WP Custom Admin Login Lite – Free WordPress plugin to make a customized admin login page Security & Risk Analysis

wordpress.org/plugins/wp-custom-admin-login-lite

WP Custom Admin Login - WordPress Plugin to make a Customized Admin Login Page allow you to beautify your wp-login page with quick easy templates.

40 active installs v1.0.1 PHP 5.6+ WP 4.8+ Updated Aug 10, 2018
admin-custom-logincustom-admin-logincustom-logincustom-login-customizercustom-login-page
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is WP Custom Admin Login Lite – Free WordPress plugin to make a customized admin login page Safe to Use in 2026?

Generally Safe

Score 85/100

WP Custom Admin Login Lite – Free WordPress plugin to make a customized admin login page has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

This plugin, wp-custom-admin-login-lite v1.0.1, exhibits a strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points significantly limits the potential attack surface. Furthermore, the code signals indicate a lack of dangerous functions, all SQL queries utilizing prepared statements, and a high percentage of properly escaped output. The presence of file operations and an external HTTP request are not inherently risky but warrant careful review in a deeper analysis.

The vulnerability history is exceptionally clean, with zero known CVEs and no recorded common vulnerability types. This suggests a well-maintained codebase or a lack of prior security scrutiny, but the absence of past issues is a positive indicator. The primary areas of concern from the static analysis are the complete absence of nonce checks and the single capability check. While the attack surface is currently zero, the lack of these standard WordPress security mechanisms could become a risk if new functionalities are added or if the plugin interacts with user-controllable data in the future without implementing these checks.

In conclusion, wp-custom-admin-login-lite v1.0.1 appears to be a secure plugin with good coding practices evident in its prepared statements and output escaping. The lack of historical vulnerabilities is also a significant strength. However, the complete omission of nonce checks and limited capability checks represent a potential weakness that could be exploited if the plugin's functionality expands or its interaction points with user input are not carefully secured.

Key Concerns

  • No nonce checks implemented
  • Limited capability checks
  • External HTTP requests without context
Vulnerabilities
None known

WP Custom Admin Login Lite – Free WordPress plugin to make a customized admin login page Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP Custom Admin Login Lite – Free WordPress plugin to make a customized admin login page Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
24
201 escaped
Nonce Checks
0
Capability Checks
1
File Operations
3
External Requests
1
Bundled Libraries
0

Output Escaping

89% escaped225 total outputs
Attack Surface

WP Custom Admin Login Lite – Free WordPress plugin to make a customized admin login page Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 25
actionadmin_menuinc\classes\admin\wcal-admin.php:12
actionadmin_menuinc\classes\admin\wcal-admin.php:13
actionwp_enqueue_scriptsinc\classes\admin\wcal-enqueue.php:8
actionadmin_enqueue_scriptsinc\classes\admin\wcal-enqueue.php:9
actioninitinc\classes\admin\wcal-init.php:5
actioncustomize_registerinc\classes\customizer-class\wcal-customizer-tabs\customizer.php:294
actioncustomize_preview_initinc\classes\customizer-class\wcal-customizer-tabs\tab-class.php:28
filterlogin_enqueue_scriptsinc\classes\wcal-admin-login-core.php:12
actioncustomize_registerinc\classes\wcal-customizer.php:12
actioncustomize_controls_enqueue_scriptsinc\classes\wcal-customizer.php:13
filterlogin_headinc\classes\wcal-templates\wcal-template-1.php:12
filterlogin_footerinc\classes\wcal-templates\wcal-template-1.php:13
filterlogin_forminc\classes\wcal-templates\wcal-template-1.php:14
filterlogin_headinc\classes\wcal-templates\wcal-template-2.php:12
filterlogin_footerinc\classes\wcal-templates\wcal-template-2.php:13
filterlogin_forminc\classes\wcal-templates\wcal-template-2.php:14
filterlogin_headinc\classes\wcal-templates\wcal-template-3.php:12
filterlogin_footerinc\classes\wcal-templates\wcal-template-3.php:13
filterlogin_forminc\classes\wcal-templates\wcal-template-3.php:14
filterlogin_headinc\classes\wcal-templates\wcal-template-4.php:12
filterlogin_footerinc\classes\wcal-templates\wcal-template-4.php:13
filterlogin_forminc\classes\wcal-templates\wcal-template-4.php:14
filterlogin_headinc\classes\wcal-templates\wcal-template-5.php:12
filterlogin_footerinc\classes\wcal-templates\wcal-template-5.php:13
filterlogin_forminc\classes\wcal-templates\wcal-template-5.php:14
Maintenance & Trust

WP Custom Admin Login Lite – Free WordPress plugin to make a customized admin login page Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedAug 10, 2018
PHP min version5.6
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs40
Developer Profile

WP Custom Admin Login Lite – Free WordPress plugin to make a customized admin login page Developer Profile

8Degree Themes

4 plugins · 260 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP Custom Admin Login Lite – Free WordPress plugin to make a customized admin login page

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-custom-admin-login-lite/css/font-awesome.min.css/wp-content/plugins/wp-custom-admin-login-lite/css/wcal-backend.css/wp-content/plugins/wp-custom-admin-login-lite/js/alpha-color-picker.js/wp-content/plugins/wp-custom-admin-login-lite/css/alpha-color-picker.css
Script Paths
/wp-content/plugins/wp-custom-admin-login-lite/js/alpha-color-picker.js
Version Parameters
wp-custom-admin-login-lite/css/font-awesome.min.css?ver=wp-custom-admin-login-lite/css/wcal-backend.css?ver=wp-custom-admin-login-lite/js/alpha-color-picker.js?ver=wp-custom-admin-login-lite/css/alpha-color-picker.css?ver=

HTML / DOM Fingerprints

CSS Classes
alpha-color-controlcustomize-control-titledescription customize-control-description
Data Attributes
data-show-opacitydata-palettedata-default-color
JS Globals
WCAL_PATHWCAL_IMG_DIRWCAL_CSS_DIRWCAL_JS_DIRWCAL_VERSIONWCAL_TD+1 more
FAQ

Frequently Asked Questions about WP Custom Admin Login Lite – Free WordPress plugin to make a customized admin login page