
LWS Hide Login Security & Risk Analysis
wordpress.org/plugins/lws-hide-loginSecure your access to the admin page with this plugin !
Is LWS Hide Login Safe to Use in 2026?
Generally Safe
Score 98/100LWS Hide Login has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "lws-hide-login" plugin version 2.2.4 exhibits a mixed security posture. On the positive side, the code demonstrates good practices with a high percentage of properly escaped outputs, no dangerous functions or file operations, and all SQL queries utilizing prepared statements. The presence of 7 nonce checks and 1 capability check also indicates an awareness of security principles. However, the presence of an unprotected AJAX handler represents a significant concern, as it could potentially be exploited by unauthenticated users.
The vulnerability history of this plugin is concerning, with 3 known CVEs, including one high and two medium severity vulnerabilities. The common vulnerability types (Protection Mechanism Failure, CSRF, Missing Authorization) strongly suggest recurring issues with securing critical functionalities. The recent last vulnerability in November 2023 indicates that these issues have persisted and were not effectively addressed in past updates, despite the plugin claiming to have no currently unpatched vulnerabilities.
Overall, while the static analysis reveals some strong security implementations, the unprotected AJAX entry point and the plugin's history of significant vulnerabilities paint a picture of a moderately risky plugin. The plugin creators need to address the identified entry point and ensure that past vulnerability patterns are thoroughly remediated.
Key Concerns
- Unprotected AJAX handler
- Missing Authorization vulnerability history
- Cross-Site Request Forgery vulnerability history
- Protection Mechanism Failure vulnerability history
- High severity vulnerability in history
- Medium severity vulnerability in history (x2)
LWS Hide Login Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
LWS Hide Login <= 2.1.8 - Protection Mechanism Bypass
LWS Hide Login <= 2.1.6 - Cross-Site Request Forgery
LWS Plugins <= (Various Versions) - Missing Authorization Checks
LWS Hide Login Release Timeline
LWS Hide Login Code Analysis
Output Escaping
Data Flow Analysis
LWS Hide Login Attack Surface
AJAX Handlers 4
WordPress Hooks 13
Maintenance & Trust
LWS Hide Login Maintenance & Trust
Maintenance Signals
Community Trust
LWS Hide Login Alternatives
LWS Tools
lws-tools
Optimize and modify your website's parameters
Wordfence Security – Firewall, Malware Scan, and Login Security
wordfence
Firewall, Malware Scanner, Two Factor Auth, and Comprehensive Security Features, powered by our 24-hour team. Make security a priority with Wordfence.
Hostinger Tools
hostinger
Simplified WordPress management. Manage site info, maintenance, security, & redirects.
Jetpack – WP Security, Backup, Speed, & Growth
jetpack
Improve your WP security with powerful one-click tools like backup, WAF, and malware scan. Includes free tools like stats, CDN and social sharing.
Really Simple Security – Simple and Performant Security (formerly Really Simple SSL)
really-simple-ssl
Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vulnerability Detection and SSL certificate.
LWS Hide Login Developer Profile
6 plugins · 78K total installs
How We Detect LWS Hide Login
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lws-hide-login/css/lws_hl_css.csslws-hide-login/css/lws_hl_css.css?ver=HTML / DOM Fingerprints
lwshl_review_block_generallwshl_circlelwshl_review_block_imagelwshl_review_block_titlelwshl_review_block_desclwshl_button_rate_pluginlwshl_review_button_secondarylws_hidden+1 moredata-action="lws_hl_reminder_ajax"data-action="lws_hl_donotask_ajax"lws_hl_csslws_hl_Poppinslwshl_remind_melwshl_do_not_bother_me