
RefineURL – Hide login page, Redirect login attempt, Open link in new tab Security & Risk Analysis
wordpress.org/plugins/refineurlRefineURL is a light weight login page redirection plugin. It allows you to hide the login page from unauthorized users.
Is RefineURL – Hide login page, Redirect login attempt, Open link in new tab Safe to Use in 2026?
Generally Safe
Score 100/100RefineURL – Hide login page, Redirect login attempt, Open link in new tab has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The refineurl v1.1.10 plugin exhibits a strong security posture based on the provided static analysis. It demonstrates excellent practices by having zero identified AJAX handlers, REST API routes, shortcodes, or cron events, which significantly minimizes its attack surface. Furthermore, the absence of dangerous functions, file operations, and external HTTP requests, coupled with the exclusive use of prepared statements for SQL queries, indicates a robust approach to preventing common web vulnerabilities. The presence of nonce checks, although not on all entry points (since there are none), is a positive sign. The vulnerability history of zero recorded CVEs further reinforces this positive assessment, suggesting a well-maintained and secure codebase.
However, a notable concern arises from the output escaping analysis. With 38% of outputs properly escaped, there is a significant risk of Cross-Site Scripting (XSS) vulnerabilities. While the taint analysis did not reveal any unsanitized paths or critical/high severity flows, this could be due to the limited scope of the analysis or the specific nature of the plugin's functionality. The bundled Freemius library also warrants attention, as outdated bundled libraries can introduce unpatched vulnerabilities. Overall, the plugin is highly secure in terms of attack surface and data handling, but the unescaped output represents a tangible risk that needs immediate attention.
Key Concerns
- High percentage of unescaped output
- Bundled outdated library (Freemius v1.0)
RefineURL – Hide login page, Redirect login attempt, Open link in new tab Security Vulnerabilities
RefineURL – Hide login page, Redirect login attempt, Open link in new tab Release Timeline
RefineURL – Hide login page, Redirect login attempt, Open link in new tab Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
RefineURL – Hide login page, Redirect login attempt, Open link in new tab Attack Surface
WordPress Hooks 10
Maintenance & Trust
RefineURL – Hide login page, Redirect login attempt, Open link in new tab Maintenance & Trust
Maintenance Signals
Community Trust
RefineURL – Hide login page, Redirect login attempt, Open link in new tab Alternatives
WPHH SECURE – AIO WordPress Security With File Locking & WP Hide Login
wphhsecure
Secure your WordPress site with one-click file locking, login path hiding, role-based access, and smart dashboard visibility.
SharpLogin
sharp-login
With SharpLogin plugin you can get to play with Login screen.
RefineURL – Hide login page, Redirect login attempt, Open link in new tab Developer Profile
1 plugin · 0 total installs
How We Detect RefineURL – Hide login page, Redirect login attempt, Open link in new tab
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/refineurl/assets/css/admin-style.css/wp-content/plugins/refineurl/assets/js/admin-main-script.js/wp-content/plugins/refineurl/assets/js/admin-main-script.jsrefineurl/assets/css/admin-style.css?ver=refineurl/assets/js/admin-main-script.js?ver=