
RKM Custom Login Security & Risk Analysis
wordpress.org/plugins/rkm-loginA WordPress plugin for custom login page.
Is RKM Custom Login Safe to Use in 2026?
Generally Safe
Score 85/100RKM Custom Login has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The rkm-login v1.0.4 plugin exhibits a generally positive security posture based on the provided static analysis and vulnerability history. The absence of known CVEs and no recorded vulnerabilities in its history suggest a history of responsible development or fortunate circumvention of common issues. The code analysis shows a complete lack of dangerous functions, external HTTP requests, and file operations, which are common vectors for exploits. The use of prepared statements for all SQL queries is a significant strength, preventing SQL injection vulnerabilities. However, there are notable concerns. The low rate of properly escaped output (40%) indicates a potential risk of Cross-Site Scripting (XSS) vulnerabilities, as unsanitized output can be rendered and executed by user browsers. Furthermore, the complete absence of nonce checks and capability checks across all entry points is a critical weakness. This means that any user, regardless of their role or authentication status, could potentially trigger actions associated with the plugin's shortcode, opening the door to unauthorized operations if the shortcode performs sensitive actions. The small attack surface, consisting of only one shortcode, is a mitigating factor, but the lack of authentication/authorization on this single entry point remains a significant security gap.
Key Concerns
- Unescaped output detected
- Missing nonce checks on entry points
- Missing capability checks on entry points
RKM Custom Login Security Vulnerabilities
RKM Custom Login Release Timeline
RKM Custom Login Code Analysis
Output Escaping
RKM Custom Login Attack Surface
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
RKM Custom Login Maintenance & Trust
Maintenance Signals
Community Trust
RKM Custom Login Alternatives
Custom Login Page Customizer
colorlib-login-customizer
Customize your WordPress login page with live preview. Change logo, background, colors, and form styling without coding.
WP Custom Login
bm-custom-login
Customize the WordPress login screen with your own colors, logo, backgrounds, and form styles.
Loginfy – Custom Login Page Customizer plugin
loginfy
Custom login page customizer for WordPress. 16+ templates, live preview, white-label options. Perfect for agencies, businesses & freelancers brand …
CLP – Custom Login Page by NiteoThemes
clp-custom-login-page
Custom Login Page plugin allows you to customize any essential element on WordPress login page. It utilizes powerful customizer to implement changes i …
Login Page UI Customizer
login-page-ui-customizer
With Login Page UI Customizer customize your login page to make it look as beautiful as your website. Start your creative engine and get started now!
RKM Custom Login Developer Profile
2 plugins · 100 total installs
How We Detect RKM Custom Login
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/rkm-login/assets/img/rkmlogin02.png/wp-content/plugins/rkm-login/assets/img/rkmbcakground.png/wp-content/plugins/rkm-login/assets/img/rkmlogin2.pnghttps://cdn.jsdelivr.net/npm/bootstrap@3.3.7/dist/js/bootstrap.min.jsHTML / DOM Fingerprints
rkm-login-arearkm-login-brandingrkm-login-formrkm-login-comdivrkm-innerlogin-msgnotifinotifi2+2 moreplugin-dir-url('rkm-login/assets/img/rkmbcakground.png')plugin-dir-url('rkm-login/assets/img/rkmlogin2.png')rkm_post_slugrkmpage_title[rkm_login]