[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fQmopODgsExigEHzZLlonLgiS-KW-jz49iJ8Au_wlNSs":3,"$fTiJKV-VpniVUzwwI5Bcyq_uQQXYq_yHv0HiaUBpqlzo":247,"$fFkt1rkRN63uxXkVVWxHo860SQNN9DOuiT8YGcU5znQQ":251},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":14,"last_updated":15,"tested_up_to":16,"requires_at_least":17,"requires_php":18,"tags":19,"homepage":25,"download_link":26,"security_score":13,"vuln_count":11,"unpatched_count":11,"last_vuln_date":27,"fetched_at":28,"discovery_status":29,"vulnerabilities":30,"developer":31,"crawl_stats":27,"alternatives":37,"analysis":128,"fingerprints":234},"secure-login-shield","Treder Secure Login Shield","2.0.6","Ben Treder","https:\u002F\u002Fprofiles.wordpress.org\u002Fbdtreder\u002F","\u003Cp>\u003Cstrong>Secure Login Shield\u003C\u002Fstrong> helps you lock down your WordPress login page.\u003Cbr \u002F>\nBy default, WordPress exposes \u003Ccode>\u002Fwp-login.php\u003C\u002Fcode> and \u003Ccode>\u002Fwp-admin\u002F\u003C\u002Fcode>. Bots hammer these URLs every day.\u003C\u002Fp>\n\u003Cp>This plugin gives you a \u003Cstrong>private login slug\u003C\u002Fstrong> (e.g. \u003Ccode>\u002Fdragon-lair\u003C\u002Fcode>) and hides the default login endpoint:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Defaults to \u003Ccode>\u002Fwp-login.php\u003C\u002Fcode> until you change it.\u003C\u002Fli>\n\u003Cli>Once changed, \u003Cstrong>only your custom slug\u003C\u002Fstrong> works.\u003C\u002Fli>\n\u003Cli>Direct access to \u003Ccode>\u002Fwp-login.php\u003C\u002Fcode> shows a \u003Cstrong>404 Not Found\u003C\u002Fstrong> (stealth mode).\u003C\u002Fli>\n\u003Cli>Logged-out visitors hitting \u003Ccode>\u002Fwp-admin\u002F\u003C\u002Fcode> are \u003Cstrong>redirected to the homepage\u003C\u002Fstrong>.\u003C\u002Fli>\n\u003Cli>Deactivate the plugin \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> everything reverts to normal.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Made with ❤️ by \u003Ca href=\"https:\u002F\u002FBenTreder.com\" rel=\"nofollow ugc\">Ben Treder\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch3>Features\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Private login slug\u003C\u002Fstrong> (e.g. \u003Ccode>\u002Fdragon-lair\u003C\u002Fcode>, \u003Ccode>\u002Fcontrol-center\u003C\u002Fcode>, \u003Ccode>\u002Fsecret-gate\u003C\u002Fcode>)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Stealth 404 protection\u003C\u002Fstrong>: Bots hitting \u003Ccode>\u002Fwp-login.php\u003C\u002Fcode> see “Not Found”\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Homepage redirect\u003C\u002Fstrong>: \u003Ccode>\u002Fwp-admin\u002F\u003C\u002Fcode> (logged out) \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> homepage\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Easy settings page\u003C\u002Fstrong> under Settings \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Secure Login Shield\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Safe activation\u002Fdeactivation\u003C\u002Fstrong>: no core hacks, auto-reverts when disabled\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Contribute & Support\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Website: \u003Ca href=\"https:\u002F\u002FBenTreder.com\" rel=\"nofollow ugc\">BenTreder.com\u003C\u002Fa>  \u003C\u002Fli>\n\u003Cli>Author: \u003Ca href=\"https:\u002F\u002Fprofiles.wordpress.org\u002Fbentreder\u002F\" rel=\"nofollow ugc\">Ben Treder\u003C\u002Fa>  \u003C\u002Fli>\n\u003Cli>Issues & Feature Requests: Please open a ticket on \u003Ca href=\"https:\u002F\u002FBenTreder.com\" rel=\"nofollow ugc\">BenTreder.com\u003C\u002Fa>  \u003C\u002Fli>\n\u003Cli>Like this plugin? ⭐ Leave a review and help spread the word!  \u003C\u002Fli>\n\u003Cli>☕ Support development: \u003Ca href=\"https:\u002F\u002Fwww.buymeacoffee.com\u002Fbentreder\" rel=\"nofollow ugc\">Buy Me a Coffee\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n","Create a private login URL and hide \u002Fwp-login.php with stealth 404s. Logged-out \u002Fwp-admin\u002F visits redirect to your homepage.",0,547,100,1,"2026-06-12T00:22:00.000Z","7.0.2","6.0","7.4",[20,21,22,23,24],"custom-login","hardening","login","security","wp-login","https:\u002F\u002Fplugins.bentreder.com\u002Fsecure-login-shield","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fsecure-login-shield.2.0.6.zip",null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":32,"display_name":7,"profile_url":8,"plugin_count":33,"total_installs":11,"avg_security_score":13,"avg_patch_time_days":34,"trust_score":35,"computed_at":36},"bdtreder",6,30,94,"2026-08-25T04:34:50.813Z",[38,60,73,95,113],{"slug":39,"name":40,"version":41,"author":42,"author_profile":43,"description":44,"short_description":45,"active_installs":46,"downloaded":47,"rating":13,"num_ratings":48,"last_updated":49,"tested_up_to":50,"requires_at_least":51,"requires_php":52,"tags":53,"homepage":58,"download_link":59,"security_score":13,"vuln_count":11,"unpatched_count":11,"last_vuln_date":27,"fetched_at":28},"admin-login-hide-pti","Admin Login Hide – PTI","1.0.4","PTI WebTech","https:\u002F\u002Fprofiles.wordpress.org\u002Fptiwebtech2025\u002F","\u003Cp>\u003Cstrong>Admin Login Hide – PTI\u003C\u002Fstrong> helps protect your WordPress site by hiding or customizing the default login URLs (\u003Ccode>wp-login.php\u003C\u002Fcode> and \u003Ccode>wp-admin\u003C\u002Fcode>). This helps reduce automated bot attacks, brute-force attempts, and unauthorized login access.\u003C\u002Fp>\n\u003Cp>With just a few clicks, you can:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Change the default login URL to a custom path\u003C\u002Fli>\n\u003Cli>Prevent access to the default \u003Ccode>wp-login.php\u003C\u002Fcode> and \u003Ccode>wp-admin\u003C\u002Fcode> paths\u003C\u002Fli>\n\u003Cli>Improve your site’s overall login security\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Perfect for WordPress users who want a lightweight, easy-to-use security enhancement without needing complex settings or heavy plugins.\u003C\u002Fp>\n","Easily hide or customize your WordPress login URL to enhance security and prevent unauthorized access.",10,716,3,"2026-03-23T12:29:00.000Z","6.9.5","5.0","7.2",[54,55,23,56,57],"custom-login-url","hide-login","wp-admin","wp-login-php","https:\u002F\u002Fgithub.com\u002Fptiwebtech\u002Fadmin-login-hide-pti","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fadmin-login-hide-pti.1.0.4.zip",{"slug":61,"name":62,"version":63,"author":64,"author_profile":65,"description":66,"short_description":67,"active_installs":46,"downloaded":68,"rating":11,"num_ratings":11,"last_updated":69,"tested_up_to":50,"requires_at_least":51,"requires_php":52,"tags":70,"homepage":71,"download_link":72,"security_score":13,"vuln_count":11,"unpatched_count":11,"last_vuln_date":27,"fetched_at":28},"change-hide-login-url","Secure WordPress Admin – Change & Hide Login URL","1.2","Yasar Khalifa","https:\u002F\u002Fprofiles.wordpress.org\u002Fyasirkhalifa\u002F","\u003Cp>\u003Cstrong>Secure WordPress Admin – Change & Hide Login URL\u003C\u002Fstrong> improves your website’s login security by allowing you to replace the default WordPress login page (wp-login.php) with any custom slug of your choice. It also blocks direct access to both \u003Cstrong>wp-login.php\u003C\u002Fstrong> and \u003Cstrong>\u002Fwp-admin\u002F\u003C\u002Fstrong> for all non-logged-in users.\u003C\u002Fp>\n\u003Cp>Upon activation, the plugin automatically sets the custom login slug to \u003Cstrong>mysecretlogin\u003C\u002Fstrong>.\u003Cbr \u002F>\nExample:\u003Cbr \u002F>\n    https:\u002F\u002Fyourwebsite.com\u002Fmysecretlogin\u003C\u002Fp>\n\u003Cp>You can update the slug anytime from the settings page.\u003Cbr \u002F>\n\u003Cstrong>Important:\u003C\u002Fstrong> After changing the custom slug, go to \u003Cstrong>Settings \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Permalinks\u003C\u002Fstrong> and click \u003Cstrong>Save Changes\u003C\u002Fstrong> to ensure the new login URL works correctly.\u003C\u002Fp>\n\u003Cp>This plugin is lightweight, fast, and follows WordPress coding standards without modifying core files.