OlalaWeb – Custom WP Login Security & Risk Analysis

wordpress.org/plugins/olalaweb-custom-wp-login

Customize your WP login screen with your own logo (from your Media Library) and resize the form with a few clicks.

10 active installs v1.0 PHP + WP 3.0.1+ Updated Nov 14, 2014
custom-loginloginlogin-formlogin-logoolalaweb
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is OlalaWeb – Custom WP Login Safe to Use in 2026?

Generally Safe

Score 85/100

OlalaWeb – Custom WP Login has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The "olalaweb-custom-wp-login" v1.0 plugin exhibits a mixed security posture. On the positive side, there are no recorded vulnerabilities (CVEs) and the plugin's static analysis indicates a remarkably small attack surface, with zero AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, all SQL queries appear to be using prepared statements, which is a strong security practice.

However, significant concerns arise from the output escaping and taint analysis. The fact that 0% of the 26 identified output points are properly escaped is a major red flag, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The taint analysis revealing 3 flows with unsanitized paths further strengthens this concern, although the absence of critical or high severity ratings in this area might suggest the unsanitized data doesn't directly lead to catastrophic outcomes within the current plugin logic, it's still a critical omission.

The lack of any recorded vulnerability history could imply either a very mature and secure plugin or that it hasn't been subjected to extensive security auditing or real-world attacks. Given the output escaping issues, the latter is more probable. In conclusion, while the plugin has a clean slate regarding known CVEs and a small attack surface, the critical lack of output escaping and the presence of unsanitized paths represent substantial security weaknesses that require immediate attention.

Key Concerns

  • 0% of output properly escaped
  • 3 flows with unsanitized paths
  • 0 capability checks
  • 0 nonce checks
Vulnerabilities
None known

OlalaWeb – Custom WP Login Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

OlalaWeb – Custom WP Login Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
26
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped26 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

3 flows3 with unsanitized paths
ola_ll_admin (ola-ll-settings.php:77)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

OlalaWeb – Custom WP Login Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_menuola-ll-settings.php:75
actionadmin_print_scriptsola-ll.php:31
actionadmin_print_stylesola-ll.php:32
actionlogin_enqueue_scriptsola-ll.php:88
Maintenance & Trust

OlalaWeb – Custom WP Login Maintenance & Trust

Maintenance Signals

WordPress version tested4.0.38
Last updatedNov 14, 2014
PHP min version
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

OlalaWeb – Custom WP Login Developer Profile

Matthieu

2 plugins · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect OlalaWeb – Custom WP Login

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/olalaweb-custom-wp-login/css/stylesheet.css/wp-content/plugins/olalaweb-custom-wp-login/js/script.js
Script Paths
/wp-content/plugins/olalaweb-custom-wp-login/js/script.js
Version Parameters
olalaweb-custom-wp-login/css/stylesheet.css?ver=olalaweb-custom-wp-login/js/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
loginhndle
Data Attributes
id="upload_image"id="upload_image_button"name="ola_upload_image"name="save_logo"name="save_sizes"
FAQ

Frequently Asked Questions about OlalaWeb – Custom WP Login