[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fS32XymWoOs3nR6qwV7AW4oAg6rwxmhasSwndWfe1tio":3},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":14,"last_updated":15,"tested_up_to":16,"requires_at_least":17,"requires_php":18,"tags":19,"homepage":24,"download_link":25,"security_score":26,"vuln_count":27,"unpatched_count":27,"last_vuln_date":28,"fetched_at":29,"vulnerabilities":30,"developer":31,"crawl_stats":28,"alternatives":38,"analysis":146,"fingerprints":417},"sb-login","SB Login","2.5","Fida Al Hasan","https:\u002F\u002Fprofiles.wordpress.org\u002Ffida02\u002F","\u003Cp>Sb login widget that allows a user to login, register, reset their password, see recent activity, time, post and comment count, author info, in one place. You can also customize wordpress mail from name and address.\u003C\u002Fp>\n\u003Ch4>Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>A login and registration widget for your blog\u003C\u002Fli>\n\u003Cli>Tabs\u002Flinks for logged out users include login, register, and ‘lost password’.\u003C\u002Fli>\n\u003Cli>Captcha functionality included.\u003C\u002Fli>\n\u003Cli>Logged in users can see their name, avatar, logged in date, and comments\u002Fposts since sign in.\u003C\u002Fli>\n\u003Cli>User can see his\u002Fher recent viewed posts and recent comments made by him\u002Fher.\u003C\u002Fli>\n\u003Cli>User can see his ID, First joined date, total number of his\u002Fher posts, total number of comments made by him\u002Fher, user level, posts feed, comments feed.\u003C\u002Fli>\n\u003Cli>AJAX validation makes this thing run smooth\u003C\u002Fli>\n\u003Cli>Shortcode & PHP Code if you don’t want to use widget\u003C\u002Fli>\n\u003Cli>Options page for customizing the plugin\u003C\u002Fli>\n\u003Cli>User can add extra link\u003C\u002Fli>\n\u003Cli>This plugin is so light\u003C\u002Fli>\n\u003Cli>Smart & nice looking. You love it.\u003C\u002Fli>\n\u003Cli>Nice warning & success system.\u003C\u002Fli>\n\u003Cli>You can translate this plugin.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Translations\u003C\u002Fh4>\n\u003Cp>Available translations are listed in the plugin’s admin page\u003C\u002Fp>\n\u003Cp>If you have made a translation file please send it to this \u003Ca href=\"mailto:fidaalhasan@gmail.com\" rel=\"nofollow ugc\">mail\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>Why dont you rate the plugin if you like it !! 🙂\u003C\u002Fp>\n\u003Cp>Our team \u003Ca href=\"http:\u002F\u002Fwebcarezone.com\u002F\" rel=\"nofollow ugc\">Web Care Zone\u003C\u002Fa>.\u003C\u002Fp>\n","Sb login widget that allows a user to login, register, reset their password, see recent activity,time,post and comment count & many more in one pl &hellip;",70,36276,80,24,"2014-05-23T09:38:00.000Z","3.9.40","2.8","",[20,21,4,22,23],"login","sb","sidebar-login-widget","wordpress-login-widget","http:\u002F\u002Fwebcarezone.com\u002Fprojects\u002Fsb-login.asp","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fsb-login.2.5.zip",85,0,null,"2026-03-15T15:16:48.613Z",[],{"slug":32,"display_name":7,"profile_url":8,"plugin_count":33,"total_installs":13,"avg_security_score":34,"avg_patch_time_days":35,"trust_score":36,"computed_at":37},"fida02",2,93,30,89,"2026-04-04T17:07:06.961Z",[39,60,78,102,124],{"slug":40,"name":41,"version":42,"author":43,"author_profile":44,"description":45,"short_description":46,"active_installs":47,"downloaded":48,"rating":49,"num_ratings":50,"last_updated":51,"tested_up_to":52,"requires_at_least":53,"requires_php":18,"tags":54,"homepage":58,"download_link":59,"security_score":26,"vuln_count":27,"unpatched_count":27,"last_vuln_date":28,"fetched_at":29},"sb-login-page","SB Login Page","1.1.1","skylarkcob","https:\u002F\u002Fprofiles.wordpress.org\u002Fskylarkcob\u002F","\u003Cp>SB Login Page is a plugin that allows user to custom WordPress login page. You can change login page logo image, update the default logo url to home page.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Required Plugin\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fsb-core\u002F\" rel=\"ugc\">SB Core\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Translations\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>English\u003C\u002Fli>\n\u003Cli>Vietnamese\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Recommended WordPress Plugins\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fsb-banner-widget\u002F\" rel=\"ugc\">SB Banner Widget\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fsb-clean\u002F\" rel=\"ugc\">SB Clean\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fsb-comment\u002F\" rel=\"ugc\">SB Comment\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fsb-paginate\u002F\" rel=\"ugc\">SB Paginate\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fsb-post-widget\u002F\" rel=\"ugc\">SB Post Widget\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fsb-tab-widget\u002F\" rel=\"ugc\">SB Tab Widget\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fsb-tbfa\u002F\" rel=\"ugc\">SB TBFA\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n","SB Login Page is a plugin that allows user to custom WordPress login page.",10,2569,100,1,"2015-04-09T01:28:00.000Z","4.1.42","3.9",[21,40,55,56,57],"sb-plugin","sb-team","wordpress-login","http:\u002F\u002Fhocwp.net\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fsb-login-page.zip",{"slug":61,"name":62,"version":63,"author":64,"author_profile":65,"description":66,"short_description":67,"active_installs":47,"downloaded":68,"rating":27,"num_ratings":27,"last_updated":69,"tested_up_to":70,"requires_at_least":71,"requires_php":18,"tags":72,"homepage":76,"download_link":77,"security_score":26,"vuln_count":27,"unpatched_count":27,"last_vuln_date":28,"fetched_at":29},"iw-profile","iw profile","1.4","Hamid Alinia","https:\u002F\u002Fprofiles.wordpress.org\u002Fglboy\u002F","\u003Cp>iw profile widget that allows a user to login, register, reset their password, see recent activity, time, post and comment count, author info, in one place. You can also customize wordpress mail from name and address.\u003C\u002Fp>\n\u003Ch4>Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>A login and registration widget for your blog\u003C\u002Fli>\n\u003Cli>Tabs\u002Flinks for logged out users include login, register, and ‘lost password’.\u003C\u002Fli>\n\u003Cli>Captcha functionality included.\u003C\u002Fli>\n\u003Cli>Logged in users can see their name, avatar, logged in date, and comments\u002Fposts since sign in.