\u003C\u002Fp>\n\u003Ch3>Features\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Change \u003Cstrong>wp-login.php\u003C\u002Fstrong> to a custom login slug  \u003C\u002Fli>\n\u003Cli>Default login slug automatically set to \u003Cstrong>mysecretlogin\u003C\u002Fstrong>  \u003C\u002Fli>\n\u003Cli>Blocks direct access to \u003Cstrong>wp-login.php\u003C\u002Fstrong>  \u003C\u002Fli>\n\u003Cli>Blocks unauthorized access to \u003Cstrong>\u002Fwp-admin\u002F\u003C\u002Fstrong>  \u003C\u002Fli>\n\u003Cli>Simple admin settings page to manage the slug  \u003C\u002Fli>\n\u003Cli>Fully translation-ready  \u003C\u002Fli>\n\u003Cli>Uses WordPress security best practices  \u003C\u002Fli>\n\u003Cli>Zero impact on site performance\u003C\u002Fli>\n\u003C\u002Ful>\n","Secure and customize your WordPress admin login by changing the default wp-login.php URL to a custom slug and blocking unauthorized access to wp-admin &hellip;",597,"2025-12-10T04:07:00.000Z",[54,22,23,24,56],"","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fchange-hide-login-url.zip",{"slug":74,"name":75,"version":76,"author":77,"author_profile":78,"description":79,"short_description":80,"active_installs":46,"downloaded":81,"rating":82,"num_ratings":14,"last_updated":83,"tested_up_to":84,"requires_at_least":85,"requires_php":18,"tags":86,"homepage":91,"download_link":92,"security_score":93,"vuln_count":11,"unpatched_count":11,"last_vuln_date":27,"fetched_at":94},"modify-login","Modify Login – Custom WordPress Login URL & Login Page Designer","2.0.0","MantraBrain","https:\u002F\u002Fprofiles.wordpress.org\u002Fmantrabrain\u002F","\u003Cp>\u003Cstrong>Modify Login\u003C\u002Fstrong> transforms the default WordPress login experience with enhanced security features and a modern, customizable login page design.\u003C\u002Fp>\n\u003Cp>✅ Prevent brute force attacks by hiding your login page\u003Cbr \u002F>\n✅ Create a beautiful branded login experience in minutes\u003Cbr \u002F>\n✅ No coding required – easy drag and drop builder\u003Cbr \u002F>\n✅ Redirect unauthorized users to any page\u003C\u002Fp>\n\u003Ch3>🔒 Security Features\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Custom Login URL\u003C\u002Fstrong>: Replace the standard wp-login.php with your custom endpoint (e.g., yourdomain.com\u002Fsetup)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Login Protection\u003C\u002Fstrong>: Block direct access to wp-login.php and wp-admin for non-logged in users\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Redirect Protection\u003C\u002Fstrong>: Redirect unauthorized access attempts to a URL of your choice\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Google reCAPTCHA Integration\u003C\u002Fstrong>: Add CAPTCHA verification to prevent bot attacks\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Login Attempt Tracking\u003C\u002Fstrong>: Monitor and log all login attempts with IP addresses and location data\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>🎨 Design Features\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Visual Login Builder\u003C\u002Fstrong>: Modern drag-and-drop interface to customize your login page appearance\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Background Customization\u003C\u002Fstrong>: Set custom background colors, images, and opacity\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Logo Control\u003C\u002Fstrong>: Upload your own logo with full control over dimensions and positioning\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Form Styling\u003C\u002Fstrong>: Customize the login form with custom colors, borders, and padding\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Button Styling\u003C\u002Fstrong>: Style login buttons with custom colors and hover effects\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Custom CSS\u003C\u002Fstrong>: Add your own CSS for unlimited customization possibilities\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>🔄 Redirect Options\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Login Redirect\u003C\u002Fstrong>: Send users to a specific URL after successful login\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Logout Redirect\u003C\u002Fstrong>: Redirect users to a custom URL after logging out\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>👨‍💻 Developer Friendly\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Clean Code\u003C\u002Fstrong>: Well-organized, documented code following WordPress best practices\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Filter Hooks\u003C\u002Fstrong>: Extensive filter hooks for developers to extend functionality\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Performance Optimized\u003C\u002Fstrong>: Lightweight implementation with minimal impact on site speed\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Perfect