LoginAura Security & Risk Analysis

wordpress.org/plugins/loginaura

Customize your WordPress login page with beautiful themes, logo upload, custom colors, and redirects. No code needed.

10 active installs v1.1.1 PHP 7.4+ WP 5.9+ Updated Apr 1, 2026
brandingcustom-loginloginlogin-pagewp-login
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is LoginAura Safe to Use in 2026?

Generally Safe

Score 100/100

LoginAura has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The Loginaura v1.1.1 plugin exhibits a strong security posture based on the static analysis. The absence of dangerous functions, reliance on prepared statements for all SQL queries, and 100% proper output escaping indicate robust coding practices against common vulnerabilities like SQL injection and cross-site scripting. Furthermore, the plugin implements nonce and capability checks on all identified entry points, which are crucial for preventing unauthorized actions. The vulnerability history being clear of any recorded CVEs reinforces the impression of a secure plugin.

While the attack surface is small and appears to be well-secured, the absence of taint analysis data, with zero flows analyzed, leaves a blind spot. This means that while direct vulnerabilities might not be apparent through static code inspection, the potential for complex or indirect vulnerabilities that exploit data flow might not have been fully explored. The plugin also doesn't leverage bundled libraries, which while not a direct risk, means it doesn't benefit from any potential security hardening that might be present in well-maintained libraries.

Vulnerabilities
None known

LoginAura Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

LoginAura Release Timeline

v1.1.1Current
v1.0.1
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

LoginAura Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
132 escaped
Nonce Checks
2
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped132 total outputs
Attack Surface

LoginAura Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_loginaura_saveadmin/class-loginaura-admin.php:23
authwp_ajax_loginaura_resetadmin/class-loginaura-admin.php:24
WordPress Hooks 16
actionadmin_menuadmin/class-loginaura-admin.php:21
actionadmin_enqueue_scriptsadmin/class-loginaura-admin.php:22
filteradmin_body_classadmin/class-loginaura-admin.php:26
actioncustomize_registerincludes/class-loginaura-customizer.php:22
actioncustomize_preview_initincludes/class-loginaura-customizer.php:23
actioncustomize_controls_enqueue_scriptsincludes/class-loginaura-customizer.php:24
filterlogin_headerurlincludes/class-loginaura-login.php:22
filterlogin_headertextincludes/class-loginaura-login.php:23
actionlogin_enqueue_scriptsincludes/class-loginaura-login.php:26
filterlogin_titleincludes/class-loginaura-login.php:29
actionlogin_footerincludes/class-loginaura-login.php:32
filterlogin_errorsincludes/class-loginaura-login.php:35
filterlogin_body_classincludes/class-loginaura-login.php:38
filterlogin_redirectincludes/class-loginaura-redirects.php:21
filterlogout_redirectincludes/class-loginaura-redirects.php:22
actionplugins_loadedloginaura.php:63
Maintenance & Trust

LoginAura Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedApr 1, 2026
PHP min version7.4
Downloads125

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

LoginAura Developer Profile

Amel-Nokoe

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect LoginAura

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/loginaura/assets/fonts/fonts.css/wp-content/plugins/loginaura/assets/css/admin.css/wp-content/plugins/loginaura/assets/js/admin.js
Script Paths
/wp-content/plugins/loginaura/assets/js/admin.js
Version Parameters
loginaura-fonts?ver=loginaura-admin?ver=

HTML / DOM Fingerprints

CSS Classes
loginaura-fullscreen
Data Attributes
data-loginaura-page
JS Globals
LoginAura
REST Endpoints
/wp-json/loginaura/v1/settings
FAQ

Frequently Asked Questions about LoginAura