My Custom Login Security & Risk Analysis

wordpress.org/plugins/my-custom-login

My Custom Login is the WordPress login plugin, allows site admin to add login/registration on their sites menu.

10 active installs v1.0.0 PHP + WP 4.3.1+ Updated Nov 18, 2015
customlog-inloginregisterregistration
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is My Custom Login Safe to Use in 2026?

Generally Safe

Score 85/100

My Custom Login has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The 'my-custom-login' plugin v1.0.0 exhibits a very strong security posture based on the provided static analysis and vulnerability history. There are no identified attack vectors like AJAX handlers, REST API routes, shortcodes, or cron events exposed by the plugin. Furthermore, the code signals indicate a lack of dangerous functions, all SQL queries are properly prepared, and all output is correctly escaped. The absence of file operations, external HTTP requests, and importantly, any identified nonce or capability checks, alongside a clean taint analysis, suggests a well-secured codebase. The plugin also has no recorded vulnerability history, further bolstering its perceived security. The primary concern, however, is the complete lack of capability checks and nonce checks. While the static analysis found no direct vulnerabilities, this absence means that even if the plugin were to introduce new entry points in the future, they might not be adequately protected against unauthorized access or cross-site request forgery attacks unless explicit authorization mechanisms are added. The plugin's strength lies in its clean code and lack of known issues, but its current design might not be robust enough for future expansion without careful security considerations.

Key Concerns

  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

My Custom Login Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

My Custom Login Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

My Custom Login Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
filterwp_nav_menu_itemsmy-custom-login.php:13
filterwp_nav_menu_itemsmy-custom-login.php:21
Maintenance & Trust

My Custom Login Maintenance & Trust

Maintenance Signals

WordPress version tested4.3.34
Last updatedNov 18, 2015
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

My Custom Login Developer Profile

Ajay Singh

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect My Custom Login

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about My Custom Login