\u003C\u002Fli>\n\u003Cli>User can see his\u002Fher recent viewed posts and recent comments made by him\u002Fher.\u003C\u002Fli>\n\u003Cli>User can see his ID, First joined date, total number of his\u002Fher posts, total number of comments made by him\u002Fher, user level, posts feed, comments feed.\u003C\u002Fli>\n\u003Cli>AJAX validation makes this thing run smooth\u003C\u002Fli>\n\u003Cli>Shortcode & PHP Code if you don’t want to use widget\u003C\u002Fli>\n\u003Cli>Options page for customizing the plugin\u003C\u002Fli>\n\u003Cli>User can add extra link\u003C\u002Fli>\n\u003Cli>This plugin is so light\u003C\u002Fli>\n\u003Cli>Smart & nice looking. You love it.\u003C\u002Fli>\n\u003Cli>Nice warning & success system.\u003C\u002Fli>\n\u003Cli>You can translate this plugin.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Translations\u003C\u002Fh4>\n\u003Cp>Available translations are listed in the plugin’s admin page\u003C\u002Fp>\n\u003Cp>If you have made a translation file please send it to this \u003Ca href=\"mailto:a.goodlookingboy@gmail.com\" rel=\"nofollow ugc\">mail\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>Why dont you rate the plugin if you like it !! 🙂\u003C\u002Fp>\n\u003Cp>Our team \u003Ca href=\"http:\u002F\u002Fidehweb.com\u002F\" rel=\"nofollow ugc\">IDehweb\u003C\u002Fa>.\u003C\u002Fp>\n","iw profile is a login\u002Fregister form and profile which you need to set frontend beautiful profile and special use when you have set up woocommerce.",1641,"2016-05-27T12:06:00.000Z","4.4.34","3.2",[73,74,20,75,22],"iw","iw-login","profile","http:\u002F\u002FIDEHWEB.com","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fiw-profile.1.4.zip",{"slug":79,"name":80,"version":81,"author":82,"author_profile":83,"description":84,"short_description":85,"active_installs":86,"downloaded":87,"rating":88,"num_ratings":89,"last_updated":90,"tested_up_to":91,"requires_at_least":92,"requires_php":18,"tags":93,"homepage":18,"download_link":99,"security_score":88,"vuln_count":100,"unpatched_count":27,"last_vuln_date":101,"fetched_at":29},"limit-login-attempts-reloaded","Limit Login Attempts Reloaded – Login Security, Brute Force Protection, Firewall","2.26.28","WPChef","https:\u002F\u002Fprofiles.wordpress.org\u002Fwpchefgadget\u002F","\u003Cp>\u003Ca href=\"https:\u002F\u002Fwww.limitloginattempts.com\" rel=\"nofollow ugc\">Limit Login Attempts Reloaded\u003C\u002Fa> functions as a robust deterrent against \u003Ca href=\"https:\u002F\u002Fwww.limitloginattempts.com\u002Fcracking-the-code-unveiling-the-mechanics-behind-brute-force-attacks\u002F\" rel=\"nofollow ugc\">brute force attacks\u003C\u002Fa>, bolstering your website’s security measures and optimizing its performance. It achieves this by \u003Cstrong>restricting the number of login attempts allowed\u003C\u002Fstrong>. This applies not only to the standard login method, but also to XMLRPC, Woocommerce, and custom login pages. With more than 2.5 million active users, this plugin fulfills all your login security requirements.\u003C\u002Fp>\n\u003Cp>The plugin functions by automatically preventing further attempts from a particular Internet Protocol (IP) address and\u002For username once a predetermined limit of retries has been surpassed. This significantly weakens the effectiveness of brute force attacks on your website.\u003C\u002Fp>\n\u003Cp>By default, WordPress permits an unlimited number of login attempts, posing a vulnerability where passwords can be easily deciphered through brute force methods.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Limit Login Attempts Reloaded Premium (Try Free with \u003Ca href=\"https:\u002F\u002Fwww.limitloginattempts.com\u002Fpremium-security-zero-cost-discover-the-benefits-of-micro-cloud\u002F\" rel=\"nofollow ugc\">Micro Cloud\u003C\u002Fa>)\u003C\u002Fstrong>\u003Cbr \u002F>\nUpgrade to \u003Ca href=\"https:\u002F\u002Fwww.limitloginattempts.com\u002Fplans\u002F\" rel=\"nofollow ugc\">Limit Login Attempts Reloaded Premium\u003C\u002Fa> to extend cloud-based protection to the Limit Login Attempts Reloaded plugin, thereby enhancing your login security. The premium version includes a range of highly beneficial features, including \u003Ca href=\"https:\u002F\u002Fwww.limitloginattempts.com\u002Ffeatures\u002Fip-intelligence\u002F\" rel=\"nofollow ugc\">IP intelligence\u003C\u002Fa> to \u003Cstrong>detect, counter and deny malicious login attempts\u003C\u002Fstrong>. Your \u003Ca href=\"https:\u002F\u002Fwww.limitloginattempts.com\u002Ffailed-login-attempts-in-wordpress\u002F\" rel=\"nofollow ugc\">failed login attempts\u003C\u002Fa> will be safely neutralized in the cloud so your website can function at its optimal performance during an attack.\u003C\u002Fp>\n\u003Cp>\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002FJfkvIiQft14?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\u003C\u002Fp>\n\u003Ch4>Features (Free Version):\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>2FA\u003C\u002Fstrong> – Coming soon.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Limit Logins\u003C\u002Fstrong> – Limit the number of retry attempts when logging in (per each IP).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Configurable Lockout Timings\u003C\u002Fstrong> – Modify the amount of time a user or IP must wait after a lockout.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Remaining Tries\u003C\u002Fstrong> – Informs the user about the remaining retries or lockout time on the login page.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Lockout Email Notifications\u003C\u002Fstrong> – Informs the admin via email of lockouts.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Denied Attempt Logs\u003C\u002Fstrong> – View a log of all denied attempts and lockouts.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>IP & Username Safelist\u002FDenylist\u003C\u002Fstrong> – Control access to usernames and IPs.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>New User Registration Protection (Micro Cloud Accounts)\u003C\u002Fstrong> – Protects default WP registration.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Sucuri\u003C\u002Fstrong> compatibility.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Wordfence\u003C\u002Fstrong> compatibility.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Ultimate Member\u003C\u002Fstrong> compatibility.