Is it safe for me to use in live website?
member.php
if($_SESSION['login'] == 1) //member stuff $_SESSION['login'] is set after user authenticate via login.php
Yes, you should check if $_SESSION is set too.
if(isset($_SESSION['login'])) { ... if($_SESSION['login'] == 1) { ... if( isset($_SESSION['login']) && $_SESSION['login'] == 1 ) The right hand part of the expression isn't evaluated if the left hand is false, so no notice will be generated