
Wp Super Login Security & Risk Analysis
wordpress.org/plugins/wp-super-loginWith this plugin now more your site will look good with a choice of 7 different themes wp-super-login plugin with you. No ads.
Is Wp Super Login Safe to Use in 2026?
Generally Safe
Score 100/100Wp Super Login has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-super-login plugin v1.5.3 presents a mixed security posture. On the positive side, there are no documented CVEs, the plugin does not utilize external HTTP requests or file operations, and all SQL queries are prepared statements, indicating good practices in these areas. The absence of shortcodes, cron events, and REST API routes also suggests a limited attack surface. However, the static analysis reveals significant concerns. Notably, 100% of the plugin's output is unescaped, creating a high risk for cross-site scripting (XSS) vulnerabilities. Furthermore, while the taint analysis found no critical or high severity flows, there are two flows with unsanitized paths, and importantly, zero capability checks or nonce checks across all entry points. This lack of authorization and integrity checks makes any potential vulnerabilities that might arise from the unsanitized paths much easier to exploit.
The vulnerability history is clean, with no recorded CVEs, which is a positive indicator. However, this is often more a reflection of the plugin's age and potentially less rigorous security auditing in the past rather than a guarantee of future security. The lack of recent vulnerabilities might also be influenced by the limited attack surface and absence of certain common attack vectors. The critical weaknesses lie in the unescaped output and the complete absence of capability and nonce checks. These are fundamental security mechanisms that should be implemented on all entry points, especially when handling any form of data that could be influenced by user input.
In conclusion, while wp-super-login v1.5.3 has strengths in its database interactions and lack of external dependencies, the pervasive issue of unescaped output and the complete absence of essential security checks (nonces and capability checks) present significant risks. The taint analysis also flags unsanitized paths, which are particularly dangerous when combined with the lack of proper authorization. Users should be cautious, and further investigation into the exact nature of these unsanitized paths and the output contexts is highly recommended before deploying this plugin.
Key Concerns
- All output unescaped
- No nonce checks on entry points
- No capability checks on entry points
- Taint flow with unsanitized path
- Taint flow with unsanitized path
Wp Super Login Security Vulnerabilities
Wp Super Login Code Analysis
Output Escaping
Data Flow Analysis
Wp Super Login Attack Surface
WordPress Hooks 8
Maintenance & Trust
Wp Super Login Maintenance & Trust
Maintenance Signals
Community Trust
Wp Super Login Alternatives
WPS Hide Login
wps-hide-login
Change wp-login.php to anything you want.
LoginPress | wp-login Custom Login Page Customizer
loginpress
LoginPress is a Custom Login Page Customizer plugin allows you to easily customize the layout of login, admin login, client login, register pages.
Custom Login Page Customizer
login-customizer
Custom Login Customizer allows you to easily customize your admin login page, straight from your WordPress Customizer!
All In One Login — WP Admin Login Page Security and Customization with Google reCAPTCHA, Social Login, Limit Login Attempt, 2FA, and more.
change-wp-admin-login
Do you want to secure and customize the WordPress login page? Download the All in One Login plugin for login page security and customization.
Easy Hide Login
easy-hide-login
Hide wp-login.php file, prevent attacks on login form, hide login & increase security. No files are changed.
Wp Super Login Developer Profile
7 plugins · 70 total installs
How We Detect Wp Super Login
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-super-login/codemirror.css/wp-content/plugins/wp-super-login/codemirror.js/wp-content/plugins/wp-super-login/xml.js/wp-content/plugins/wp-super-login/codemirror.js/wp-content/plugins/wp-super-login/xml.jsHTML / DOM Fingerprints
sm_pnressm_rebuildCodeMirrorCodeMirror-scrollid="sm_pnres"id="sm_rebuild"