Modify Login – Custom WordPress Login URL & Login Page Designer Security & Risk Analysis

wordpress.org/plugins/modify-login

Secure WordPress login with custom URL, protect wp-admin, and design beautiful login pages with drag & drop builder. No code required.

20 active installs v2.0.0 PHP 7.4+ WP 5.8+ Updated Unknown
custom-loginhide-wp-loginlogin-customizerlogin-pagelogin-security
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Modify Login – Custom WordPress Login URL & Login Page Designer Safe to Use in 2026?

Generally Safe

Score 100/100

Modify Login – Custom WordPress Login URL & Login Page Designer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "modify-login" plugin v2.0.0 exhibits a generally strong security posture with no known critical or high vulnerabilities in its history. The static analysis reveals good practices such as the presence of nonce and capability checks for all identified AJAX entry points, and a high percentage of properly escaped output. The plugin also avoids bundled libraries, which can often introduce outdated and vulnerable components. The absence of REST API routes and shortcodes further limits its attack surface.

However, there are areas for improvement. The plugin's static analysis did identify one flow with an unsanitized path, which, while not flagged as critical or high severity in the taint analysis, represents a potential risk. Additionally, 35% of SQL queries not using prepared statements is a concern, as this can lead to SQL injection vulnerabilities if not handled with extreme care. The presence of file operations and external HTTP requests, while limited, also warrants careful review to ensure they are not being exploited.

Overall, the plugin appears to be developed with security in mind, evidenced by the robust auth checks and output escaping. The lack of any historical vulnerabilities is a positive indicator. Nonetheless, the identified unsanitized path flow and the use of raw SQL queries introduce some risk that should be addressed to achieve a more secure state.

Key Concerns

  • Flow with unsanitized path found
  • 35% of SQL queries not using prepared statements
Vulnerabilities
None known

Modify Login – Custom WordPress Login URL & Login Page Designer Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Modify Login – Custom WordPress Login URL & Login Page Designer Code Analysis

Dangerous Functions
0
Raw SQL Queries
15
8 prepared
Unescaped Output
12
181 escaped
Nonce Checks
8
Capability Checks
8
File Operations
2
External Requests
2
Bundled Libraries
0

SQL Query Safety

35% prepared23 total queries

Output Escaping

94% escaped193 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

6 flows1 with unsanitized paths
save_settings (includes\admin\admin-ajax.php:143)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Modify Login – Custom WordPress Login URL & Login Page Designer Attack Surface

Entry Points7
Unprotected0

AJAX Handlers 7

authwp_ajax_modify_login_save_builder_settingsincludes\admin\admin-ajax.php:22
authwp_ajax_modify_login_reset_builder_settingsincludes\admin\admin-ajax.php:23
authwp_ajax_modify_login_upload_mediaincludes\admin\admin-ajax.php:24
authwp_ajax_modify_login_save_settingsincludes\admin\admin-ajax.php:27
authwp_ajax_modify_login_reset_settingsincludes\admin\admin-ajax.php:28
authwp_ajax_modify_login_get_logsincludes\admin\admin-ajax.php:31
authwp_ajax_modify_login_clear_logsincludes\admin\admin-ajax.php:32
WordPress Hooks 29
actionadmin_menuincludes\admin\class-modify-login-admin.php:63
actionadmin_enqueue_scriptsincludes\admin\class-modify-login-admin.php:66
actionadmin_enqueue_scriptsincludes\admin\class-modify-login-admin.php:67
actioninitincludes\class-modify-login-rewrite.php:91
actionparse_requestincludes\class-modify-login-rewrite.php:94
filterquery_varsincludes\class-modify-login-rewrite.php:97
actiontemplate_redirectincludes\class-modify-login-rewrite.php:100
actioninitincludes\class-modify-login-rewrite.php:103
filterlogin_form_middleincludes\class-modify-login-rewrite.php:106
filtersite_urlincludes\class-modify-login-rewrite.php:107
filternetwork_site_urlincludes\class-modify-login-rewrite.php:108
filterwp_redirectincludes\class-modify-login-rewrite.php:109
actionlogin_formincludes\class-modify-login-rewrite.php:110
filterlogin_redirectincludes\class-modify-login-rewrite.php:113
filterlogout_redirectincludes\class-modify-login-rewrite.php:114
actionwp_loadedincludes\class-modify-login-rewrite.php:247
actioninitincludes\class-modify-login.php:121
actioninitincludes\class-modify-login.php:122
actionlogin_enqueue_scriptsincludes\frontend\class-modify-login-frontend.php:42
actionlogin_enqueue_scriptsincludes\frontend\class-modify-login-frontend.php:43
actionlogin_headincludes\frontend\class-modify-login-frontend.php:44
filterlogin_headerurlincludes\frontend\class-modify-login-frontend.php:45
filterlogin_headertextincludes\frontend\class-modify-login-frontend.php:46
actionlogin_formincludes\frontend\class-modify-login-frontend.php:47
actionwp_authenticate_userincludes\frontend\class-modify-login-frontend.php:48
actionwp_login_failedincludes\frontend\class-modify-login-frontend.php:51
actionwp_loginincludes\frontend\class-modify-login-frontend.php:52
actioninitincludes\frontend\class-modify-login-frontend.php:662
actiontemplate_redirectincludes\frontend\class-modify-login-frontend.php:663
Maintenance & Trust

Modify Login – Custom WordPress Login URL & Login Page Designer Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedUnknown
PHP min version7.4
Downloads3K

Community Trust

Rating20/100
Number of ratings1
Active installs20
Developer Profile

Modify Login – Custom WordPress Login URL & Login Page Designer Developer Profile

MantraBrain

11 plugins · 9K total installs

87
trust score
Avg Security Score
98/100
Avg Patch Time
88 days
View full developer profile
Detection Fingerprints

How We Detect Modify Login – Custom WordPress Login URL & Login Page Designer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/modify-login/assets/dist/admin/css/tailwind.min.css/wp-content/plugins/modify-login/assets/dist/admin/css/settings.min.css/wp-content/plugins/modify-login/assets/dist/admin/css/login-logs.min.css/wp-content/plugins/modify-login/assets/dist/admin/js/settings.min.js/wp-content/plugins/modify-login/assets/dist/admin/js/logs.min.js
Script Paths
/wp-content/plugins/modify-login/assets/dist/admin/js/settings.min.js/wp-content/plugins/modify-login/assets/dist/admin/js/logs.min.js
Version Parameters
modify-login/assets/dist/admin/css/tailwind.min.css?ver=modify-login/assets/dist/admin/css/settings.min.css?ver=modify-login/assets/dist/admin/css/login-logs.min.css?ver=modify-login/assets/dist/admin/js/settings.min.js?ver=modify-login/assets/dist/admin/js/logs.min.js?ver=

HTML / DOM Fingerprints

JS Globals
modifyLoginAdmin
FAQ

Frequently Asked Questions about Modify Login – Custom WordPress Login URL & Login Page Designer