PLUGIN SECURITY
Is Loginizer safe?
Loginizer is a WordPress security plugin which helps you fight against bruteforce attacks.
What this plugin does
- Slug:
loginizer - Author: Softaculous
- 1000000+ active installs
- 96/100 rating (1030 reviews on wordpress.org)
- 31764187 all-time downloads
- On WordPress.org since 2016-01-27
accessadminloginLoginizersecurity
Maintenance status
- Latest known version: 2.0.9
- Last updated: 2026-08-19 12:04pm GMT
- Tested up to WordPress: 7.1
- Requires PHP: 5.5+
- Max supported PHP (analyzed): <8.0
Known vulnerabilities
8 known CVEs on file for Loginizer. Reported between 2017 and 2024.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2024-10097 | Loginizer [loginizer] < 1.9.3 | Improper Authentication | High 8.1 | < 1.9.3 | 1.9.3 | 2024-11-04 | ✓ fixed in latest |
| CVE-2023-2296 | Loginizer [loginizer] < 1.7.9 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 1.7.9 | 1.7.9 | 2023-05-02 | ✓ fixed in latest |
| CVE-2022-45079 | Loginizer [loginizer] < 1.7.6 | Cross-Site Request Forgery (CSRF) | Medium 4.7 | < 1.7.6 | 1.7.6 | 2022-12-05 | ✓ fixed in latest |
| CVE-2022-45084 | Loginizer [loginizer] < 1.7.6 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.1 | < 1.7.6 | 1.7.6 | 2022-05-12 | ✓ fixed in latest |
| CVE-2020-27615 | Loginizer [loginizer] < 1.6.4 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | Critical 9.8 | < 1.6.4 | 1.6.4 | 2020-10-21 | ✓ fixed in latest |
| — | Loginizer [loginizer] < 1.6.4 | — | Unknown | < 1.6.4 | 1.6.4 | 2020-10-21 | ✓ fixed in latest |
| CVE-2018-11366 | Loginizer [loginizer] >= 1.3.8 - <= 1.3.9 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | 1.3.8–1.4.0 | 1.4.0 | 2018-05-22 | ✓ fixed in latest |
| CVE-2017-12650 | Loginizer [loginizer] < 1.3.6 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | Critical 9.8 | < 1.3.6 | 1.3.6 | 2017-08-07 | ✓ fixed in latest |
+ 3 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2017-12651 | Loginizer [loginizer] < 1.3.6 | Cross-Site Request Forgery (CSRF) | High 8.8 | < 1.3.6 | 1.3.6 | 2017-08-07 | ✓ fixed in latest |
| — | Loginizer [loginizer] < 1.7.6 | — | Unknown | < 1.7.6 | 1.7.6 | — | ✓ fixed in latest |
| — | Loginizer [loginizer] < 1.7.6 | — | Unknown | < 1.7.6 | 1.7.6 | — | ✓ fixed in latest |
How to fix it
Keep Loginizer updated — 2.0.9 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- WPS Hide Login — 2000000+ active installs — 96/100 (2111) — max PHP 8.4
- Security Optimizer – The All-In-One Protection Plugin — 1000000+ active installs — 90/100 (157) — max PHP <8.0
- User Role Editor — 700000+ active installs — 90/100 (288) — max PHP 8.4
- Members – Membership & User Role Editor Plugin — 300000+ active installs — 98/100 (1274) — max PHP 8.4
- Limit Login Attempts — 300000+ active installs — 92/100 (202) — max PHP 8.4
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.