
MM Login Customization Security & Risk Analysis
wordpress.org/plugins/mm-login-customizationTo hide admin login url by this plugin auto generated URL and make secure your site and it's data. You may frequenty change the URL for your site …
Is MM Login Customization Safe to Use in 2026?
Generally Safe
Score 85/100MM Login Customization has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "mm-login-customization" v1.4 plugin exhibits significant security concerns primarily due to its extensive unprotected attack surface. All 8 identified AJAX handlers lack any form of authentication or authorization checks, presenting a direct and easily exploitable entry point for attackers. This is further compounded by the fact that all SQL queries are executed without prepared statements, making the plugin highly susceptible to SQL injection vulnerabilities. While there are no recorded CVEs for this plugin and a majority of output is properly escaped, these strengths are overshadowed by the fundamental security flaws in handling user input and protecting critical functionalities.
The taint analysis, while limited in scope, identified flows with unsanitized paths, which is a clear indicator of potential cross-site scripting (XSS) or other injection vulnerabilities. The complete absence of nonce and capability checks on the AJAX handlers means that any authenticated or unauthenticated user could potentially trigger these actions, leading to unauthorized modifications, data exposure, or even site compromise. Given the lack of historical vulnerabilities, it's difficult to ascertain if this is due to a lack of targeting or a recent introduction of these insecure practices. However, the current state of the code suggests a high risk of exploitation.
Key Concerns
- AJAX handlers without authentication checks
- SQL queries without prepared statements
- Unsanitized paths in taint flows
- Nonce checks missing on AJAX handlers
- Capability checks missing on AJAX handlers
MM Login Customization Security Vulnerabilities
MM Login Customization Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
MM Login Customization Attack Surface
AJAX Handlers 8
WordPress Hooks 12
Maintenance & Trust
MM Login Customization Maintenance & Trust
Maintenance Signals
Community Trust
MM Login Customization Alternatives
Obfuscate Admin
obfuscate-admin
You want to stop users from accessing the wp-admin of your WordPress installation. Obfoscate WordPress admin url and prevent casual discovery.
Disable Admin Notices – Hide Dashboard Notifications
disable-admin-notices
Disable admin notices and hide dashboard notifications from plugins, themes and core. Hide all notices, selected ones, or show them in a single line.
SecuPress with Simple SSL – Simple and Performant Security
secupress
Protect your WordPress with SecuPress, analyze and ensure the safety of your website daily.
Hide Admin Bar
hide-admin-bar
Hide the Admin Bar in WordPress 3.1+.
Hide Admin Bar Based on User Roles
hide-admin-bar-based-on-user-roles
Hide the WordPress Admin Bar for specific user roles, capabilities, devices, pages, or time windows. The ultimate toolbar control plugin for membershi …
MM Login Customization Developer Profile
2 plugins · 0 total installs
How We Detect MM Login Customization
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mm-login-customization/assets/css/front/mmlc_front_style.css/wp-content/plugins/mm-login-customization/assets/js/front/mmlc_front_ajax.js/wp-content/plugins/mm-login-customization/assets/css/front/mmlc_front_tempate_one_style.css/wp-content/plugins/mm-login-customization/assets/css/front/mmlc_front_tempate_two_style.css/wp-content/plugins/mm-login-customization/assets/css/back/mmlc_admin_style.css/wp-content/plugins/mm-login-customization/assets/js/back/mmlc_admin_ajax.jsmm-login-customization/assets/js/front/mmlc_front_ajax.js?ver=1.0.0mm-login-customization/assets/js/back/mmlc_admin_ajax.js?ver=1.0.0HTML / DOM Fingerprints
lc_admin_localize_ajax_urllc_front_localize_ajax_url/wp-json/get_lc_status/wp-json/get_lc_url_save/wp-json/get_lc_disable/wp-json/get_lc_template_save