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WPS Hide Login\u003C\u002Fstrong> compatibility.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>MemberPress\u003C\u002Fstrong> compatibility.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>XMLRPC\u003C\u002Fstrong> gateway protection.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Woocommerce\u003C\u002Fstrong> login page protection.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Multi-site compatibility\u003C\u002Fstrong> with extra MU settings.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>GDPR\u003C\u002Fstrong> compliant.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Custom IP origins support\u003C\u002Fstrong> (Cloudflare, Sucuri, etc.).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>llar_admin\u003C\u002Fstrong> own capability.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Features (Premium Version):\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Performance Optimizer\u003C\u002Fstrong> – Offload the burden of excessive failed logins from your server to protect your server resources, resulting in improved speed and efficiency of your website.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Enhanced IP Intelligence\u003C\u002Fstrong> – Identify repetitive and suspicious login attempts to detect potential brute force attacks. IPs with known malicious activity are stored and used to help prevent and counter future attacks.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Enhanced Throttling\u003C\u002Fstrong> – Longer lockout intervals each time a malicious IP or username tries to login unsuccessfully.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Deny By Country\u003C\u002Fstrong> – \u003Ca href=\"https:\u002F\u002Fwww.limitloginattempts.com\u002Fblock-logins-by-country-in-wordpress\u002F\" rel=\"nofollow ugc\">Block logins by country\u003C\u002Fa> by simply selecting the countries you want to deny.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Auto IP Denylist\u003C\u002Fstrong> – Automatically add IP addresses to your active cloud deny list that repeatedly fail login attempts.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>New User Registration Protection\u003C\u002Fstrong> – Protects default WP registration.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Global Denylist Protection\u003C\u002Fstrong> – Utilize our active cloud IP data from thousands of websites in the LLAR network.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Synchronized Lockouts\u003C\u002Fstrong> –  Lockout IP data can be shared between multiple domains for enhanced protection in your network.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Synchronized Safelist\u002FDenylist\u003C\u002Fstrong> – Safelist\u002FDenylist IP and username data can be shared between multiple domains.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Premium Support\u003C\u002Fstrong> – Email support with a security tech.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Auto Backups of All IP Data\u003C\u002Fstrong> – Store your active IP data in the cloud.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Successful Logins Log\u003C\u002Fstrong> – Store successful logins in the cloud including IP info, city, state and lat\u002Flong.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Enhanced lockout logs\u003C\u002Fstrong> – Gain valuable insights into the origins of IPs that are attempting logins.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>CSV Download of IP Data\u003C\u002Fstrong> – Download IP data direclty from the cloud.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Supports IPV6 Ranges For Safelist\u002FDenylist\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Unlock The Locked Admin\u003C\u002Fstrong> – Easily \u003Ca href=\"https:\u002F\u002Fwww.limitloginattempts.com\u002Fhow-to-unlock-your-site-if-you-are-locked-out-by-limit-login-attempts-reloaded\u002F\" rel=\"nofollow ugc\">unlock the locked admin\u003C\u002Fa> through the cloud.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>*Some features require higher level plans.\u003C\u002Fp>\n\u003Ch4>Upgrading from the old Limit Login Attempts plugin?\u003C\u002Fh4>\n\u003Col>\n\u003Cli>Go to the Plugins section in your site’s backend.\u003C\u002Fli>\n\u003Cli>Remove the Limit Login Attempts plugin.\u003C\u002Fli>\n\u003Cli>Install the Limit Login Attempts Reloaded plugin.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>All your settings will be kept intact!\u003C\u002Fp>\n\u003Cp>Many languages are currently supported in the Limit Login Attempts Reloaded plugin but we welcome any additional ones.\u003C\u002Fp>\n\u003Cp>Help us bring Limit Login Attempts Reloaded to even more countries.\u003C\u002Fp>\n\u003Cp>Translations: Bulgarian, Brazilian Portuguese, Catalan, Chinese (Traditional), Czech, Dutch, Finnish, French, German, Hungarian, Norwegian, Persian, Romanian, Russian, Spanish, Swedish, Turkish\u003C\u002Fp>\n\u003Cp>Plugin uses standard actions and filters only.\u003C\u002Fp>\n\u003Cp>Based on the original code from Limit Login Attempts plugin by Johan Eenfeldt.\u003C\u002Fp>\n\u003Ch4>Branding Guidelines\u003C\u002Fh4>\n\u003Cp>Limit Login Attempts Reloaded™ is a trademark of Atlantic Silicon Inc. When writing about the plugin, please make sure to use Reloaded after Limit Login Attempts. Limit Login Attempts is the old plugin.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Limit Login Attempts Reloaded (correct)\u003C\u002Fli>\n\u003Cli>Limit Login Attempts (incorrect)\u003C\u002Fli>\n\u003C\u002Ful>\n","Block excessive login attempts and protect your site against brute force attacks. Simple, yet powerful tools to improve site performance.",2000000,79399145,98,1441,"2026-01-12T16:01:00.000Z","6.9.4","3.0",[94,95,96,97,98],"2fa","brute-force","firewall","login-security","security","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Flimit-login-attempts-reloaded.2.26.28.zip",4,"2023-12-20 00:00:00",{"slug":103,"name":104,"version":105,"author":106,"author_profile":107,"description":108,"short_description":109,"active_installs":86,"downloaded":110,"rating":111,"num_ratings":112,"last_updated":113,"tested_up_to":91,"requires_at_least":114,"requires_php":115,"tags":116,"homepage":18,"download_link":121,"security_score":122,"vuln_count":47,"unpatched_count":27,"last_vuln_date":123,"fetched_at":29},"wps-hide-login","WPS Hide Login","1.9.18","Remy Perona","https:\u002F\u002Fprofiles.wordpress.org\u002Ftabrisrp\u002F","\u003Ch4>English\u003C\u002Fh4>\n\u003Cp>\u003Cem>WPS Hide Login\u003C\u002Fem> is a very light plugin that lets you easily and safely change the url of the login form page to anything you want. It doesn’t literally rename or change files in core, nor does it add rewrite rules. It simply intercepts page requests and works on any WordPress website. The wp-admin directory and wp-login.php page become inaccessible, so you should bookmark or remember the url. Deactivating this plugin brings your site back exactly to the state it was before.