WP Login and Logout Redirect Security & Risk Analysis

wordpress.org/plugins/wp-login-and-logout-redirect

This plugin enable simple and easy way to redirect user to your chosen page URL after login or logout or both.

6K active installs v3.1.5 PHP 7.4+ WP 5.8+ Updated Dec 24, 2025
login-redirectlogout-redirectwordpress-login-logout-redirectwp-login-and-logout-redirectwp-login-logout-redirect
100
A · Safe
CVEs total1
Unpatched0
Last CVEApr 10, 2024
Safety Verdict

Is WP Login and Logout Redirect Safe to Use in 2026?

Generally Safe

Score 100/100

WP Login and Logout Redirect has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Apr 10, 2024Updated 4mo ago
Risk Assessment

The plugin "wp-login-and-logout-redirect" v3.1.5 presents a mixed security profile. While the static analysis shows an absence of immediate threats like dangerous functions, raw SQL queries, file operations, external requests, and taint flows, there are notable areas for improvement. The complete lack of capability checks and nonce checks across all identified entry points is a significant concern, suggesting a potential for unauthorized actions if such entry points existed. Furthermore, the moderate rate of unescaped output, while not critical, could expose users to cross-site scripting vulnerabilities if malicious data is processed. The plugin's vulnerability history, with one known medium-severity CVE for cross-site scripting, further reinforces the importance of robust input sanitization and output escaping. Despite the lack of critical immediate findings in the static analysis, the absence of critical security controls like capability checks on potential entry points and the past XSS vulnerability highlight a need for vigilance and further hardening.

Key Concerns

  • No capability checks on entry points
  • No nonce checks on entry points
  • Moderate rate of unescaped output
  • Past medium CVE for XSS
Vulnerabilities
1 published

WP Login and Logout Redirect Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-31927medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

WP Login and Logout Redirect <= 1.2 - Authenticated (Admin+) Stored Cross-Site Scripting

Apr 10, 2024 Patched in 2.0 (7d)
Version History

WP Login and Logout Redirect Release Timeline

v3.1.5Current
v3.1.4
v3.1.3
v3.1.2
v3.1.1
v3.1
v3.0
v2.0.1
v2.0
v1.21 CVE
v1.11 CVE
v1.01 CVE
Code Analysis
Analyzed Mar 16, 2026

WP Login and Logout Redirect Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
8 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

80% escaped10 total outputs
Attack Surface

WP Login and Logout Redirect Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 18
actioninitincludes\Assets.php:10
actionadmin_enqueue_scriptsincludes\Assets.php:13
actionwp_enqueue_scriptsincludes\Assets.php:15
filterlogin_redirectincludes\Redirection.php:10
filterwoocommerce_login_redirectincludes\Redirection.php:11
actionwp_logoutincludes\Redirection.php:12
actionadmin_menuincludes\Settings.php:10
actionadmin_initincludes\Settings.php:12
actionwp_loginincludes\UserLoginTime.php:10
filtermanage_users_columnsincludes\UserLoginTime.php:11
filtermanage_users_custom_columnincludes\UserLoginTime.php:12
filtermanage_users_sortable_columnsincludes\UserLoginTime.php:13
actionpre_get_usersincludes\UserLoginTime.php:14
actionplugins_loadedincludes\WpLoginLogoutRedirect.php:47
actionwoocommerce_flush_rewrite_rulesincludes\WpLoginLogoutRedirect.php:48
actioninitincludes\WpLoginLogoutRedirect.php:146
actioninitincludes\WpLoginLogoutRedirect.php:147
actionplugins_loadedincludes\WpLoginLogoutRedirect.php:148
Maintenance & Trust

WP Login and Logout Redirect Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 24, 2025
PHP min version7.4
Downloads61K

Community Trust

Rating96/100
Number of ratings5
Active installs6K
Developer Profile

WP Login and Logout Redirect Developer Profile

Md Aminur Islam

5 plugins · 16K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
8 days
View full developer profile
Detection Fingerprints

How We Detect WP Login and Logout Redirect

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-login-and-logout-redirect/assets/css/style.css/wp-content/plugins/wp-login-and-logout-redirect/assets/js/script.js
Script Paths
/wp-content/plugins/wp-login-and-logout-redirect/assets/js/script.js
Version Parameters
wp-login-and-logout-redirect/assets/css/style.css?ver=wp-login-and-logout-redirect/assets/js/script.js?ver=

HTML / DOM Fingerprints

JS Globals
Wp_Login_Logout_Redirect_AdminWp_Login_Logout_Redirect
FAQ

Frequently Asked Questions about WP Login and Logout Redirect