Sky Login Redirect Security & Risk Analysis

wordpress.org/plugins/sky-login-redirect

Control where users land after login/logout. Redirect by role, user, or previous page. Includes a powerful login customizer and WooCommerce support.

2K active installs v4.1.6 PHP 8.1+ WP 5.6+ Updated Feb 9, 2026
custom-loginlogin-customizerlogin-redirectlogout-redirectwoocommerce-login
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Sky Login Redirect Safe to Use in 2026?

Generally Safe

Score 100/100

Sky Login Redirect has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The 'sky-login-redirect' plugin v4.1.6 exhibits a generally good security posture due to the absence of known vulnerabilities and the consistent use of prepared statements for all SQL queries. The plugin also demonstrates strong output escaping practices with 92% of outputs properly escaped, and the presence of nonce and capability checks on its entry points. However, there are significant concerns regarding its attack surface. Two of the three identified entry points, specifically AJAX handlers, lack authentication checks. This creates a potential avenue for unauthorized actions if these handlers can be triggered by unauthenticated users. The lack of recorded vulnerabilities in its history is a positive sign, suggesting a developer who may be attentive to security, but it doesn't entirely mitigate the risks posed by the unprotected entry points.

In conclusion, while the plugin has commendable secure coding practices in place for data handling and output, the unprotected AJAX endpoints present a notable security weakness. The absence of known CVEs is reassuring, but the uncovered attack surface warrants attention. It is recommended that the developer implement robust authentication and authorization checks on all AJAX handlers to fully secure the plugin.

Key Concerns

  • AJAX handlers without auth checks
  • Bundled Freemius v1.0
Vulnerabilities
None known

Sky Login Redirect Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Sky Login Redirect Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
5 prepared
Unescaped Output
3
35 escaped
Nonce Checks
2
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0

SQL Query Safety

100% prepared5 total queries

Output Escaping

92% escaped38 total outputs
Attack Surface
2 unprotected

Sky Login Redirect Attack Surface

Entry Points3
Unprotected2

AJAX Handlers 2

authwp_ajax_slr_search_pagesincludes\ajax-handlers.php:254
authwp_ajax_slr_search_usersincludes\ajax-handlers.php:262

Shortcodes 1

[login-logout] sky-login-redirect.php:371
WordPress Hooks 43
filtercarbon_fields_field_htmlincludes\ajax-handlers.php:304
filterlogin_urlincludes\login-customizer.php:550
filterlogin_headerurlincludes\login-customizer.php:551
filterlogin_headertextincludes\login-customizer.php:552
actionadmin_enqueue_scriptsincludes\login-customizer.php:553
filterlogin_headincludes\login-customizer.php:554
filterlogin_headincludes\login-customizer.php:555
actionwoocommerce_login_form_startincludes\login-customizer.php:556
filteredd_login_formincludes\login-customizer.php:557
actionlogin_footerincludes\login-customizer.php:558
actionwoocommerce_login_form_endincludes\login-customizer.php:559
filteredd_login_formincludes\login-customizer.php:560
filterlogin_display_language_dropdownincludes\login-customizer.php:564
actionadmin_initincludes\notices.php:61
actionadmin_enqueue_scriptsincludes\notices.php:62
actionadmin_noticesincludes\notices.php:120
actioncarbon_fields_register_fieldsincludes\options.php:104
filtersky_login_redirect_options_tabsincludes\options.php:132
filtersky_login_redirect_options_fields_tab_login_logoutincludes\options.php:407
filtersky_login_redirect_options_fields_tab_tweaksincludes\options.php:501
filtersky_login_redirect_options_fields_tab_woocommerceincludes\options.php:848
filtersky_login_redirect_options_fields_tab_customizerincludes\options.php:990
filtersky_login_redirect_options_fields_tab_pluginsincludes\options.php:1067
filtersky_login_redirect_options_fields_tab_restrictincludes\options.php:1239
filtersky_login_redirect_options_fields_tab_modalincludes\options.php:1486
filtersky_login_redirect_options_fields_tab_blocksincludes\options.php:1669
actioncarbon_fields_container_sky_login_redirect_after_sidebarincludes\options.php:1803
actionafter_uninstallsky-login-redirect.php:134
actionadmin_enqueue_scriptssky-login-redirect.php:155
actionafter_setup_themesky-login-redirect.php:166
actionplugins_loadedsky-login-redirect.php:176
actiontemplate_redirectsky-login-redirect.php:220
actionsend_headerssky-login-redirect.php:224
actionlogin_enqueue_scriptssky-login-redirect.php:246
actionwp_logoutsky-login-redirect.php:293
filterlogout_urlsky-login-redirect.php:325
filterlogin_redirectsky-login-redirect.php:347
filterlogout_redirectsky-login-redirect.php:353
filterwidget_textsky-login-redirect.php:373
actioncarbon_fields_register_fieldssky-login-redirect.php:383
actioncarbon_fields_theme_options_container_savedsky-login-redirect.php:437
actionbefore_woocommerce_initsky-login-redirect.php:467
actionadmin_enqueue_scriptssky-login-redirect.php:565
Maintenance & Trust

Sky Login Redirect Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 9, 2026
PHP min version8.1
Downloads99K

Community Trust

Rating94/100
Number of ratings24
Active installs2K
Developer Profile

Sky Login Redirect Developer Profile

Matt Biscay

5 plugins · 2K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
29 days
View full developer profile
Detection Fingerprints

How We Detect Sky Login Redirect

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sky-login-redirect/assets/css/login-customizer.css/wp-content/plugins/sky-login-redirect/assets/js/login-customizer.js/wp-content/plugins/sky-login-redirect/assets/css/admin.css/wp-content/plugins/sky-login-redirect/assets/js/admin.js
Script Paths
/wp-content/plugins/sky-login-redirect/vendor/freemius/wordpress-sdk/start.php/wp-content/plugins/sky-login-redirect/vendor/autoload.php/wp-content/plugins/sky-login-redirect/lib/admin/meta.php/wp-content/plugins/sky-login-redirect/includes/notices.php/wp-content/plugins/sky-login-redirect/includes/ajax-handlers.php/wp-content/plugins/sky-login-redirect/includes/class-redirect-manager.php+2 more
Version Parameters
sky-login-redirect/assets/css/login-customizer.css?ver=sky-login-redirect/assets/js/login-customizer.js?ver=sky-login-redirect/assets/css/admin.css?ver=sky-login-redirect/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
sky-login-redirect
Data Attributes
data-sky-login-redirect-enabled
JS Globals
SkyLoginRedirect
REST Endpoints
/wp-json/sky-login-redirect/v1/settings
FAQ

Frequently Asked Questions about Sky Login Redirect