
Advanced Settings 3 Security & Risk Analysis
wordpress.org/plugins/advanced-settingsAdds settings that you might expect to find in the WordPress core.
Is Advanced Settings 3 Safe to Use in 2026?
Generally Safe
Score 96/100Advanced Settings 3 has a strong security track record. Known vulnerabilities have been patched promptly.
The "advanced-settings" v3.3.0 plugin exhibits a mixed security posture. While it demonstrates good practices by utilizing prepared statements for all SQL queries and having a substantial number of capability checks, significant concerns remain. The static analysis reveals a notable attack surface, with one AJAX handler lacking authentication checks, which is a direct entry point for potential unauthorized actions.
Furthermore, the plugin's vulnerability history is a serious red flag, with three known CVEs, including one high-severity and two medium-severity vulnerabilities. The common types of vulnerabilities, such as Unrestricted Upload of File with Dangerous Type and Cross-Site Request Forgery (CSRF), indicate recurring security weaknesses. The fact that the last vulnerability was as recent as September 2025 suggests a pattern of security issues that may not be fully addressed or reoccurring.
Overall, while the plugin shows some positive security implementations, the presence of an unprotected AJAX endpoint and a history of significant vulnerabilities necessitate caution. The potential for exploitation due to the unprotected entry point, combined with past occurrences of serious vulnerabilities, makes this plugin a moderate to high-risk component until these issues are thoroughly remediated and validated.
Key Concerns
- Unprotected AJAX handler
- History of 1 High Severity CVE
- History of 2 Medium Severity CVEs
- 57% of outputs properly escaped
Advanced Settings 3 Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Advanced Settings <= 3.1.1 - Authenticated (Author+) Arbitrary File Upload
Advanced Settings <= 3.1.1 - Cross-Site Request Forgery
Advanced Settings <= 3.0.1 - Cross-Site Request Forgery
Advanced Settings 3 Code Analysis
SQL Query Safety
Output Escaping
Advanced Settings 3 Attack Surface
AJAX Handlers 3
REST API Routes 3
WordPress Hooks 85
Maintenance & Trust
Advanced Settings 3 Maintenance & Trust
Maintenance Signals
Community Trust
Advanced Settings 3 Alternatives
Frontend Admin by DynamiApps
acf-frontend-form-element
This awesome plugin allows you to easily display frontend forms on your site so your clients can easily edit content by themselves from the frontend.
Multiple Admin Email Addresses
multiple-admin-email-addresses
Multiple Admin Email Addresses allows you to replace the blog's admin email with a comma separated list of admin emails
DevBrothers Admin Panel
devbrothers-admin-panel
Centralized admin panel for all DevBrothers plugins.
Adminimal
adminimal
A toolbar for WordPress front-end.
PZ Frontend Manager
pz-frontend-manager
PZ Frontend Manager allows your clients to manage their platform without accessing the wp-admin dashboard.
Advanced Settings 3 Developer Profile
5 plugins · 300 total installs
How We Detect Advanced Settings 3
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/advanced-settings/admin-ui/images/admin-bar-icon.svgHTML / DOM Fingerprints
advset-admin-iconAdmin UI functionality for Advanced Settings
*
* This file handles the admin bar icon and modal dialog for administratorsonclickadvset_open_modal/wp-json/advanced-settings/