
Admin User Message Security & Risk Analysis
wordpress.org/plugins/admin-user-messageAdd message to users of your site. Choose wheter they can dismiss it or not.
Is Admin User Message Safe to Use in 2026?
Generally Safe
Score 85/100Admin User Message has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "admin-user-message" plugin v0.0.9 presents a generally positive security posture based on the provided static analysis. The plugin demonstrates good practices by utilizing prepared statements for all SQL queries and implementing a nonce check for its single AJAX handler, indicating an effort to prevent common web vulnerabilities. The absence of critical or high severity taint flows, along with no recorded vulnerabilities in its history, further reinforces this perception of a well-secured plugin.
However, there are areas for improvement. The plugin lacks capability checks on its AJAX handler, which could potentially allow any logged-in user, regardless of their role or permissions, to interact with this entry point. Additionally, 60% of output escaping is not ideal; while not a critical flaw on its own in this instance, it could become a vector for Cross-Site Scripting (XSS) if sensitive data were processed without proper sanitization. The presence of one file operation, while not inherently risky, warrants attention to ensure it's used securely and doesn't introduce unintended side effects or vulnerabilities.
In conclusion, the plugin is built with some strong security foundations, particularly in its database interactions and basic input validation. The primary concern lies in the lack of role-based access control for its administrative functionality. Addressing the output escaping and scrutinizing the file operation would further enhance its security, making it a more robust and trustworthy plugin.
Key Concerns
- Missing capability checks on AJAX handler
- Insufficient output escaping
Admin User Message Security Vulnerabilities
Admin User Message Code Analysis
Output Escaping
Admin User Message Attack Surface
AJAX Handlers 1
WordPress Hooks 6
Maintenance & Trust
Admin User Message Maintenance & Trust
Maintenance Signals
Community Trust
Admin User Message Alternatives
Hide Update Reminder Message
hide-update-reminder-message
Hides the Update Reminder in the Admin for all non Admin users.
Zedna Custom Dashboard Messages
custom-dashboard-messages
Allow admin to write messages on user dashboard.
Dashboard Message
dashboard-message-for-wordpress
Displays a custom message on the dashboard with full HTML/PHP/JavaScript support. Useful for administrator who have clients as users.
OCWS Admin Bar Greeting
ocws-admin-bar-greeting
This plugin enables the user to replace the ‘howdy’ greeting on the admin bar.
Post Updated Messages
post-updated-messages
Tailored updated messages for custom post types.
Admin User Message Developer Profile
5 plugins · 710 total installs
How We Detect Admin User Message
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/admin-user-message/admin-user-message.phpHTML / DOM Fingerprints
admin-user-messageadmin-user-message-update-nagname="admin_user_message_active"name="admin_user_message_type"name="admin_user_message_content"name="admin_user_message_exclude[]"name="admin_user_message_dismiss"name="admin_user_message_reset"/wp-json/admin-user-message/v1/dismiss