For:\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Membership sites\u003C\u002Fli>\n\u003Cli>Client websites\u003C\u002Fli>\n\u003Cli>E-commerce stores\u003C\u002Fli>\n\u003Cli>Educational platforms\u003C\u002Fli>\n\u003Cli>Business websites\u003C\u002Fli>\n\u003Cli>Any WordPress site needing improved security\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>How It Works\u003C\u002Fh3>\n\u003Col>\n\u003Cli>Set a custom login URL endpoint in the plugin settings (default is “setup”)\u003C\u002Fli>\n\u003Cli>Optionally enable redirect protection to block direct access to wp-login.php\u003C\u002Fli>\n\u003Cli>Customize the login page appearance using the visual builder\u003C\u002Fli>\n\u003Cli>Add optional reCAPTCHA verification for enhanced security\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch3>Get Help\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fmantrabrain.com\u002Fdocs-category\u002Fmodify-login\u002F\" rel=\"nofollow ugc\">Documentation\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Fplugin\u002Fmodify-login\u002F\" rel=\"ugc\">Support Forum\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fmantrabrain.com\u002Fcontact\u002F\" rel=\"nofollow ugc\">Contact Us\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n","Secure WordPress login with custom URL, protect wp-admin, and design beautiful login pages with drag & drop builder. No code required.",2999,20,"2025-04-24T14:45:00.000Z","6.8.5","5.8",[20,87,88,89,90],"hide-wp-login","login-customizer","login-page","login-security","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fmodify-login","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fmodify-login.2.0.1.zip",92,"2026-04-16T10:56:18.058Z",{"slug":96,"name":97,"version":98,"author":99,"author_profile":100,"description":101,"short_description":102,"active_installs":11,"downloaded":103,"rating":11,"num_ratings":11,"last_updated":104,"tested_up_to":105,"requires_at_least":106,"requires_php":107,"tags":108,"homepage":111,"download_link":112,"security_score":93,"vuln_count":11,"unpatched_count":11,"last_vuln_date":27,"fetched_at":28},"custom-login-url-manager","Custom Login URL Manager – Hide Login Admin URL","1.1.2","WPDesigner","https:\u002F\u002Fprofiles.wordpress.org\u002Fwpdesignerpl\u002F","\u003Cp>Custom Login URL Manager allows you to secure your WordPress site by changing the default login URL (wp-login.php) to a custom URL. This helps protect against unauthorized login attempts and automated bots trying to access your admin panel.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Key Features:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Custom Login URL\u003C\u002Fstrong>: Replace the default WordPress login URL with a custom one.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Login URL Redirect\u003C\u002Fstrong>: Redirect unauthorized access attempts (e.g., wp-login.php or wp-admin) to a specified URL, such as a custom error page or homepage.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>User-Friendly Interface\u003C\u002Fstrong>: Easily configure your login URL and redirect settings through the WordPress admin panel.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Security Enhancement\u003C\u002Fstrong>: Hides the default login page, adding an extra layer of security to your website.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Translation Ready\u003C\u002Fstrong>: .pot file included for easy translation into different languages.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Languages\u003C\u002Fstrong>: Available in both English and Polish.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>License\u003C\u002Fh3>\n\u003Cp>This plugin is free software; you can redistribute it and\u002For modify it under the terms of the GNU General Public License as published by the Free Software Foundation; version 2 of the License, or (at your option) any later version.