
Blocdash – Backend Dashboard Toolkit Security & Risk Analysis
wordpress.org/plugins/blocdash-backend-dashboard-toolkitBlocdash provides a modular frontend dashboard with announcements, login/register/profile forms, and optional Google login for block themes.
Is Blocdash – Backend Dashboard Toolkit Safe to Use in 2026?
Generally Safe
Score 100/100Blocdash – Backend Dashboard Toolkit has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "blocdash-backend-dashboard-toolkit" v1.0.1 plugin exhibits a generally good security posture based on the provided static analysis. A significant strength is the complete absence of critical or high-severity vulnerabilities in its history, suggesting a history of responsible development and patching. Furthermore, the static analysis reveals excellent practices like 100% of SQL queries using prepared statements and a high percentage (92%) of properly escaped output, minimizing risks of SQL injection and cross-site scripting (XSS) respectively. The presence of nonce checks on all AJAX handlers and capability checks on relevant entry points also indicates an awareness of common WordPress attack vectors.
However, there are a few areas that warrant attention. While the total number of entry points is relatively low, the presence of 3 unsanitized paths in the taint analysis is a potential concern. Although none of these flows were classified as critical or high severity, unsanitized paths can sometimes lead to unexpected behavior or can be chained with other minor issues to form a more significant vulnerability. Additionally, while not flagged as a vulnerability in this analysis, the plugin makes 3 external HTTP requests, which could become a risk if the external services are compromised or if the requests themselves are not handled securely, such as by not properly validating responses.
In conclusion, this plugin appears to be developed with security in mind, leveraging many best practices. The vulnerability history is a very strong indicator of this. The main areas for improvement would be to investigate and sanitize the identified unsanitized paths in the taint analysis and to ensure robust security measures are in place for all external HTTP requests. Overall, the risk is currently assessed as low, but these minor areas could be addressed to further strengthen its security.
Key Concerns
- Flows with unsanitized paths detected
- External HTTP requests made by the plugin
Blocdash – Backend Dashboard Toolkit Security Vulnerabilities
Blocdash – Backend Dashboard Toolkit Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Blocdash – Backend Dashboard Toolkit Attack Surface
AJAX Handlers 18
Shortcodes 6
WordPress Hooks 24
Scheduled Events 1
Maintenance & Trust
Blocdash – Backend Dashboard Toolkit Maintenance & Trust
Maintenance Signals
Community Trust
Blocdash – Backend Dashboard Toolkit Alternatives
Frontend Dashboard
frontend-dashboard
Frontend Dashboard is bundled with huge list of custom features which can easily customise the User profile, Posts, Login, Register, Custom roles.
Frontend Dashboard Captcha
frontend-dashboard-captcha
Frontend Dashboard Captcha WordPress plugin is a supportive plugin for Frontend Dashboard to protect against spam in Login and Register form.
Frontend Dashboard Notification
frontend-dashboard-notification
Frontend Dashboard Notification is an add-on for Frontend Dashboard WordPress plugin which allows user to show notification in Frontend Dashboard page …
Protect Ai Login
protect-ai-login
Change default login site to a custom URL, block spam, bot registration, and brute-force using Google reCAPTCHA.
Login Lockdown & Protection
login-lockdown
Protect, lockdown & secure login form by limiting login attempts from the same IP & banning IPs.
Blocdash – Backend Dashboard Toolkit Developer Profile
4 plugins · 0 total installs
How We Detect Blocdash – Backend Dashboard Toolkit
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/blocdash-backend-dashboard-toolkit/assets/css/admin-styles.css/wp-content/plugins/blocdash-backend-dashboard-toolkit/assets/js/admin-scripts.js/wp-content/plugins/blocdash-backend-dashboard-toolkit/assets/css/dashboard-styles.css/wp-content/plugins/blocdash-backend-dashboard-toolkit/assets/js/dashboard-scripts.js/wp-content/plugins/blocdash-backend-dashboard-toolkit/assets/css/forms-styles.css/wp-content/plugins/blocdash-backend-dashboard-toolkit/assets/js/forms-scripts.js/wp-content/plugins/blocdash-backend-dashboard-toolkit/assets/js/admin-scripts.js/wp-content/plugins/blocdash-backend-dashboard-toolkit/assets/js/dashboard-scripts.js/wp-content/plugins/blocdash-backend-dashboard-toolkit/assets/js/forms-scripts.jsblocdash-backend-dashboard-toolkit/assets/css/admin-styles.css?ver=blocdash-backend-dashboard-toolkit/assets/js/admin-scripts.js?ver=blocdash-backend-dashboard-toolkit/assets/css/dashboard-styles.css?ver=blocdash-backend-dashboard-toolkit/assets/js/dashboard-scripts.js?ver=blocdash-backend-dashboard-toolkit/assets/css/forms-styles.css?ver=blocdash-backend-dashboard-toolkit/assets/js/forms-scripts.js?ver=HTML / DOM Fingerprints
blocdash-loaderblocdash_ajaxblocdash_forms_ajax/wp-json/blocdash/v1/settings/wp-json/blocdash/v1/update-settings