
Admin Expert Mode Security & Risk Analysis
wordpress.org/plugins/admin-expert-modeAllows users to hide inline documentation and help text that are geared for beginning users in the WordPress admin.
Is Admin Expert Mode Safe to Use in 2026?
Generally Safe
Score 85/100Admin Expert Mode has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "admin-expert-mode" v2.9 plugin exhibits a strong security posture based on the provided static analysis. There are no identified vulnerabilities in its vulnerability history, and the static analysis reveals no dangerous functions, no SQL queries that are not prepared, no external HTTP requests, and no file operations, all of which significantly reduce the attack surface. The absence of taint analysis findings further reinforces this positive outlook.
However, a notable concern is the complete lack of nonce checks across all identified entry points, despite the presence of capability checks. While the absence of a large attack surface mitigates immediate risk, relying solely on capability checks without nonces for certain operations, if they were present and sensitive, could theoretically leave the plugin susceptible to CSRF attacks if the plugin were to introduce such functionalities in the future. The fact that there are no AJAX handlers, REST API routes, shortcodes, or cron events with checks further means that any future introduction of these without proper nonce and capability checks would represent a new and significant security gap.
In conclusion, the plugin is currently in a very secure state with no known vulnerabilities and a code base that adheres to many good security practices. The primary area for caution is the complete absence of nonce checks. While not a current vulnerability due to the limited attack surface, it represents a potential area of weakness should the plugin's functionality expand without incorporating this essential security measure.
Key Concerns
- No nonce checks found.
Admin Expert Mode Security Vulnerabilities
Admin Expert Mode Release Timeline
Admin Expert Mode Code Analysis
Output Escaping
Admin Expert Mode Attack Surface
WordPress Hooks 7
Maintenance & Trust
Admin Expert Mode Maintenance & Trust
Maintenance Signals
Community Trust
Admin Expert Mode Alternatives
Admin Help Docs
admin-help-docs
Site developers and operators can easily create help documentation and notices for the admin area.
Admin Documentation
admin-documentation
Adds a simple documentation page to your WordPress admin to keep instructions, notes, and other helpful information for maintaining your website.
WP Help Docs
ilab-docs
Directly integrate markdown based help documentation for your WordPress theme or plugin into the WordPress admin for your end users and clients.
WP Help
wp-help
Site operators can create detailed, hierarchical documentation for the site's authors, editors, and contributors, viewable in the WordPress admin …
One Click Close Comments
one-click-close-comments
Conveniently close or open comments for a post or page with one click from the admin listing of posts.
Admin Expert Mode Developer Profile
63 plugins · 92K total installs
How We Detect Admin Expert Mode
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/admin-expert-mode/admin.cssHTML / DOM Fingerprints
Copyright (c) 2009-2021 by Scott Reilly (aka coffee2code)id="message" class="updated fade"for="admin_expert_mode"id="admin_expert_mode"name="admin_expert_mode"value="1"