\u003C\u002Fp>\n\u003Ch3>Donate Link\u003C\u002Fh3>\n\u003Cp>If you’d like to support the development of this plugin, consider donating at: https:\u002F\u002Fko-fi.com\u002Fwpdesigner\u003C\u002Fp>\n","Change the default WordPress login URL and redirect unauthorized attempts to a specified page for enhanced security.",1293,"2024-10-20T11:54:00.000Z","6.6.5","6.2","7.2.5",[20,109,110,23,57],"login-redirect","login-url","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fcustom-login-url-manager\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fcustom-login-url-manager.1.1.2.zip",{"slug":114,"name":115,"version":116,"author":117,"author_profile":118,"description":119,"short_description":120,"active_installs":11,"downloaded":121,"rating":11,"num_ratings":11,"last_updated":122,"tested_up_to":16,"requires_at_least":123,"requires_php":18,"tags":124,"homepage":126,"download_link":127,"security_score":13,"vuln_count":11,"unpatched_count":11,"last_vuln_date":27,"fetched_at":28},"hsarticle-login-warden","HSArticle Login Warden","1.0.0","hsarticle","https:\u002F\u002Fprofiles.wordpress.org\u002Fhsarticle\u002F","\u003Cp>Most “hide login” plugins only do one thing: change the URL of wp-login.php. HSArticle Login Warden does that too, but it’s built around a wider goal — make it harder for anyone to find or confirm who has access to your WordPress admin in the first place. Hiding the login form doesn’t help much if your usernames are still leaking out through three other doors, so HSArticle Login Warden closes those too, all as optional one-click toggles.\u003C\u002Fp>\n\u003Cp>It doesn’t rename or modify any core files, and it doesn’t add rewrite rules — it simply intercepts requests for wp-login.php and \u002Fwp-admin and shows a 404 (or redirects) to logged-out visitors, while your chosen custom URL loads the real login form.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Custom login URL\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Set any custom login URL slug\u003C\u002Fli>\n\u003Cli>Choose what logged-out visitors see when they hit the old login page or \u002Fwp-admin: a 404 page, a redirect to your homepage, or a redirect to any custom URL\u003C\u002Fli>\n\u003Cli>Your current login URL is always visible on the settings page with a one-click Copy button, so you never lose track of it\u003C\u002Fli>\n\u003Cli>Built-in conflict check — you can’t accidentally set your login slug to something that collides with an existing page or post\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Optional hardening toggles\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Disable XML-RPC (xmlrpc.php) — a second, often-forgotten login door and a common brute-force target\u003C\u002Fli>\n\u003Cli>Generic login error messages — stops WordPress confirming whether a failed login had a real username or not\u003C\u002Fli>\n\u003Cli>Block username enumeration via ?author=1, ?author=2, etc. — stops one of the most common ways real usernames get discovered\u003C\u002Fli>\n\u003Cli>Hide the \u002Fwp-json\u002Fwp\u002Fv2\u002Fusers REST endpoint from logged-out requests — this lists every username on your site by default\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>None of these toggles track, log, or store anything about your visitors — they simply stop information from leaking out. All logged-in functionality (dashboard, admin, post editing) works completely normally; every toggle here only affects logged-out visitors.\u003C\u002Fp>\n\u003Cp>Deactivating the plugin brings your site back to its default state immediately.\u003C\u002Fp>\n","Hide your login URL and stop leaking your admin usernames. Custom login URL, XML-RPC lockdown, and enumeration blocking.",62,"2026-07-18T20:21:00.000Z","5.6",[54,55,90,24,125],"xmlrpc","https:\u002F\u002Fhsarticle.com\u002Fhsarticle-login-warden\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fhsarticle-login-warden.1.0.0.zip",{"attackSurface":129,"codeSignals":165,"taintFlows":184,"riskAssessment":227,"analyzedAt":233},{"hooks":130,"ajaxHandlers":161,"restRoutes":162,"shortcodes":163,"cronEvents":164,"entryPointCount":11,"unprotectedCount":11},[131,138,142,145,148,151,154,156,157,158,159,160],{"type":132,"name":133,"callback":134,"priority":135,"file":136,"line":137},"action","init","closure",9,"secure-login-shield.php",41,{"type":139,"name":140,"callback":134,"priority":46,"file":136,"line":141},"filter","site_url",53,{"type":132,"name":143,"callback":134,"file":136,"line":144},"login_init",70,{"type":132,"name":133,"callback":134,"priority":146,"file":136,"line":147},11,105,{"type":132,"name":149,"callback":134,"file":136,"line":150},"admin_notices",143,{"type":132,"name":152,"callback":134,"file":136,"line":153},"admin_menu",160,{"type":132,"name":133,"callback":134,"priority":135,