Admin Tools Security & Risk Analysis

wordpress.org/plugins/admin-tools

Admin Tools Helps you to get better admin for your customers. Manage your menus, plugins, Top Bar, updates and more

4K active installs v1.3.9 PHP + WP 4.2+ Updated Sep 30, 2021
adminadmin-toolscustomizehide-admin-menuhide-admin-menus
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Admin Tools Safe to Use in 2026?

Generally Safe

Score 85/100

Admin Tools has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The "admin-tools" plugin v1.3.9 demonstrates a generally strong security posture, with no identified vulnerabilities in its history and a lack of critical signals in the static analysis. The absence of known CVEs and the plugin's clean vulnerability history suggest a history of responsible development and maintenance. Furthermore, the static analysis reveals no dangerous functions, SQL queries are exclusively using prepared statements, and there are no file operations or external HTTP requests, all of which are positive indicators. The total absence of entry points like AJAX handlers, REST API routes, shortcodes, and cron events also significantly reduces the plugin's attack surface. However, a notable concern is the output escaping, with 67% properly escaped. While not critical, this still leaves a significant portion of output potentially vulnerable to cross-site scripting (XSS) if user-supplied data is directly reflected without adequate sanitization in the unescaped portions. The lack of any nonces or capability checks, combined with zero unprotected entry points, is contradictory and warrants further investigation. If there are indeed zero entry points, then these checks are naturally absent. However, if there are entry points that were not detected by the static analysis, their absence would be a significant concern.

Key Concerns

  • Significant portion of output not properly escaped
Vulnerabilities
None known

Admin Tools Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Admin Tools Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

Admin Tools Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
47
96 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

67% escaped143 total outputs
Attack Surface

Admin Tools Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 35
actionadmin_menuadmin-tools.php:36
actionadmin_initadmin-tools.php:37
actionadmin_enqueue_scriptsadmin-tools.php:38
actionplugins_loadedadmin-tools.php:39
actionpre_user_queryadmin-tools.php:40
actionpre_current_active_pluginsadmin-tools.php:41
actionadmin_menuadmin-tools.php:42
actionpre_current_active_pluginsadmin-tools.php:43
actionlogin_enqueue_scriptsadmin-tools.php:44
actioninitadmin-tools.php:45
actionadmin_enqueue_scriptsadmin-tools.php:46
actionwp_enqueue_scriptsadmin-tools.php:47
actionwp_before_admin_bar_renderadmin-tools.php:48
actionadmin_bar_menuadmin-tools.php:49
actionadmin_bar_menuadmin-tools.php:50
actionadmin_headadmin-tools.php:51
actionadmin_initadmin-tools.php:52
actionadmin_menuadmin-tools.php:53
filterallow_dev_auto_core_updatesadmin-tools.php:56
filterallow_minor_auto_core_updatesadmin-tools.php:59
filterallow_major_auto_core_updatesadmin-tools.php:62
filterauto_update_translationadmin-tools.php:65
filterauto_core_update_send_emailadmin-tools.php:68
filterauto_update_pluginadmin-tools.php:70
filterviews_usersadmin-tools.php:558
filterviews_pluginsadmin-tools.php:708
filterviews_pluginsadmin-tools.php:735
filtershow_admin_baradmin-tools.php:846
filtershow_admin_baradmin-tools.php:849
filterpre_site_transient_update_coreadmin-tools.php:986
filterpre_site_transient_update_coreadmin-tools.php:990
filterpre_site_transient_update_pluginsadmin-tools.php:996
filterpre_site_transient_update_pluginsadmin-tools.php:1000
filterpre_site_transient_update_themesadmin-tools.php:1006
filterpre_site_transient_update_themesadmin-tools.php:1010
Maintenance & Trust

Admin Tools Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedSep 30, 2021
PHP min version
Downloads41K

Community Trust

Rating94/100
Number of ratings11
Active installs4K
Developer Profile

Admin Tools Developer Profile

Yehi

2 plugins · 4K total installs

92
trust score
Avg Security Score
88/100
Avg Patch Time
5 days
View full developer profile
Detection Fingerprints

How We Detect Admin Tools

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/admin-tools/css/ycat.css/wp-content/plugins/admin-tools/js/ycat.js
Script Paths
/wp-content/plugins/admin-tools/js/ycat.js
Version Parameters
admin-tools/css/ycat.css?ver=admin-tools/js/ycat.js?ver=

HTML / DOM Fingerprints

CSS Classes
ycat-settingstabtablinkstabcontent
Data Attributes
data-tab
JS Globals
ycat
FAQ

Frequently Asked Questions about Admin Tools