
Admin Command Palette Security & Risk Analysis
wordpress.org/plugins/admin-command-paletteOptimize WordPress admin navigation with a modal window to search for and navigate directly to WordPress admin pages.
Is Admin Command Palette Safe to Use in 2026?
Generally Safe
Score 85/100Admin Command Palette has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'admin-command-palette' plugin v1.0.2 exhibits a mixed security posture. While it demonstrates good practices such as using prepared statements for all SQL queries and having no recorded vulnerabilities or dangerous functions, significant concerns arise from its attack surface and output handling. The plugin exposes one AJAX handler that lacks any authentication or capability checks, creating a direct entry point for potential attackers. Furthermore, a concerning 100% of its output operations are not properly escaped, which could lead to Cross-Site Scripting (XSS) vulnerabilities if any user-supplied data is reflected directly to the browser without sanitization. The absence of taint analysis findings and vulnerability history is positive, suggesting that any past issues have been addressed or that the plugin's functionality doesn't typically lend itself to common complex vulnerabilities. However, the identified unprotected AJAX endpoint and the widespread unescaped output represent clear and actionable security risks that need immediate attention to improve the overall security of the plugin.
Key Concerns
- Unprotected AJAX handler
- 0% of outputs properly escaped
Admin Command Palette Security Vulnerabilities
Admin Command Palette Code Analysis
SQL Query Safety
Output Escaping
Admin Command Palette Attack Surface
AJAX Handlers 1
WordPress Hooks 15
Maintenance & Trust
Admin Command Palette Maintenance & Trust
Maintenance Signals
Community Trust
Admin Command Palette Alternatives
Dashboard Navigator
dashnav
Navigate your WordPress dashboard by searching with a few keystrokes. Press shift shift, then a few letters of the menu item you want.
Admin Compass
admin-compass
Admin Compass provides fast, global search functionality for your WordPress admin area.
Admin Menu Search (AMS)
admin-menu-search-ams
Quickly search for menu items with support for multiple keyboard layouts.
Admin Menu Search
admin-menu-search
Admin Menu Search adds a search box filter to the top of the WordPress Admin Menu so you can easily locate items on sites with lots of menus.
Admin Search
admin-search
Admin Search adds a simple, easy-to-use interface to your WordPress admin site that gives you and your admin users the ability to search across multip …
Admin Command Palette Developer Profile
1 plugin · 70 total installs
How We Detect Admin Command Palette
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/admin-command-palette/admin/css/acp-admin.css/wp-content/plugins/admin-command-palette/admin/js/admin.min.js/wp-content/plugins/admin-command-palette/admin/js/admin.min.jsadmin-command-palette/admin/css/acp-admin.css?ver=admin-command-palette/admin/js/admin.min.js?ver=HTML / DOM Fingerprints
data-search-results-group-by-typeacp_user_optionsacpAjax/wp-json/acp/v1/search