\u003C\u002Fp>\n\u003Cp>This plugin is kindly proposed by \u003Ca href=\"https:\u002F\u002Fwww.wpserveur.net\u002F?refwps=14&campaign=wpshidelogin\" rel=\"nofollow ugc\">WPServeur\u003C\u002Fa> the specialized WordPress web host.\u003C\u002Fp>\n\u003Cp>Discover also our other free extensions:\u003Cbr \u002F>\n– \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fwps-limit-login\u002F\" rel=\"ugc\">WPS Limit Login\u003C\u002Fa> to block brute force attacks.\u003Cbr \u002F>\n– \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fwps-bidouille\u002F\" rel=\"ugc\">WPS Bidouille\u003C\u002Fa> to optimize your WordPress and get more info.\u003Cbr \u002F>\n– \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fwps-cleaner\u002F\" rel=\"ugc\">WPS Cleaner\u003C\u002Fa> to clean your WordPress site.\u003C\u002Fp>\n\u003Cp>This plugin is only maintained, which means we do not guarantee free support. Consider reporting a problem and be patient.\u003C\u002Fp>\n\u003Ch4>Français\u003C\u002Fh4>\n\u003Cp>\u003Cem>WPS Hide Login\u003C\u002Fem> est un plugin très léger qui vous permet de changer facilement et en toute sécurité l’url de la page de formulaire de connexion. Il ne renomme pas littéralement ou ne modifie pas les fichiers dans le noyau, ni n’ajoute des règles de réécriture. Il intercepte simplement les demandes de pages et fonctionne sur n’importe quel site WordPress. Le répertoire wp-admin et la page wp-login.php deviennent inaccessibles, vous devez donc ajouter un signet ou vous souvenir de l’URL. Désactiver ce plugin ramène votre site exactement à l’état dans lequel il était auparavant.\u003C\u002Fp>\n\u003Cp>Ce plugin vous est gentiment proposé par \u003Ca href=\"https:\u002F\u002Fwww.wpserveur.net\u002F?refwps=14&campaign=wpshidelogin\" rel=\"nofollow ugc\">WPServeur\u003C\u002Fa> l’hébergeur spécialisé WordPress.\u003C\u002Fp>\n\u003Cp>Plus d’infos sur son utilisation : \u003Ca href=\"https:\u002F\u002Fwpformation.com\u002Fwps-hide-login-url-connexion-wordpress\u002F\" rel=\"nofollow ugc\">https:\u002F\u002Fwpformation.com\u002Fwps-hide-login-url-connexion-wordpress\u002F\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>Découvrez également nos autres extensions gratuites :\u003Cbr \u002F>\n– \u003Ca href=\"https:\u002F\u002Ffr.wordpress.org\u002Fplugins\u002Fwps-limit-login\u002F\" rel=\"nofollow ugc\">WPS Limit Login\u003C\u002Fa> pour bloquer les attaques par force brute.\u003Cbr \u002F>\n– \u003Ca href=\"https:\u002F\u002Ffr.wordpress.org\u002Fplugins\u002Fwps-bidouille\u002F\" rel=\"nofollow ugc\">WPS Bidouille\u003C\u002Fa> pour optimiser votre WordPress et faire le plein d’infos.\u003Cbr \u002F>\n– \u003Ca href=\"https:\u002F\u002Ffr.wordpress.org\u002Fplugins\u002Fwps-cleaner\u002F\" rel=\"nofollow ugc\">WPS Cleaner\u003C\u002Fa> pour nettoyer votre site WordPress.\u003C\u002Fp>\n\u003Cp>Ce plugin est seulement maintenu, ce qui signifie que nous ne garantissons pas un support gratuit. Envisagez de signaler un problème et soyez patient.\u003C\u002Fp>\n\u003Ch4>Compatibility\u003C\u002Fh4>\n\u003Ch4>English\u003C\u002Fh4>\n\u003Cp>Requires WordPress 4.1 or higher. All login related things such as the registration form, lost password form, login widget and expired sessions just keep working.\u003C\u002Fp>\n\u003Cp>It’s also compatible with any plugin that hooks in the login form, including:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>BuddyPress,\u003C\u002Fli>\n\u003Cli>bbPress,\u003C\u002Fli>\n\u003Cli>Jetpack,\u003C\u002Fli>\n\u003Cli>WPS Limit Login,\u003C\u002Fli>\n\u003Cli>and User Switching.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Obviously it doesn’t work with plugins or themes that \u003Cem>hardcoded\u003C\u002Fem> wp-login.php.\u003C\u002Fp>\n\u003Cp>Works with multisite, with subdomains and subfolders. Activating it for a network allows you to set a networkwide default. Individual sites can still rename their login page to something else.\u003C\u002Fp>\n\u003Cp>If you’re using a \u003Cstrong>page caching plugin\u003C\u002Fstrong> other than WP Rocket, you should add the slug of the new login url to the list of pages not to cache. WP Rocket is already fully compatible with the plugin.\u003C\u002Fp>\n\u003Ch4>Français\u003C\u002Fh4>\n\u003Cp>Nécessite WordPress 4.1 ou supérieur. Toutes les choses liées à la connexion telles que le formulaire d’inscription, le formulaire de mot de passe perdu, le widget de connexion et les sessions expirées continuent de fonctionner.\u003C\u002Fp>\n\u003Cp>Il est également compatible avec tout plugin qui se connecte au formulaire de connexion, notamment:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>BuddyPress,\u003C\u002Fli>\n\u003Cli>bbPress,\u003C\u002Fli>\n\u003Cli>Jetpack,\u003C\u002Fli>\n\u003Cli>WPS Limit Login,\u003C\u002Fli>\n\u003Cli>and User Switching.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Évidemment, cela ne fonctionne pas avec les plugins ou les thèmes \u003Cem>hardcoded\u003C\u002Fem> wp-login.php.\u003C\u002Fp>\n\u003Cp>Fonctionne en multisite, avec sous-domaines ou sous dossiers. L’activer pour un réseau vous permet de définir une valeur par défaut pour l’ensemble du réseau. Les sites individuels peuvent toujours renommer leur page de connexion pour autre chose.\u003C\u002Fp>\n\u003Cp>Si vous utilisez un \u003Cstrong>plugin de mise en cache de pages\u003C\u002Fstrong> autre que WP Rocket, vous devez ajouter le slug de la nouvelle URL de connexion à la liste des pages à ne pas mettre en cache. WP Rocket est déjà entièrement compatible avec le plugin.