"file":155,"line":137},"trunk\\secure-login-shield.php",{"type":139,"name":140,"callback":134,"priority":46,"file":155,"line":141},{"type":132,"name":143,"callback":134,"file":155,"line":144},{"type":132,"name":133,"callback":134,"priority":146,"file":155,"line":147},{"type":132,"name":149,"callback":134,"file":155,"line":150},{"type":132,"name":152,"callback":134,"file":155,"line":153},[],[],[],[],{"dangerousFunctions":166,"sqlUsage":167,"outputEscaping":169,"fileOperations":11,"externalRequests":11,"nonceChecks":182,"capabilityChecks":182,"bundledLibraries":183},[],{"prepared":11,"raw":11,"locations":168},[],{"escaped":170,"rawEcho":33,"locations":171},38,[172,175,177,179,180,181],{"file":136,"line":173,"context":174},191,"raw output",{"file":136,"line":176,"context":174},194,{"file":136,"line":178,"context":174},209,{"file":155,"line":173,"context":174},{"file":155,"line":176,"context":174},{"file":155,"line":178,"context":174},2,[],[185,203,211,219],{"entryPoint":186,"graph":187,"unsanitizedCount":11,"severity":202},"sls_render_settings_page (secure-login-shield.php:173)",{"nodes":188,"edges":199},[189,194],{"id":190,"type":191,"label":192,"file":136,"line":193},"n0","source","$_POST (x4)",181,{"id":195,"type":196,"label":197,"file":136,"line":173,"wp_function":198},"n1","sink","echo() [XSS]","echo",[200],{"from":190,"to":195,"sanitized":201},true,"low",{"entryPoint":204,"graph":205,"unsanitizedCount":11,"severity":202},"\u003Csecure-login-shield> (secure-login-shield.php:0)",{"nodes":206,"edges":209},[207,208],{"id":190,"type":191,"label":192,"file":136,"line":193},{"id":195,"type":196,"label":197,"file":136,"line":173,"wp_function":198},[210],{"from":190,"to":195,"sanitized":201},{"entryPoint":212,"graph":213,"unsanitizedCount":11,"severity":202},"sls_render_settings_page (trunk\\secure-login-shield.php:173)",{"nodes":214,"edges":217},[215,216],{"id":190,"type":191,"label":192,"file":155,"line":193},{"id":195,"type":196,"label":197,"file":155,"line":173,"wp_function":198},[218],{"from":190,"to":195,"sanitized":201},{"entryPoint":220,"graph":221,"unsanitizedCount":11,"severity":202},"\u003Csecure-login-shield> (trunk\\secure-login-shield.php:0)",{"nodes":222,"edges":225},[223,224],{"id":190,"type":191,"label":192,"file":155,"line":193},{"id":195,"type":196,"label":197,"file":155,"line":173,"wp_function":198},[226],{"from":190,"to":195,"sanitized":201},{"summary":228,"deductions":229},"The secure-login-shield v1.3.0 plugin exhibits a strong security posture based on the provided static analysis.  The absence of exposed attack surface points like AJAX handlers, REST API routes, shortcodes, and cron events, particularly without authentication checks, is a significant strength.  The code also demonstrates good practices regarding SQL queries, with 100% using prepared statements, and a high percentage of output escaping (86%), indicating a conscious effort to prevent cross-site scripting vulnerabilities. The presence of nonce and capability checks further reinforces the security design.\n\nHowever, while the immediate code analysis reveals no critical or high-severity issues, there's a slight concern regarding the 14% of outputs that are not properly escaped. This could potentially lead to low-severity XSS vulnerabilities if user-controlled data reaches these unescaped points. The plugin's vulnerability history is clean, with no recorded CVEs, which is a very positive indicator. This lack of historical issues, combined with the current code signals, suggests a well-maintained and secure plugin. The overall risk is low, with the primary area for potential improvement being the complete sanitization of all output.\n\nIn conclusion, secure-login-shield v1.3.0 appears to be a robust and secure plugin. Its minimal attack surface, safe database interactions, and effective use of security checks are commendable. The main weakness lies in the small proportion of unescaped outputs, which, while not indicating a current exploit, represents a potential avenue for future vulnerabilities. The absence of any past vulnerabilities further bolsters confidence in its security. Users can generally consider this plugin safe, with the understanding that even minor unescaped outputs are best addressed.",[230],{"reason":231,"points":232},"Unescaped output