
White Label – WordPress Custom Admin, Custom Login Page, and Custom Dashboard Security & Risk Analysis
wordpress.org/plugins/white-labelOur White Label WordPress plugin lets you make a custom admin experience. Create a custom login page, a custom dashboard, and much more.
Is White Label – WordPress Custom Admin, Custom Login Page, and Custom Dashboard Safe to Use in 2026?
Generally Safe
Score 100/100White Label – WordPress Custom Admin, Custom Login Page, and Custom Dashboard has a strong security track record. Known vulnerabilities have been patched promptly.
The "white-label" plugin v2.16.5 exhibits a mixed security posture. While the static analysis reveals a commendable absence of direct attack surface vectors like unprotected AJAX handlers, REST API routes, or shortcodes, and no critical or high severity taint flows, there are notable concerns regarding data handling and past vulnerabilities. The high percentage of improperly escaped output (80%) presents a significant risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data might be rendered directly in the browser without proper sanitization. The presence of a single SQL query that does not use prepared statements is also a concern, potentially opening the door to SQL injection if the input is not rigorously validated.
The vulnerability history shows one past medium-severity CVE, specifically a Cross-Site Request Forgery (CSRF). Although this vulnerability is currently patched, its existence indicates that the plugin has had exploitable flaws in the past. The fact that it was a CSRF vulnerability suggests issues with proper nonce checks or authorization mechanisms in previous versions. While the current static analysis shows some nonce and capability checks, the overall output escaping issue remains a critical weakness that could be exploited even with good authentication controls.
In conclusion, the plugin has strengths in its limited attack surface and the absence of severe taint analysis findings. However, the significant prevalence of unescaped output and the historical presence of a CSRF vulnerability demand careful consideration. The lack of prepared statements in the sole SQL query adds another layer of risk. Users should be aware of the potential for XSS and SQL injection, and while past vulnerabilities are patched, the need for robust output escaping cannot be overstated.
Key Concerns
- High percentage of improperly escaped output
- SQL query without prepared statements
- Historical medium severity CVE (CSRF)
White Label – WordPress Custom Admin, Custom Login Page, and Custom Dashboard Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
White Label <= 2.9.0 - Cross-Site Request Forgery via white_label_reset_wl_admins
White Label – WordPress Custom Admin, Custom Login Page, and Custom Dashboard Code Analysis
SQL Query Safety
Output Escaping
White Label – WordPress Custom Admin, Custom Login Page, and Custom Dashboard Attack Surface
WordPress Hooks 54
Maintenance & Trust
White Label – WordPress Custom Admin, Custom Login Page, and Custom Dashboard Maintenance & Trust
Maintenance Signals
Community Trust
White Label – WordPress Custom Admin, Custom Login Page, and Custom Dashboard Alternatives
AGCA – Custom Dashboard & Login Page
ag-custom-admin
CHANGE: admin menu, login page, admin bar, dashboard widgets, custom colors, custom CSS & JS, logo & images
Branda – White Label & Branding, Free Login Page Customizer
branda-white-labeling
White label & rebrand your login page & WordPress dashboard. Customize system emails & get everything to rebrand WordPress with Branda.
White Label Builder
white-label-builder
Simple & lightweight plugin to customize WordPress to fit your brand. Easily White Label and customize client websites.
Custom Login Page Customizer
colorlib-login-customizer
Customize your WordPress login page with live preview. Change logo, background, colors, and form styling without coding.
Admin Custom Login
admin-custom-login
Customize Your WordPress Login Screen Amazingly - Add Own Logo, Add Social Profiles, Login Form Positions, Background Image Slide Show
White Label – WordPress Custom Admin, Custom Login Page, and Custom Dashboard Developer Profile
4 plugins · 23K total installs
How We Detect White Label – WordPress Custom Admin, Custom Login Page, and Custom Dashboard
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/white-label/admin/css/admin.css/wp-content/plugins/white-label/admin/css/admin-pro.css/wp-content/plugins/white-label/admin/css/admin-free.css/wp-content/plugins/white-label/admin/js/admin.js/wp-content/plugins/white-label/admin/js/admin.jswhite-label/admin/css/admin.css?ver=white-label/admin/css/admin-pro.css?ver=white-label/admin/css/admin-free.css?ver=white-label/admin/js/admin.js?ver=HTML / DOM Fingerprints
white-label-admindata-white-label-settingswhiteLabelAdmin