\u003C\u002Fp>\n","Change wp-login.php to anything you want.",30498017,96,2101,"2026-01-12T08:47:00.000Z","4.1","7.0",[117,20,118,119,120],"custom-login-url","rename","wp-login","wp-login-php","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwps-hide-login.1.9.18.zip",95,"2024-06-24 00:00:00",{"slug":125,"name":126,"version":127,"author":128,"author_profile":129,"description":130,"short_description":131,"active_installs":132,"downloaded":133,"rating":134,"num_ratings":135,"last_updated":136,"tested_up_to":91,"requires_at_least":137,"requires_php":138,"tags":139,"homepage":142,"download_link":143,"security_score":34,"vuln_count":144,"unpatched_count":27,"last_vuln_date":145,"fetched_at":29},"all-in-one-wp-security-and-firewall","All-In-One Security (AIOS) – Security and Firewall","5.4.6","David Anderson \u002F Team Updraft","https:\u002F\u002Fprofiles.wordpress.org\u002Fdavidanderson\u002F","\u003Ch3>THE TOP RATED WORDPRESS SECURITY AND FIREWALL PLUGIN\u003C\u002Fh3>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fteamupdraft.com\u002Fall-in-one-security?utm_source=aios-wp-dir&utm_medium=referral&utm_campaign=plugin-dir&utm_content=aios&utm_creative_format=description\" rel=\"nofollow ugc\">All-in-One Security (AIOS)\u003C\u002Fa> is a WordPress security plugin from the same, trusted team that brought you UpdraftPlus.\u003C\u002Fp>\n\u003Cp>It’s called ‘All-In-One’ because it’s packed full of ways to keep your WordPress website(s) safe and secure.\u003C\u002Fp>\n\u003Cp>It includes:\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Login security features\u003C\u002Fstrong> keep bots at bay. Lock out users based on a configurable number of login attempts, get two-factor authentication and more.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>File and database security.\u003C\u002Fstrong> Get notified of file changes that occur outside of normal operations. Block access to key files and scan files and folders to spot insecure permissions.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Firewall.\u003C\u002Fstrong> Get PHP, .htaccess and 6G firewall rules courtesy of Perishable Press. Spot and block fake Google Bots and more!\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Spam prevention.\u003C\u002Fstrong> Prevent annoying spam comments and reduce unnecessary load on the server. Automatically and permanently block IP addresses that exceed a set number of spam comments.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Audit log.\u003C\u002Fstrong> View events happening on your WordPress website. Find out if a plugin or theme has been added, removed, updated and more.\u003C\u002Fp>\n\u003Ch4>WHY ALL-IN-ONE SECURITY?\u003C\u002Fh4>\n\u003Cp>AIOS has a near-perfect \u003Cstrong>4.7 \u002F 5-star user rating\u003C\u002Fstrong> across more than 1 million installs.\u003C\u002Fp>\n\u003Cp>Great for beginners and experts alike. AIOS guides you logically and clearly through each of its features which are all clearly explained. Security features are marked as basic, intermediate and advanced. Each step increases your security score. Turn them on and watch your protection grow!\u003C\u002Fp>\n\u003Cp>We have a large support team of software developers. That means we have the availability and the skillset to help you with the trickiest of queries.\u003C\u002Fp>\n\u003Cp>We comb the WordPress plugin directory for support tickets daily – most queries are responded to within 24 hours.\u003C\u002Fp>\n\u003Cp>\u003Cem>Excellent plugin with numerous well-thought-out options for making a website more secure. I have been using it for years and am very happy with it. I recently had a small problem setting up a website and – even as a non-premium user – I received support very quickly. Highly recommended!\u003C\u002Fem>\u003C\u002Fp>\n\u003Cp>For even more ways to stay safe and secure, upgrade to \u003Ca href=\"https:\u002F\u002Fteamupdraft.com\u002Fall-in-one-security\u002Fpricing?utm_source=aios-wp-dir&utm_medium=referral&utm_campaign=plugin-dir&utm_content=aios_premium&utm_creative_format=description\" rel=\"nofollow ugc\">AIOS Premium\u003C\u002Fa> – it packs a punch security-wise, whilst being \u003Cstrong>extremely cost-competitive\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Ch4>LOGIN SECURITY\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Two-factor authentication (TFA)\u003C\u002Fstrong> – Require TFA for specific user roles. Supports Google Authenticator, Microsoft Authenticator, Authy, and many more.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Detect and manage ‘admin’ usernames\u003C\u002Fstrong> – Identify default ‘admin’ usernames and guide users to change them to protect against brute force attacks.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Identify and correct identical login and display names\u003C\u002Fstrong> – Detect cases where the display name matches the username and provide guidance to improve login security.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Prevent user enumeration\u003C\u002Fstrong> – Block unauthorised access to URLs that can reveal sensitive information such as usernames or other details.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Control login attempts\u003C\u002Fstrong> – Prevent brute force attacks by limiting the number of failed login attempts. Choose how many login attempts are allowed, set lockout durations, and more.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Force user logout\u003C\u002Fstrong> – Automatically log out users after a specified period of time. Unattended sessions are closed, reducing the risk of unauthorised access.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Manually approve new registrations\u003C\u002Fstrong> – Review and approve new user registrations to prevent spam and fake sign-ups.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Enhance WordPress salt security\u003C\u002Fstrong> – Adds 64 extra characters to WordPress salts, rotating them weekly. Makes cracking passwords virtually impossible, even if your database is stolen.\u003C\u002Fp>\n\u003Ch4>Plugin Support\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>If you have a question or problem with the All-In-One Security plugin, post it on the support forum and we will help you. Premium customers can log queries directly with the team via https:\u002F\u002Fteamupdraft.com\u002Fall-in-one-security\u002F\u003Cbr \u002F>\n\u003Cstrong>Monitor and manage active sessions\u003C\u002Fstrong> – If a user is logged in who shouldn’t be, log them out or add them to a blacklist.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>SPAM PREVENTION\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Block spam coming from bots\u003C\u002Fstrong> – Reduce the load on your server and improve the user experience by automatically blocking spam comments from bots.