Ojasvi Custom Login Styler Security & Risk Analysis

wordpress.org/plugins/ojasvi-custom-login-styler

Short Description: Customize your WordPress login page logo, background and button colors easily from the dashboard.

0 active installs v1.3 PHP 7.2+ WP 5.0+ Updated Mar 5, 2026
brandingcustom-loginloginlogin-pagewp-login
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Ojasvi Custom Login Styler Safe to Use in 2026?

Generally Safe

Score 100/100

Ojasvi Custom Login Styler has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the 'ojasvi-custom-login-styler' v1.3 plugin exhibits a generally strong security posture. The absence of known CVEs, critical taint flows, dangerous functions, file operations, and external HTTP requests is highly encouraging. Furthermore, the plugin utilizes prepared statements for its SQL queries, which is a best practice for preventing SQL injection vulnerabilities.

However, there are a few areas that warrant attention. The complete lack of any nonce checks, capability checks, and any form of authorization for its entry points (AJAX, REST API, shortcodes, cron events) represents a significant potential blind spot. While the static analysis found no direct vulnerabilities in these areas for this specific version, this absence of fundamental security checks means that if any new functionality were to be added or existing functionality were to be manipulated in unexpected ways, it could be exploited. Additionally, the 28% of output that is not properly escaped, while not explicitly flagged as a critical issue in this analysis, could still pose a Cross-Site Scripting (XSS) risk in certain contexts.

In conclusion, the plugin has avoided common pitfalls and historical vulnerabilities, indicating a commitment to secure coding. The strengths lie in its clean handling of SQL and avoidance of known malicious functions. The primary weakness is the lack of robust authorization and input validation mechanisms on its entry points. While the current analysis doesn't reveal exploitable flaws, these omissions represent a latent risk that could be exploited if the plugin's functionality evolves or is attacked in novel ways.

Key Concerns

  • Missing nonce checks on entry points
  • Missing capability checks on entry points
  • Unescaped output detected
Vulnerabilities
None known

Ojasvi Custom Login Styler Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Ojasvi Custom Login Styler Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
11
28 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

72% escaped39 total outputs
Attack Surface

Ojasvi Custom Login Styler Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionadmin_menuojasvi-custom-login-styler.php:41
actionadmin_initojasvi-custom-login-styler.php:98
actionadmin_enqueue_scriptsojasvi-custom-login-styler.php:138
actionlogin_enqueue_scriptsojasvi-custom-login-styler.php:219
actionlogin_enqueue_scriptsojasvi-custom-login-styler.php:286
filterlogin_headerurlojasvi-custom-login-styler.php:294
filterlogin_headertextojasvi-custom-login-styler.php:299
Maintenance & Trust

Ojasvi Custom Login Styler Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 5, 2026
PHP min version7.2
Downloads128

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Ojasvi Custom Login Styler Developer Profile

virendra06

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Ojasvi Custom Login Styler

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ojasvi-custom-login-styler/css/style.css/wp-content/plugins/ojasvi-custom-login-styler/js/admin.js
Script Paths
/wp-content/plugins/ojasvi-custom-login-styler/js/admin.js
Version Parameters
ojasvi-custom-login-styler/css/style.css?ver=1.3ojasvi-custom-login-styler/js/admin.js?ver=1.3

HTML / DOM Fingerprints

CSS Classes
ocls-wrap
Data Attributes
id="upload_logo_button"id="ocls_logo"id="upload_bg_button"id="ocls_bg_image"class="ocls-color-field"
JS Globals
oclsAdmin
FAQ

Frequently Asked Questions about Ojasvi Custom Login Styler