
Rename wp-login.php to anything you want Security & Risk Analysis
wordpress.org/plugins/rename-wp-loginphp-to-anything-you-wantThis plugin changes the way you login into your website.
Is Rename wp-login.php to anything you want Safe to Use in 2026?
Generally Safe
Score 85/100Rename wp-login.php to anything you want has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "rename-wp-loginphp-to-anything-you-want" v2.0.1 exhibits a mixed security posture. On the positive side, the static analysis reveals a very small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events that are exposed without authentication. Furthermore, there are no known CVEs associated with this plugin, and it has a history of not having past vulnerabilities, suggesting a generally well-maintained codebase.
However, significant concerns arise from the code analysis. A substantial percentage (56%) of SQL queries are not using prepared statements, posing a risk of SQL injection if the inputs are not properly sanitized before being used in these queries. More critically, 0% of output escaping is properly implemented across 75 outputs. This is a major concern, as it leaves the plugin vulnerable to cross-site scripting (XSS) attacks, where malicious scripts could be injected into the website and executed in users' browsers.
The taint analysis, while small in scope, found three flows with unsanitized paths, which could potentially lead to file system vulnerabilities or other path traversal issues. While these did not reach critical or high severity in the analysis, they warrant attention. The presence of one external HTTP request and only one nonce check and one capability check might be acceptable given the plugin's apparent function, but the lack of output escaping is a severe weakness that overshadows other positive aspects of the plugin's security.
Key Concerns
- SQL queries not using prepared statements
- Output escaping not properly implemented
- Taint flows with unsanitized paths
Rename wp-login.php to anything you want Security Vulnerabilities
Rename wp-login.php to anything you want Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Rename wp-login.php to anything you want Attack Surface
WordPress Hooks 18
Maintenance & Trust
Rename wp-login.php to anything you want Maintenance & Trust
Maintenance Signals
Community Trust
Rename wp-login.php to anything you want Alternatives
WPS Hide Login
wps-hide-login
Change wp-login.php to anything you want.
Admin Login Hide – PTI
admin-login-hide-pti
Easily hide or customize your WordPress login URL to enhance security and prevent unauthorized access.
Swift WP-Login.php
swift-wp-login
Change Your wp-login.php to anything you want.
LoginPress | wp-login Custom Login Page Customizer
loginpress
LoginPress is a Custom Login Page Customizer plugin allows you to easily customize the layout of login, admin login, client login, register pages.
Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More
themeisle-companion
Add modules like share buttons, header & footer scripts, disable comments, reading progress bar, custom fonts, custom login page & more in one plugin.
Rename wp-login.php to anything you want Developer Profile
2 plugins · 600 total installs
How We Detect Rename wp-login.php to anything you want
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
rwl-settings-pageid="rwl-page-input"