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Monitor spam IP addresses\u003C\u002Fstrong> – Monitor the IP addresses of people or bots leaving spam comments. Choose which ones to block based on a configurable number of comments left.\u003C\u002Fp>\n\u003Ch4>FILE \u002F DATABASE Security\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Scan and fix file permissions\u003C\u002Fstrong> – Scan for insecure file permissions. Click once to fix issues and safeguard critical files and folders.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Disable PHP file editing\u003C\u002Fstrong> – Disable editing of PHP files (such as plugins and themes) via the dashboard. It’s often the first tool that attackers use as it allows for code execution.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Protect sensitive files\u003C\u002Fstrong> – Prevent access to files like readme.html that might reveal information about your WordPress installation.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>File change scanner\u003C\u002Fstrong> – Get notified of any file changes which occur on your system. Exclude files and folders which change as part of normal operations.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Prevent image hotlinking\u003C\u002Fstrong> – Prevent other websites from displaying your images via hotlinking and protect server bandwidth.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Secure database backups\u003C\u002Fstrong> – Perform a database backup via UpdraftPlus from AIOS. Change the default ‘wp_’ prefix to hide your WordPress database from hackers.\u003C\u002Fp>\n\u003Ch4>FIREWALL\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Get .htaccess firewall rules\u003C\u002Fstrong> – Deny access to the .htaccess and wp-config.php files. Disable the server signature and limit file uploads to a configurable size.**\u003C\u002Fp>\n\u003Cp>Block access to the debug.log file and prevent Apache servers from listing the contents of a directory when an index.php file is not present\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Get PHP firewall rules\u003C\u002Fstrong> – PHP firewall rules prevent malicious users from exploiting well-known vulnerabilities in XML-RPC. Safeguard your content by disabling RSS and Atom feeds and avoid cross-site scripting (XSS) attacks.\u003Cbr \u002F>\nBlock fake Google bots and POST requests made by bots – Block fake Google bots and stop bots from making POST requests by blocking IP addresses where the user-agent and referrer fields are blank.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Utilise 6G firewall rules\u003C\u002Fstrong> – Employ flexible blacklist rules to reduce the number of malicious URL requests that hit your website (courtesy of Perishable Press).\u003C\u002Fp>\n\u003Cp>\u003Cstrong>And more\u003C\u002Fstrong> – Blacklist (and whitelist) IP ranges and user agents and block unauthorized access to data by disabling REST API access for non-logged-in requests.\u003C\u002Fp>\n\u003Ch4>TWO-FACTOR AUTHENTICATION ENHANCED [Premium]\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Two-factor authentication\u003C\u002Fstrong> is included in the free plugin. Upgrade to Premium if you’d like to:\u003Cbr \u002F>\nRequire TFA after a set time period – Mandate TFA for all admins or other roles after their accounts reach a specified age.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Control how often TFA is required\u003C\u002Fstrong> – Set TFA to be required after a certain number of days on trusted devices instead of every login.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Customise design layout\u003C\u002Fstrong> – Adjust the TFA design to match your website’s existing layout and branding.\u003Cbr \u002F>\nEmergency codes – Generate one-time use emergency codes to regain access if you lose your TFA device.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>WordPress Multisite Compatible\u003C\u002Fstrong> – Ensure compatibility with WordPress multisite networks and their sub-sites for consistent TFA application.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Integration with login forms\u003C\u002Fstrong> – Integrate TFA with various login forms, including WooCommerce, Affiliates-WP, Elementor Pro, bbPress, and ‘Theme My Login’ without additional coding.\u003C\u002Fp>\n\u003Ch4>SMART 404 BLOCKING [Premium]\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Block IPs based on 404 errors\u003C\u002Fstrong> – Detect hackers probing your URLs via script and bots by the 404 errors they leave behind.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Smart 404 Configuration\u003C\u002Fstrong> – Set a figure for the maximum number of 404 events allowed before an IP address is blocked. Choose a time period within which the 404 events must occur (e.g., 10 errors within 10 minutes).\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Smart 404 block by URL string\u003C\u002Fstrong> – Instantly block an IP address if a 404 event includes a specific URL string.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Smart 404 whitelisting\u003C\u002Fstrong> – Prevent particular IP addresses from being permanently blocked due to 404 events.\u003C\u002Fp>\n\u003Ch4>COUNTRY BLOCKING [Premium]\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Block traffic to the entire site or to specific pages or posts\u003C\u002Fstrong> – Useful if you’re an e-commerce site and you want to block sales to some countries for shipping or tax reasons.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Whitelist some users from blocked countries\u003C\u002Fstrong> – Whitelist IP addresses or IP ranges even if they are part of a blocked country.\u003C\u002Fp>\n\u003Ch4>MALWARE SCANNING [Premium]\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Automatic malware scanning\u003C\u002Fstrong> – Detect and protect against the latest malware, trojans, and spyware.\u003Cbr \u002F>\nAlerts you to blacklisting by search engines – Monitor your site for blacklisting by search engines due to malicious code.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Response time monitoring\u003C\u002Fstrong> – Keep track of your website’s response time to identify and address any performance issues.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Uptime monitoring\u003C\u002Fstrong> – Checks your website’s uptime every 5 minutes and alerts you immediately if your site or server goes down.