found",4,"2026-03-17T07:08:29.927Z",{"wat":235,"direct":240},{"assetPaths":236,"generatorPatterns":237,"scriptPaths":238,"versionParams":239},[],[],[],[],{"cssClasses":241,"htmlComments":242,"htmlAttributes":243,"restEndpoints":244,"jsGlobals":245,"shortcodeOutput":246},[],[],[],[],[],[],{"error":201,"url":248,"statusCode":249,"statusMessage":250,"message":250},"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fsecure-login-shield\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":252,"versions":253},8,[254,260,267,274,281,288,295,301],{"version":6,"download_url":26,"svn_tag_url":255,"released_at":27,"has_diff":256,"diff_files_changed":257,"diff_lines":27,"trac_diff_url":258,"vulnerabilities":259,"is_current":201},"https:\u002F\u002Fplugins.svn.wordpress.org\u002Fsecure-login-shield\u002Ftags\u002F2.0.6\u002F",false,[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fsecure-login-shield%2Ftags%2F2.0.5&new_path=%2Fsecure-login-shield%2Ftags%2F2.0.6",[],{"version":261,"download_url":262,"svn_tag_url":263,"released_at":27,"has_diff":256,"diff_files_changed":264,"diff_lines":27,"trac_diff_url":265,"vulnerabilities":266,"is_current":256},"2.0.5","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fsecure-login-shield.2.0.5.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fsecure-login-shield\u002Ftags\u002F2.0.5\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fsecure-login-shield%2Ftags%2F2.0.4&new_path=%2Fsecure-login-shield%2Ftags%2F2.0.5",[],{"version":268,"download_url":269,"svn_tag_url":270,"released_at":27,"has_diff":256,"diff_files_changed":271,"diff_lines":27,"trac_diff_url":272,"vulnerabilities":273,"is_current":256},"2.0.4","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fsecure-login-shield.2.0.4.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fsecure-login-shield\u002Ftags\u002F2.0.4\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fsecure-login-shield%2Ftags%2F2.0.3&new_path=%2Fsecure-login-shield%2Ftags%2F2.0.4",[],{"version":275,"download_url":276,"svn_tag_url":277,"released_at":27,"has_diff":256,"diff_files_changed":278,"diff_lines":27,"trac_diff_url":279,"vulnerabilities":280,"is_current":256},"2.0.3","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fsecure-login-shield.2.0.3.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fsecure-login-shield\u002Ftags\u002F2.0.3\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fsecure-login-shield%2Ftags%2F2.0.2&new_path=%2Fsecure-login-shield%2Ftags%2F2.0.3",[],{"version":282,"download_url":283,"svn_tag_url":284,"released_at":27,"has_diff":256,"diff_files_changed":285,"diff_lines":27,"trac_diff_url":286,"vulnerabilities":287,"is_current":256},"2.0.2","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fsecure-login-shield.2.0.2.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fsecure-login-shield\u002Ftags\u002F2.0.2\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fsecure-login-shield%2Ftags%2F2.0.1&new_path=%2Fsecure-login-shield%2Ftags%2F2.0.2",[],{"version":289,"download_url":290,"svn_tag_url":291,"released_at":27,"has_diff":256,"diff_files_changed":292,"diff_lines":27,"trac_diff_url":293,"vulnerabilities":294,"is_current":256},"2.0.1","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fsecure-login-shield.2.0.1.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fsecure-login-shield\u002Ftags\u002F2.0.1\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fsecure-login-shield%2Ftags%2F2.0.0&new_path=%2Fsecure-login-shield%2Ftags%2F2.0.1",[],{"version":76,"download_url":296,"svn_tag_url":297,"released_at":27,"has_diff":256,"diff_files_changed":298,"diff_lines":27,"trac_diff_url":299,"vulnerabilities":300,"is_current":256},"https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fsecure-login-shield.2.0.0.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fsecure-login-shield\u002Ftags\u002F2.0.0\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fsecure-login-shield%2Ftags%2F1.3.0&new_path=%2Fsecure-login-shield%2Ftags%2F2.0.0",[],{"version":302,"download_url":303,"svn_tag_url":304,"released_at":27,"has_diff":256,"diff_files_changed":305,"diff_lines":27,"trac_diff_url":27,"vulnerabilities":306,"is_current":256},"1.3.0","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fsecure-login-shield.1.3.0.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fsecure-login-shield\u002Ftags\u002F1.3.0\u002F",[],[]]