
YITH Custom Login Security & Risk Analysis
wordpress.org/plugins/yith-custom-loginYITH Custom Login give you the ability to customize the login page of wordpress.
Is YITH Custom Login Safe to Use in 2026?
Generally Safe
Score 99/100YITH Custom Login has a strong security track record. Known vulnerabilities have been patched promptly.
The static analysis of yith-custom-login v1.7.7 reveals a generally positive security posture in terms of its attack surface and direct code execution risks. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, resulting in zero total entry points and zero unprotected ones. Furthermore, the plugin avoids dangerous functions, performs all SQL queries using prepared statements, and has no external HTTP requests. This suggests a careful approach to direct code interaction points.
However, concerns arise from the output escaping and file operation signals. With only 10% of outputs properly escaped among 60 total outputs, there's a significant risk of Cross-Site Scripting (XSS) vulnerabilities, especially given the plugin's past vulnerability history which includes two medium-severity XSS issues. The presence of file operations without further context also warrants caution. The complete absence of nonce and capability checks on entry points (though there are none identified) is a missed opportunity for robustness, and the zero taint analysis flows, while seemingly good, could also indicate that the analysis itself had limitations or that the plugin's structure doesn't lend itself to traditional taint flow detection.
Despite the low number of identified entry points, the vulnerability history, particularly the prevalence of XSS, coupled with the poor output escaping rates, indicates a recurring weakness. The recent medium vulnerability in September 2024, related to XSS, reinforces this. The plugin's strengths lie in its limited attack surface and secure database interactions. The weaknesses are primarily in output sanitization and the potential for unintended file interactions, which, when combined with past XSS issues, present a tangible risk to users.
Key Concerns
- Poor output escaping (10% escaped)
- Past medium XSS vulnerabilities
- No nonce checks
- No capability checks
- File operations detected
YITH Custom Login Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
YITH Custom Login <= 1.7.3 - Reflected Cross-Site Scripting
YITH Custom Login <= 1.7.0 - Authenticated (Admin+) Stored Cross-Site Scripting
YITH Custom Login Code Analysis
SQL Query Safety
Output Escaping
YITH Custom Login Attack Surface
WordPress Hooks 15
Maintenance & Trust
YITH Custom Login Maintenance & Trust
Maintenance Signals
Community Trust
YITH Custom Login Alternatives
WIP Custom Login
wip-custom-login
WIP Custom Login allows you to customize the login section of WordPress and you can replace the admin WordPress logo, set a background image and much …
Login Screen Designer
login-screen-designer
Customize WordPress login page branding—logo, background, colors, and messages. A simple and effective tool for personalizing the login experience.
Custom Login Logo – Easily Add a Logo to Your WordPress Login Page
custom-login-logo
Easily add a custom logo to your WordPress login page using the built-in media uploader.
Custom Login Logo and URL
custom-login-logo-and-url
Effortlessly customize your WordPress login page with a custom logo and branded URL to enhance user experience and security.
LoginPress | wp-login Custom Login Page Customizer
loginpress
LoginPress is a Custom Login Page Customizer plugin allows you to easily customize the layout of login, admin login, client login, register pages.
YITH Custom Login Developer Profile
33 plugins · 1.1M total installs
How We Detect YITH Custom Login
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/yith-custom-login/assets/images/mascotte.pngyith-custom-login/assets/images/mascotte.png?ver=yith-custom-login/assets/css/login-style.css?ver=HTML / DOM Fingerprints
mascotteyith_login_mascotteyith_login_mascotte_urlyith_login_background_coloryith_login_background_imageyith_login_background_repeatyith_login_background_position+17 more