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Advice and malware removal\u003C\u002Fstrong> – Need hands-on advice and support for malware removal? Our team of genuine cybersecurity experts is here to help.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Notification if something’s amiss\u003C\u002Fstrong> – Receive notifications about any issues with your site so you can address problems before they escalate.\u003C\u002Fp>\n\u003Ch4>Plugin Support\u003C\u002Fh4>\n\u003Cp>If you have a question or problem with the All-In-One Security plugin, post it on the support forum and we will help you. Premium customers can log queries directly with the team via https:\u002F\u002Fteamupdraft.com\u002Fall-in-one-security\u003C\u002Fp>\n\u003Ch4>Developers\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>If you are a developer and you need some extra hooks or filters for this plugin then let us know.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Translations\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>All-In-One Security plugin can be translated to any language.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Currently available translations:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>English\u003C\u002Fli>\n\u003Cli>German\u003C\u002Fli>\n\u003Cli>Spanish\u003C\u002Fli>\n\u003Cli>French\u003C\u002Fli>\n\u003Cli>Hungarian\u003C\u002Fli>\n\u003Cli>Italian\u003C\u002Fli>\n\u003Cli>Swedish\u003C\u002Fli>\n\u003Cli>Russian\u003C\u002Fli>\n\u003Cli>Chinese\u003C\u002Fli>\n\u003Cli>Portuguese (Brazil)\u003C\u002Fli>\n\u003Cli>Persian\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Privacy Policy\u003C\u002Fh4>\n\u003Cp>This plugin may collect IP addresses for security reasons such as mitigating brute force login threats and malicious activity.\u003C\u002Fp>\n\u003Cp>The collected information is stored on your server. No information is transmitted to third parties or remote server locations.\u003C\u002Fp>\n\u003Ch4>Usage\u003C\u002Fh4>\n\u003Cp>Go to the settings menu after you activate the plugin and follow the instructions.\u003C\u002Fp>\n\u003Ch3>Usage\u003C\u002Fh3>\n\u003Cp>Go to the settings menu after you activate the plugin and follow the instructions.\u003C\u002Fp>\n","Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plugin designed especially for WordPress.",1000000,36139406,94,1693,"2026-01-28T22:15:00.000Z","5.0","5.6",[96,97,140,98,141],"malware-scanning","two-factor-authentication","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fall-in-one-wp-security-and-firewall\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fall-in-one-wp-security-and-firewall.5.4.6.zip",26,"2024-02-08 00:00:00",{"attackSurface":147,"codeSignals":198,"taintFlows":334,"riskAssessment":401,"analyzedAt":416},{"hooks":148,"ajaxHandlers":190,"restRoutes":191,"shortcodes":192,"cronEvents":197,"entryPointCount":50,"unprotectedCount":27},[149,155,159,163,167,170,175,179,182,187],{"type":150,"name":151,"callback":152,"file":153,"line":154},"action","wp_login","your_last_login","sb-login.php",61,{"type":150,"name":156,"callback":157,"file":153,"line":158},"wp_head","nd_update_user_view_meta",90,{"type":150,"name":160,"callback":161,"file":153,"line":162},"init","nd_login_init_script",104,{"type":150,"name":164,"callback":165,"file":153,"line":166},"wp_print_styles","nd_login_init_style",114,{"type":150,"name":160,"callback":168,"priority":50,"file":153,"line":169},"nd_login_init",128,{"type":171,"name":172,"callback":173,"file":153,"line":174},"filter","wp_mail_from","sb_mail_from",178,{"type":171,"name":176,"callback":177,"file":153,"line":178},"wp_mail_from_name","sb_mail_from_name",182,{"type":150,"name":160,"callback":180,"file":153,"line":181},"nd_login_process",216,{"type":150,"name":183,"callback":184,"file":185,"line":186},"admin_menu","register_sbl_menu_page","sbl_admin.php",3,{"type":150,"name":188,"callback":189,"file":185,"line":100},"admin_init","register_sbl_settings",[],[],[193],{"tag":194,"callback":195,"file":153,"line":196},"sblogin","nd_login_widget",139,[],{"dangerousFunctions":199,"sqlUsage":200,"outputEscaping":207,"fileOperations":27,"externalRequests":27,"nonceChecks":27,"capabilityChecks":186,"bundledLibraries":333},[],{"prepared":201,"raw":50,"locations":202},5,[203],{"file":204,"line":205,"context":206},"template\\logged-in.php",102,"$wpdb->get_var() with variable interpolation",{"escaped":50,"rawEcho":208,"locations":209},71,[210,214,216,218,220,222,224,226,228,230,232,234,236,238,240,242,244,245,246,248,250,252,255,257,259,261,263,265,267,269,271,273,275,276,277,278,279,281,282,284,286,288,289,290,291,293,294,295,296,297,299,301,302,303,305,307,308,309,311,313,315,317,319,321,323,324,325,327,328,330,332],{"file":211,"line":212,"context":213},"admin\\server_info.php",32,"raw output",{"file":211,"line":215,"context":213},33,{"file":211,"line":217,"context":213},34,{"file":211,"line":219,"context":213},35,{"file":211,"line":221,"context":213},37,{"file":211,"line":223,"context":213},38,{"file":211,"line":225,"context":213},39,{"file":211,"line":227,"context":213},40,{"file":211,"line":229,"context":213},41,{"file":211,"line":231,"context":213},42,{"file":211,"line":233,"context":213},43,{"file":211,"line":235,"context":213},44,{"file":211,"line":237,"context":213},45,{"file":211,"line":239,"context":213},56,{"file":211,"line":241,"context":213},75,{"file":243,"line":100,"context":213},"admin\\settings.php",{"file":243,"line":11,"context":213},{"file":243,"line":11,"context":213},{"file":243,"line":247,"context":213},82,{"file":243,"line":249,"context":213},92,{"file":243,"line":251,"context":213},105,{"file":253,"line":254,"context":213},"admin\\usage.php",69,{"file":153,"line":256,"context":213},66,{"file":153,"line":258,"context":213},148,{"file":153,"line":260,"context":213},161,{"file":153,"line":262,"context":213},248,{"file":153,"line":264,"context":213},328,{"file":153,"line":266,"context":213},365,{"file":153,"line":268,"context":213},387,{"file":153,"line":270,"context":213},421,{"file":204,"line":272,"context":213},7,{"file":204,"line":274,"context":213},9,{"file":204,"line":274,"context":213},{"file":204,"line":274,"context":213},{"file":204,"line":274,"context":213},{"file":204,"line":274,"context":213},{"file":204,"line":280,"context":213},15,{"file":204,"line":144,"context":213},{"file":204,"line":283,"context":213},27,{"file":204,