
Login rebuilder Security & Risk Analysis
wordpress.org/plugins/login-rebuilderThis plugin will create a new login page for your site. You can also create separate login pages for administrators and for other users.
Is Login rebuilder Safe to Use in 2026?
Generally Safe
Score 99/100Login rebuilder has a strong security track record. Known vulnerabilities have been patched promptly.
The login-rebuilder plugin version 2.8.8 exhibits a generally good security posture with a strong emphasis on implementing proper security checks. The static analysis reveals a commendable lack of critical or high-severity issues in taint analysis and a complete absence of dangerous functions. The code also demonstrates good practices in its use of prepared statements for all SQL queries, a significant number of nonce and capability checks, and robust output escaping for the majority of its outputs.
However, the plugin's history of known vulnerabilities, including past instances of Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF), indicates a recurring pattern of potential input validation or output sanitization weaknesses. While there are currently no unpatched CVEs, the existence of a past high and medium severity vulnerability warrants continued vigilance. The attack surface, though small and seemingly protected by authentication checks, could still pose a risk if any of those checks are ever found to be insufficient or bypassed.
In conclusion, the login-rebuilder plugin has made significant strides in improving its security, as evidenced by the current static analysis. The use of prepared statements and robust checks are strengths. Nevertheless, the historical vulnerability profile suggests that ongoing security scrutiny and thorough testing are crucial to prevent the re-emergence of similar issues.
Key Concerns
- Past high and medium severity vulnerabilities
- 83% of outputs properly escaped
Login rebuilder Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Login rebuilder <= 2.8.0 - Authenticated (Administrator+) Stored Cross-Site Scripting
Login rebuilder < 1.2.0 - Cross-Site Request Forgery
Login rebuilder Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Login rebuilder Attack Surface
AJAX Handlers 3
WordPress Hooks 34
Maintenance & Trust
Login rebuilder Maintenance & Trust
Maintenance Signals
Community Trust
Login rebuilder Alternatives
No alternatives data available yet.
Login rebuilder Developer Profile
8 plugins · 21K total installs
How We Detect Login rebuilder
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/login-rebuilder/css/login-rebuilder.css/wp-content/plugins/login-rebuilder/css/login-rebuilder-admin.css/wp-content/plugins/login-rebuilder/js/login-rebuilder.js/wp-content/plugins/login-rebuilder/js/login-rebuilder-admin.js/wp-content/plugins/login-rebuilder/js/login-rebuilder-admin-setting.js/wp-content/plugins/login-rebuilder/js/login-rebuilder.js/wp-content/plugins/login-rebuilder/js/login-rebuilder-admin.js/wp-content/plugins/login-rebuilder/js/login-rebuilder-admin-setting.jslogin-rebuilder/css/login-rebuilder.css?ver=login-rebuilder/css/login-rebuilder-admin.css?ver=login-rebuilder/js/login-rebuilder.js?ver=login-rebuilder/js/login-rebuilder-admin.js?ver=login-rebuilder/js/login-rebuilder-admin-setting.js?ver=HTML / DOM Fingerprints
login-rebuilder-messagelogin-rebuilder-message-error<!-- Login rebuilder --><!-- login-rebuilder -->data-login-rebuilder-noncedata-login-rebuilder-ajax-noncelogin_rebuilder_ajax_object/wp-json/login-rebuilder/v1/settings