
wp Custom Login Security & Risk Analysis
wordpress.org/plugins/wp-custom-login-register-pageThis plugin can changes the logo & background image of the login form.
Is wp Custom Login Safe to Use in 2026?
Generally Safe
Score 85/100wp Custom Login has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "wp-custom-login-register-page" v1.0.1 exhibits a generally strong security posture based on the static analysis provided. The complete absence of identified AJAX handlers, REST API routes, shortcodes, and cron events suggests a very limited attack surface. Furthermore, the code signals indicate a commitment to secure coding practices, with no dangerous functions, all SQL queries using prepared statements, and no file operations or external HTTP requests.
However, there are some areas for concern. The most notable is the complete lack of nonce checks and capability checks. This means that any functionality, even if not immediately apparent from the entry points, could potentially be triggered by an unauthenticated or unauthorized user if an entry point existed. The moderate rate of proper output escaping (55%) also presents a risk of Cross-Site Scripting (XSS) vulnerabilities if untrusted data is displayed to users without sufficient sanitization. The zero taint analysis flows and vulnerability history are positive indicators, suggesting no known critical or high-severity issues have been discovered in the past, but this does not negate the risks identified in the static analysis.
In conclusion, while the plugin benefits from a minimal attack surface and secure handling of database queries, the absence of critical security checks like nonces and capability checks, coupled with a concerning percentage of unescaped output, represents a significant weakness. The lack of past vulnerabilities is a positive sign, but the current code analysis highlights potential avenues for exploitation that should be addressed.
Key Concerns
- Missing nonce checks
- Missing capability checks
- Low percentage of properly escaped output
wp Custom Login Security Vulnerabilities
wp Custom Login Code Analysis
Output Escaping
wp Custom Login Attack Surface
WordPress Hooks 6
Maintenance & Trust
wp Custom Login Maintenance & Trust
Maintenance Signals
Community Trust
wp Custom Login Alternatives
AC Change Login Image
ac-change-login-logo
This plugin changes the image in the login page (wp-login.php), you can choose any image from your gallery and use it as login logo.
Change WordPress Login Logo
change-login-logo
Upload your logo for WordPress login page instead of the usual WordPress logo with simple settings.
Custom Login
custom-login
Custom Login allows you to easily customize your admin login page, works great for client sites!
Uber Login Logo
uber-login-logo
A simple, lightweight WordPress plugin to change your login logo.
Add Logo to Admin
add-logo-to-admin
Add a custom logo to your wp-admin and login page.
wp Custom Login Developer Profile
4 plugins · 2K total installs
How We Detect wp Custom Login
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-custom-login-register-page/style-login.css/wp-content/plugins/wp-custom-login-register-page/images/logo.png/wp-content/plugins/wp-custom-login-register-page/images/bg1.jpgHTML / DOM Fingerprints
ncustom-login-options-form