
TWP login Security & Risk Analysis
wordpress.org/plugins/twp-loginsimple css editor for wp-login page
Is TWP login Safe to Use in 2026?
Generally Safe
Score 85/100TWP login has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The twp-login v1.1.1 plugin exhibits a generally good security posture with no known vulnerabilities in its history and a clean record regarding critical or high-severity issues. The static analysis shows a complete absence of a significant attack surface, with zero AJAX handlers, REST API routes, shortcodes, or cron events, which is a strong indicator of secure design. Furthermore, the absence of dangerous functions and external HTTP requests is also positive. However, there are areas of concern. The plugin uses a considerable number of SQL queries (16 total), with only 50% utilizing prepared statements, leaving half of them potentially vulnerable to SQL injection if not handled meticulously. The taint analysis reveals one flow with unsanitized paths, classified as high severity, which is a critical finding that requires immediate attention as it indicates a potential pathway for malicious data to be processed without proper validation or sanitization, possibly leading to command injection or other severe exploits. Additionally, the complete lack of nonce checks and capability checks across all entry points, coupled with only 69% of output being properly escaped, suggests a lack of robust security defenses against common web attacks like Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS). While the plugin's historical absence of vulnerabilities is commendable, the identified taint flow and the lack of fundamental security checks like nonces and capability checks represent significant potential weaknesses.
Key Concerns
- High severity unsanitized path flow
- 50% of SQL queries not using prepared statements
- Missing nonce checks
- Missing capability checks
- 31% of output not properly escaped
TWP login Security Vulnerabilities
TWP login Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
TWP login Attack Surface
WordPress Hooks 7
Maintenance & Trust
TWP login Maintenance & Trust
Maintenance Signals
Community Trust
TWP login Alternatives
WP Admin White Label WordPress Login Page
white-label-wp-login-page
Change the default style of WordPress WP Admin login with a unique, beautiful, white-label style.
Custom Login Page Customizer
login-customizer
Custom Login Customizer allows you to easily customize your admin login page, straight from your WordPress Customizer!
All In One Login — WP Admin Login Page Security and Customization with Google reCAPTCHA, Social Login, Limit Login Attempt, 2FA, and more.
change-wp-admin-login
Do you want to secure and customize the WordPress login page? Download the All in One Login plugin for login page security and customization.
Rename wp-admin login
rename-wp-admin-login
Rename wp-admin login* is a plugin that allows us to rename wp-admin login URL to anything you want
Change Login Page Logo
change-login-page-logo
A simple and easy way to change WordPress login logo, using Change Login Page Logo plugin you can change logo image, logo width, height and logo URL.
TWP login Developer Profile
2 plugins · 0 total installs
How We Detect TWP login
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/twp-login/style.css/wp-content/plugins/twp-login/adm/twp.jstwp-login/style.css?ver=twp-login/adm/twp.js?ver=HTML / DOM Fingerprints
twp_editordata-settingtwpl_color_picker