
Add Admin CSS Security & Risk Analysis
wordpress.org/plugins/add-admin-cssEasily define additional CSS (inline and/or by URL) to be added to all administration pages.
Is Add Admin CSS Safe to Use in 2026?
Generally Safe
Score 99/100Add Admin CSS has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The add-admin-css plugin, version 2.5.1, exhibits a mixed security posture. On the positive side, it has a very small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events exposed. The plugin also demonstrates good practices regarding SQL queries, with 100% using prepared statements, and a high percentage of output escaping. However, several concerns warrant attention.
The static analysis revealed a single 'dangerous function' usage: unserialize. While the data doesn't explicitly show how this function is used or if it's exposed to untrusted input, the presence of unserialize is a red flag. It's crucial to ensure that any data being unserialized is rigorously validated and comes from trusted sources to prevent object injection vulnerabilities.
The vulnerability history, particularly the medium severity CVE related to Exposure of Sensitive Information to an Unauthorized Actor, dated very recently, is a significant concern. Even though it's currently patched, this indicates a past weakness that could be exploited if not addressed thoroughly or if similar flaws exist. The absence of any direct taint analysis results with critical or high severity is a positive sign, but it doesn't entirely negate the risks posed by the unserialize function or past vulnerabilities.
Key Concerns
- Presence of 'unserialize' function
- Recent medium severity CVE (sensitive info exposure)
Add Admin CSS Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Add Admin CSS <= 2.0.1 - Unauthenticated Full Path Dislcosure
Add Admin CSS Release Timeline
Add Admin CSS Code Analysis
Dangerous Functions Found
Output Escaping
Add Admin CSS Attack Surface
WordPress Hooks 15
Maintenance & Trust
Add Admin CSS Maintenance & Trust
Maintenance Signals
Community Trust
Add Admin CSS Alternatives
Custom CSS Manager
custom-css-manager-plugin
Simple plugin to manage Custom CSS Code!
Zeus WordPress Admin
zeus-admin-theme
A simple, clean admin theme with select features to extend and improve your WordPress experience.
Custom CSS Injector
css-injector
Fast & simple solution to control custom CSS code in selected areas of Your website. Works to 8 times faster than most popular CSS plugin.
Conditional Stylesheets and Body Classes
browsers
Add conditional browser stylesheets and body class declarations
DBD Login Style
dbd-login-style
Add style to your login page!! This plugin enables you to specify a style sheet to be used on the login page.
Add Admin CSS Developer Profile
63 plugins · 92K total installs
How We Detect Add Admin CSS
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/add-admin-css/add-admin-css/style.css?ver=HTML / DOM Fingerprints
<!-- This plugin is disabled. -->data-c2c-add-admin-csswindow.c2c_AddAdminCSS