customizer and Designer Security & Risk Analysis

wordpress.org/plugins/login-page-customizer-and-designer

Customize your WordPress login page with custom templates, animations, backgrounds & security. Make Beautiful login pages in minutes.

0 active installs v1.0.0 PHP 7.4+ WP 6.2+ Updated Unknown
brandingcustom-logincustomizerloginlogin-page
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Login Page Customizer and Designer Safe to Use in 2026?

Generally Safe

Score 100/100

Login Page Customizer and Designer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "login-page-customizer-and-designer" plugin version 1.0.1 demonstrates a generally strong security posture based on the static analysis. The complete absence of unsanitized taint flows, raw SQL queries without prepared statements, unescaped output, and a lack of critical or high severity vulnerabilities in its history are all positive indicators. The plugin also implements proper nonce and capability checks on its entry points, including its AJAX handlers, which is a crucial security practice.

However, a few areas warrant attention. The presence of file operations and external HTTP requests, while not inherently insecure, represent potential attack vectors if not handled with extreme care. The bundled Freemius library, even at version 1.0, could be a concern if it contains known vulnerabilities or is outdated, although no history of vulnerabilities for this specific library is provided. The limited total entry points (3 AJAX handlers) and zero unprotected entry points are commendable, but it's essential to ensure the robustness of the existing checks.

In conclusion, the plugin appears to be well-developed from a security perspective, with no immediate critical flaws identified. The focus on prepared statements and output escaping is excellent. The primary areas for vigilance would be monitoring the security of bundled libraries and the secure implementation of file operations and external requests. The lack of historical vulnerabilities is a strong positive sign, suggesting consistent security efforts by the developers.

Key Concerns

  • Bundled Freemius library v1.0
  • Presence of file operations
  • Presence of external HTTP requests
Vulnerabilities
None known

Login Page Customizer and Designer Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Login Page Customizer and Designer Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
14 prepared
Unescaped Output
0
247 escaped
Nonce Checks
4
Capability Checks
5
File Operations
5
External Requests
5
Bundled Libraries
1

Bundled Libraries

Freemius1.0

SQL Query Safety

88% prepared16 total queries

Output Escaping

100% escaped247 total outputs
Attack Surface

Login Page Customizer and Designer Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 3

authwp_ajax_lpcd_toggle_enabledadmin\class-lpcd-admin.php:46
authwp_ajax_lpcd_install_pluginadmin\class-lpcd-admin.php:47
authwp_ajax_lpcd_activate_pluginadmin\class-lpcd-admin.php:48
WordPress Hooks 30
actionadmin_menuadmin\class-lpcd-admin.php:44
actionadmin_enqueue_scriptsadmin\class-lpcd-admin.php:45
actionin_admin_headeradmin\class-lpcd-admin.php:49
actionrest_api_initadmin\class-lpcd-rest-api.php:30
actioninitincludes\class-lpcd-login-renderer.php:66
actionlogin_enqueue_scriptsincludes\class-lpcd-login-renderer.php:67
actionlogin_headincludes\class-lpcd-login-renderer.php:68
filterlogin_body_classincludes\class-lpcd-login-renderer.php:69
filterlogin_messageincludes\class-lpcd-login-renderer.php:70
filterlogin_headerurlincludes\class-lpcd-login-renderer.php:71
filterlogin_headertextincludes\class-lpcd-login-renderer.php:72
filterlogin_titleincludes\class-lpcd-login-renderer.php:73
filterwp_login_errorsincludes\class-lpcd-login-renderer.php:74
filterlogin_redirectincludes\class-lpcd-login-renderer.php:75
actionlogin_headerincludes\class-lpcd-login-renderer.php:78
actionlogin_formincludes\class-lpcd-login-renderer.php:81
actionlostpassword_formincludes\class-lpcd-login-renderer.php:82
filterwp_authenticate_userincludes\class-lpcd-login-renderer.php:83
actionlostpassword_postincludes\class-lpcd-login-renderer.php:84
actionlogin_footerincludes\class-lpcd-login-renderer.php:87
filterwoocommerce_login_redirectincludes\class-lpcd-login-renderer.php:91
filterregistration_redirectincludes\class-lpcd-url-changer.php:31
actioninitincludes\class-lpcd-url-changer.php:48
actionwp_loadedincludes\class-lpcd-url-changer.php:51
filtersite_urlincludes\class-lpcd-url-changer.php:54
filternetwork_site_urlincludes\class-lpcd-url-changer.php:55
filterwp_redirectincludes\class-lpcd-url-changer.php:56
filterregister_urlincludes\class-lpcd-url-changer.php:57
actionafter_uninstalllogin-page-customizer-and-designer.php:61
actionplugins_loadedlogin-page-customizer-and-designer.php:124
Maintenance & Trust

Login Page Customizer and Designer Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedUnknown
PHP min version7.4
Downloads91

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Login Page Customizer and Designer Developer Profile

Shois WP

3 plugins · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Login Page Customizer and Designer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/login-page-customizer-and-designer/admin/assets/css/admin.css/wp-content/plugins/login-page-customizer-and-designer/admin/assets/js/admin.js/wp-content/plugins/login-page-customizer-and-designer/includes/assets/css/login.css
Script Paths
/wp-content/plugins/login-page-customizer-and-designer/admin/assets/js/admin.js
Version Parameters
login-page-customizer-and-designer/admin/assets/css/admin.css?ver=login-page-customizer-and-designer/admin/assets/js/admin.js?ver=login-page-customizer-and-designer/includes/assets/css/login.css?ver=

HTML / DOM Fingerprints

CSS Classes
lpcd-editor-applpcd-settings-applpcd-overview-app
HTML Comments
<!-- Login Page Customizer and Designer Editor --><!-- Login Page Customizer and Designer Settings --><!-- Login Page Customizer and Designer Overview -->
Data Attributes
data-lpcd-editordata-lpcd-settingsdata-lpcd-overview
JS Globals
lpcd_editor_paramslpcd_settings_paramslpcd_overview_params
REST Endpoints
/wp-json/lpcd/v1/templates/wp-json/lpcd/v1/settings/wp-json/lpcd/v1/render_login/wp-json/lpcd/v1/save_template/wp-json/lpcd/v1/delete_template/wp-json/lpcd/v1/save_settings/wp-json/lpcd/v1/toggle_enabled/wp-json/lpcd/v1/install_plugin/wp-json/lpcd/v1/activate_plugin
FAQ

Frequently Asked Questions about Login Page Customizer and Designer