
Smithers Login Security & Risk Analysis
wordpress.org/plugins/smithers-loginAdd style to your WordPress multisite login pages! This plugin enables you to specify a CSS to be used on the login page with a custom image/messages.
Is Smithers Login Safe to Use in 2026?
Generally Safe
Score 85/100Smithers Login has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The smithers-login plugin version 0.4 exhibits a generally positive security posture based on the static analysis, with no identified dangerous functions, file operations, or external HTTP requests. The use of prepared statements for all SQL queries is a significant strength, mitigating the risk of SQL injection. Furthermore, the plugin has no known historical vulnerabilities, suggesting a history of secure development or a lack of prior scrutiny.
However, there are notable areas of concern. The complete absence of nonce checks is a significant weakness, particularly if any of the plugin's functionalities were to be exposed through AJAX handlers (though none are currently identified). The fact that 100% of output is not properly escaped presents a high risk of Cross-Site Scripting (XSS) vulnerabilities, even if the current attack surface is small. The presence of a capability check without adequate context raises questions about its effectiveness in protecting sensitive operations. The limited analysis depth indicated by zero taint flows also means potential vulnerabilities could be missed.
In conclusion, while the plugin avoids common pitfalls like raw SQL and has a clean vulnerability history, the lack of output escaping and nonce checks are critical oversights that could lead to significant security breaches if the plugin's functionalities evolve or are utilized in unexpected ways. The small attack surface is currently a mitigating factor, but the underlying potential for XSS remains a serious concern.
Key Concerns
- 100% of outputs are not properly escaped
- No nonce checks present
- Limited taint analysis depth
Smithers Login Security Vulnerabilities
Smithers Login Code Analysis
SQL Query Safety
Output Escaping
Smithers Login Attack Surface
WordPress Hooks 9
Maintenance & Trust
Smithers Login Maintenance & Trust
Maintenance Signals
Community Trust
Smithers Login Alternatives
DBD Login Style
dbd-login-style
Add style to your login page!! This plugin enables you to specify a style sheet to be used on the login page.
Add Admin CSS
add-admin-css
Easily define additional CSS (inline and/or by URL) to be added to all administration pages.
Custom CSS Manager
custom-css-manager-plugin
Simple plugin to manage Custom CSS Code!
Custom Login Admin Front-end CSS
custom-login-admin-front-end-css-with-multisite-support
Loads custom CSS on WordPress Login Pages, Admin and Front-end via admin interface. Works on Multisites as well.
Loginstyle
loginstyle
Brand and customize your login page without any coding knowledge.
Smithers Login Developer Profile
11 plugins · 2K total installs
How We Detect Smithers Login
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/smithers-login/smithers-login.cssHTML / DOM Fingerprints
custom-login-messagecustom-logout-messagesl_pass_form_msg