"line":285,"context":213},28,{"file":204,"line":287,"context":213},29,{"file":204,"line":35,"context":213},{"file":204,"line":217,"context":213},{"file":204,"line":219,"context":213},{"file":204,"line":292,"context":213},36,{"file":204,"line":292,"context":213},{"file":204,"line":223,"context":213},{"file":204,"line":233,"context":213},{"file":204,"line":233,"context":213},{"file":204,"line":298,"context":213},51,{"file":204,"line":300,"context":213},59,{"file":204,"line":300,"context":213},{"file":204,"line":241,"context":213},{"file":204,"line":304,"context":213},87,{"file":204,"line":306,"context":213},91,{"file":204,"line":122,"context":213},{"file":204,"line":251,"context":213},{"file":204,"line":310,"context":213},109,{"file":312,"line":50,"context":213},"template\\login-form.php",{"file":312,"line":314,"context":213},8,{"file":312,"line":316,"context":213},17,{"file":312,"line":318,"context":213},18,{"file":312,"line":320,"context":213},22,{"file":322,"line":50,"context":213},"template\\lost-password-form.php",{"file":322,"line":314,"context":213},{"file":322,"line":318,"context":213},{"file":326,"line":50,"context":213},"template\\register-form.php",{"file":326,"line":314,"context":213},{"file":326,"line":329,"context":213},19,{"file":331,"line":274,"context":213},"template\\tabs.php",{"file":331,"line":47,"context":213},[],[335,352,365,374,388],{"entryPoint":336,"graph":337,"unsanitizedCount":50,"severity":351},"get_serverinfo_x (admin\\server_info.php:2)",{"nodes":338,"edges":348},[339,343],{"id":340,"type":341,"label":342,"file":211,"line":212},"n0","source","$_SERVER['SERVER_SOFTWARE']",{"id":344,"type":345,"label":346,"file":211,"line":212,"wp_function":347},"n1","sink","echo() [XSS]","echo",[349],{"from":340,"to":344,"sanitized":350},false,"medium",{"entryPoint":353,"graph":354,"unsanitizedCount":50,"severity":351},"nd_handle_login (sb-login.php:218)",{"nodes":355,"edges":363},[356,359],{"id":340,"type":341,"label":357,"file":153,"line":358},"$_REQUEST",237,{"id":344,"type":345,"label":360,"file":153,"line":361,"wp_function":362},"wp_redirect() [Open Redirect]",255,"wp_redirect",[364],{"from":340,"to":344,"sanitized":350},{"entryPoint":366,"graph":367,"unsanitizedCount":50,"severity":373},"\u003Cserver_info> (admin\\server_info.php:0)",{"nodes":368,"edges":371},[369,370],{"id":340,"type":341,"label":342,"file":211,"line":212},{"id":344,"type":345,"label":346,"file":211,"line":212,"wp_function":347},[372],{"from":340,"to":344,"sanitized":350},"low",{"entryPoint":375,"graph":376,"unsanitizedCount":50,"severity":387},"nd_handle_lost_password (sb-login.php:342)",{"nodes":377,"edges":385},[378,381],{"id":340,"type":341,"label":379,"file":153,"line":380},"$_POST",354,{"id":344,"type":345,"label":382,"file":153,"line":383,"wp_function":384},"get_var() [SQLi]",396,"get_var",[386],{"from":340,"to":344,"sanitized":350},"high",{"entryPoint":389,"graph":390,"unsanitizedCount":33,"severity":387},"\u003Csb-login> (sb-login.php:0)",{"nodes":391,"edges":398},[392,393,394,396],{"id":340,"type":341,"label":357,"file":153,"line":358},{"id":344,"type":345,"label":360,"file":153,"line":361,"wp_function":362},{"id":395,"type":341,"label":379,"file":153,"line":380},"n2",{"id":397,"type":345,"label":382,"file":153,"line":383,"wp_function":384},"n3",[399,400],{"from":340,"to":344,"sanitized":350},{"from":395,"to":397,"sanitized":350},{"summary":402,"deductions":403},"The \"sb-login\" plugin v2.5 exhibits a mixed security posture.  While it has a limited attack surface with no exposed AJAX handlers or REST API routes, and no previously recorded vulnerabilities (CVEs), significant concerns arise from the static analysis of its code. A striking 1% of output escaping indicates that the vast majority of dynamic content generated by the plugin is not properly sanitized, posing a high risk of Cross-Site Scripting (XSS) vulnerabilities.  Furthermore, the taint analysis reveals 5 flows with unsanitized paths, including 2 of high severity, suggesting potential injection vulnerabilities that could be exploited if an attacker can manipulate the input to these flows.\n\nThe absence of documented CVEs is a positive sign, implying a history of reasonable security. However, this is heavily overshadowed by the critical findings in the static analysis. The lack of nonce checks and only 3 capability checks across the entire plugin, combined with a very low percentage of properly escaped output, points to a general lack of robust security controls. The high number of SQL queries that do not use prepared statements is also a concern, increasing the risk of SQL injection. While the plugin has a small attack surface, the identified code-level weaknesses create significant potential for exploitation.\n\nIn conclusion, \"sb-login\" v2.5 has some foundational strengths such as a minimal attack surface and no prior CVEs. However, the overwhelming lack of output escaping and the presence of high-severity unsanitized taint flows represent critical security flaws. These issues, along with the potential for SQL injection and insufficient authorization checks, significantly elevate the risk associated with using this plugin. Remediation of these code-level issues should be a top priority.",[404,406,408,410,412,414],{"reason":405,"points":280},"Unsanitized taint flows (high severity)",{"reason":407,"points":47},"Unsanitized taint flows (overall)",{"reason":409,"points":280},"Very low output escaping percentage",{"reason":411,"points":47},"SQL queries without prepared statements",{"reason":413,"points":47},"No nonce checks",{"reason":415,"points":201},"Limited capability checks","2026-03-16T21:32:03.929Z",{"wat":418,"direct":429},{"assetPaths":419,"generatorPatterns":423,"scriptPaths":424,"versionParams":425},[420,421,422],"\u002Fwp-content\u002Fplugins\u002Fsb-login\u002Fjs\u002Flogin.js","\u002Fwp-content\u002Fplugins\u002Fsb-login\u002Fjs\u002Fblockui.js","\u002Fwp-content\u002Fplugins\u002Fsb-login\u002Fcss\u002Flogin.css",[],[420,421],[426,427,428],"sb-login\u002Fjs\u002Flogin.js?ver=","sb-login\u002Fjs\u002Fblockui.js?ver=","sb-login\u002Fcss\u002Flogin.css",{"cssClasses":430,"htmlComments":432,"htmlAttributes":435,"restEndpoints":437,"jsGlobals":438,"shortcodeOutput":440},[194,431],"sb-login-wrap",[433,434],"WEBCAREZONE.COM","An Ajax powered Login &amp; Register widget. See the ReadMe for customisation instructions.",[436],"data-sb-login-nonce",[],[439],"nd_login_vars",[441],"[sblogin]"]