Secure Admin Login With Customize Security & Risk Analysis

wordpress.org/plugins/secure-admin-login-with-customize

Secure admin login with customize allows you to customize your WordPress admin login page within WordPress customizer.

10 active installs v1.4 PHP 7.2+ WP 5.9+ Updated Jan 29, 2025
custom-admin-logincustom-login-logocustom-wp-logincustomise-wordpress-loginlogin-customizer
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Secure Admin Login With Customize Safe to Use in 2026?

Generally Safe

Score 92/100

Secure Admin Login With Customize has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "secure-admin-login-with-customize" plugin v1.4 demonstrates a generally strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points is a significant positive. Furthermore, the code signals are largely reassuring: no dangerous functions were detected, SQL queries are exclusively using prepared statements, and the vast majority of output is properly escaped. The plugin also includes some nonce checks and performs a file operation and an external HTTP request, which are standard functionalities.

However, there are a couple of areas that warrant attention. The lack of any identified capability checks is a notable concern, especially for a plugin likely intended to secure administrative functions. This means that even if entry points were discovered, they might not be properly restricted to authorized users. The fact that no taint flows were found, while seemingly positive, could also be interpreted as the analysis not being able to detect such flows due to the limited scope or complexity of the analyzed code. The plugin's vulnerability history is clean, with no recorded CVEs, which is excellent and suggests a history of security-conscious development or a lack of targeted attacks.

In conclusion, the plugin exhibits good development practices with its use of prepared statements and output escaping. The minimal attack surface and clean vulnerability history are strengths. The primary weakness identified is the absence of capability checks, which is a critical oversight for administrative security. While the lack of identified taint flows and dangerous functions is positive, it's important to remain vigilant and consider the potential for undiscovered vulnerabilities.

Key Concerns

  • Missing capability checks
Vulnerabilities
None known

Secure Admin Login With Customize Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Secure Admin Login With Customize Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
81 escaped
Nonce Checks
2
Capability Checks
0
File Operations
1
External Requests
1
Bundled Libraries
0

Output Escaping

98% escaped83 total outputs
Attack Surface

Secure Admin Login With Customize Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 24
actionlogin_formadmin\captcha\class-secure-admin-login-with-customize-captcha.php:19
actionwp_authenticate_useradmin\captcha\class-secure-admin-login-with-customize-captcha.php:20
actionlogin_enqueue_scriptsadmin\captcha\class-secure-admin-login-with-customize-captcha.php:21
actionlogin_footeradmin\captcha\class-secure-admin-login-with-customize-captcha.php:22
actionlogin_formadmin\captcha\class-secure-admin-login-with-customize-captcha.php:26
actionwp_authenticate_useradmin\captcha\class-secure-admin-login-with-customize-captcha.php:27
actionlogin_footeradmin\captcha\class-secure-admin-login-with-customize-captcha.php:28
actionlogin_formadmin\captcha\class-secure-login-recaptcha.php:41
actionwp_authenticate_useradmin\captcha\class-secure-login-recaptcha.php:42
actionlogin_enqueue_scriptsadmin\captcha\class-secure-login-recaptcha.php:43
actionlogin_footeradmin\captcha\class-secure-login-recaptcha.php:44
actionlogin_formadmin\captcha\class-secure-login-recaptcha.php:48
actionwp_authenticate_useradmin\captcha\class-secure-login-recaptcha.php:49
actionlogin_footeradmin\captcha\class-secure-login-recaptcha.php:50
filterlogin_headertitleadmin\class-secure-admin-login-with-customize.php:11
filterlogin_headerurladmin\class-secure-admin-login-with-customize.php:12
actionlogin_enqueue_scriptsadmin\class-secure-admin-login-with-customize.php:13
filterlogin_headertextadmin\class-secure-login-admin.php:21
filterlogin_headerurladmin\class-secure-login-admin.php:22
actionlogin_enqueue_scriptsadmin\class-secure-login-admin.php:23
actioncustomize_registeradmin\customizer\class-secure-admin-login-with-customize-customizer.php:8
actioncustomize_registeradmin\customizer\class-secure-login-customizer.php:17
actionplugins_loadedsecure-admin-login-with-customize.php:33
actionplugins_loadedsecure-admin-login-with-customize.php:58
Maintenance & Trust

Secure Admin Login With Customize Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedJan 29, 2025
PHP min version7.2
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Secure Admin Login With Customize Developer Profile

Dilip Bheda

2 plugins · 4K total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Secure Admin Login With Customize

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/secure-admin-login-with-customize/admin/images/reload.png
Script Paths
https://www.google.com/recaptcha/api.js

HTML / DOM Fingerprints

CSS Classes
g-recaptcha
Data Attributes
data-sitekeydata-callbackdata-size
JS Globals
grecaptchasafelogin
FAQ

Frequently Asked Questions about Secure Admin Login With Customize