Easy White Label Security & Risk Analysis

wordpress.org/plugins/wp-white-label-login

Enhance login experience with a customized login, registration, and lost password page. Activate and enjoy a seamless branded login area.

50 active installs v7.2.1 PHP 7.4+ WP 3.4+ Updated Feb 3, 2024
brandingcustom-custom-loginlogin-customizerwhite-labelwordpress-login
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Easy White Label Safe to Use in 2026?

Generally Safe

Score 85/100

Easy White Label has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The "wp-white-label-login" plugin version 7.2.1 exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for all SQL queries and avoiding dangerous functions, file operations, and external HTTP requests. The plugin also implements a reasonable number of nonce and capability checks. However, significant concerns arise from the attack surface. The presence of two AJAX handlers without authentication checks presents a direct risk, as these entry points are vulnerable to unauthorized access and potential exploitation.

The taint analysis reveals two flows with unsanitized paths, though they are not classified as critical or high severity. This still indicates a potential for issues related to how data is handled, even if not immediately exploitable for severe damage. The output escaping is also a weakness, with only 53% of outputs being properly escaped. This could lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is displayed without sufficient sanitization.

The plugin's vulnerability history is notably clean, with no recorded CVEs. This suggests a generally well-maintained codebase and a lack of publicly known exploits. While this is a strong positive, it does not negate the risks identified in the static and taint analysis. The absence of past vulnerabilities is encouraging, but the identified weaknesses in the attack surface and output escaping require attention to maintain a robust security profile.

Key Concerns

  • Unprotected AJAX handlers
  • Low percentage of properly escaped output
  • Flows with unsanitized paths (low severity)
Vulnerabilities
None known

Easy White Label Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Easy White Label Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
67
75 escaped
Nonce Checks
5
Capability Checks
9
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

53% escaped142 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
<background.admin> (src\EasyWhiteLabel\Admin\pages\white-label-options\background.admin.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Easy White Label Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_cnkt_plugin_installersrc\EasyWhiteLabel\Plugin.php:92
authwp_ajax_cnkt_plugin_activationsrc\EasyWhiteLabel\Plugin.php:93
WordPress Hooks 18
actionnetwork_admin_menusrc\EasyWhiteLabel\Admin\AbstractAdminCore.php:309
actionadmin_menusrc\EasyWhiteLabel\Admin\AbstractAdminCore.php:311
actionadmin_enqueue_scriptssrc\EasyWhiteLabel\Admin\AbstractAdminCore.php:315
actionewl_update_plugins_listsrc\EasyWhiteLabel\DailyTask.php:27
actionadmin_initsrc\EasyWhiteLabel\PageAccess.php:26
actiontemplate_redirectsrc\EasyWhiteLabel\PageAccess.php:38
actioninitsrc\EasyWhiteLabel\Plugin.php:55
actioncustomize_registersrc\EasyWhiteLabel\Plugin.php:60
actioninitsrc\EasyWhiteLabel\Plugin.php:65
actionadmin_menusrc\EasyWhiteLabel\Plugin.php:72
filterlogin_headsrc\EasyWhiteLabel\Plugin.php:74
filterlogin_footersrc\EasyWhiteLabel\Plugin.php:76
filterlogin_headsrc\EasyWhiteLabel\Plugin.php:77
actionlogin_enqueue_scriptssrc\EasyWhiteLabel\Plugin.php:78
filterlogin_headertextsrc\EasyWhiteLabel\Plugin.php:79
actionlogin_enqueue_scriptssrc\EasyWhiteLabel\Plugin.php:80
filterlogin_headerurlsrc\EasyWhiteLabel\Plugin.php:83
actionadmin_enqueue_scriptssrc\EasyWhiteLabel\Plugin.php:91

Scheduled Events 2

ewl_update_plugins_list
ewl_update_plugins_list
Maintenance & Trust

Easy White Label Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedFeb 3, 2024
PHP min version7.4
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs50
Developer Profile

Easy White Label Developer Profile

uri

15 plugins · 1K total installs

88
trust score
Avg Security Score
91/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Easy White Label

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-white-label-login/assets/js/admin.js/wp-content/plugins/wp-white-label-login/assets/css/admin.css/wp-content/plugins/wp-white-label-login/assets/css/admin-main.css/wp-content/plugins/wp-white-label-login/assets/js/admin/settings.js/wp-content/plugins/wp-white-label-login/assets/js/admin/login-customizer.js/wp-content/plugins/wp-white-label-login/assets/js/admin/users.js/wp-content/plugins/wp-white-label-login/assets/js/admin/dashboard.js/wp-content/plugins/wp-white-label-login/assets/js/admin/support.js+3 more
Script Paths
/wp-content/plugins/wp-white-label-login/assets/js/admin.js/wp-content/plugins/wp-white-label-login/assets/js/admin/settings.js/wp-content/plugins/wp-white-label-login/assets/js/admin/login-customizer.js/wp-content/plugins/wp-white-label-login/assets/js/admin/users.js/wp-content/plugins/wp-white-label-login/assets/js/admin/dashboard.js/wp-content/plugins/wp-white-label-login/assets/js/admin/support.js+3 more
Version Parameters
wp-white-label-login/assets/css/admin.css?ver=wp-white-label-login/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
ewl-admin-wrapperewl-login-customizerewl-dashboard-statsewl-users-list-tableewl-support-sectionewl-activation-stepsewl-update-plugin-item
HTML Comments
<!-- Easy White Label plugin --><!-- Easy White Label Admin Wrapper --><!-- Easy White Label Login Customizer --><!-- Easy White Label Dashboard Statistics -->+4 more
Data Attributes
data-ewl-login-previewdata-ewl-user-iddata-ewl-setting-namedata-ewl-color-picker
JS Globals
window.EwlAdminwindow.EwlLoginCustomizerwindow.EwlDashboardwindow.EwlUsersListwindow.EwlSupportwindow.EwlActivation+3 more
REST Endpoints
/wp-json/ewl/v1/settings/wp-json/ewl/v1/login_customizer/wp-json/ewl/v1/users/wp-json/ewl/v1/support/wp-json/ewl/v1/activation/wp-json/ewl/v1/update
Shortcode Output
[easy-white-label-login-form][easy-white-label-registration-form][easy-white-label-lost-password-form]
FAQ

Frequently Asked Questions about Easy White Label