CMS admin area Security & Risk Analysis

wordpress.org/plugins/cms-admin-area

Useful and easy way to customize your WordPress admin area and the login page.

10 active installs v1.1 PHP + WP 3.2+ Updated Jun 24, 2013
admin-panelcmsdashboardmanagementmetaboxes
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is CMS admin area Safe to Use in 2026?

Generally Safe

Score 85/100

CMS admin area has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The 'cms-admin-area' plugin v1.1 exhibits a mixed security posture. On one hand, the absence of known vulnerabilities (CVEs) and the use of prepared statements for all SQL queries are strong positive indicators of good development practices. The plugin also demonstrates awareness of entry points by having zero unprotected AJAX handlers, REST API routes, shortcodes, or cron events, which significantly limits the potential attack surface. However, several critical concerns arise from the static analysis. The presence of four instances of the deprecated `create_function` is a significant security risk, as this function can be exploited for code injection vulnerabilities if not handled with extreme care and sanitization, which is not apparent here. Furthermore, the complete lack of output escaping on all 38 identified outputs is a major vulnerability, leaving the plugin highly susceptible to Cross-Site Scripting (XSS) attacks. The limited capability checks also raise concerns about authorization for the plugin's functions.

While the plugin has no recorded vulnerability history, this does not guarantee its current safety. The static analysis reveals critical weaknesses, particularly the unescaped output and the use of `create_function`, which represent immediate threats. The lack of taint analysis data also means potential flow-based vulnerabilities might not have been identified. In conclusion, despite the positive aspects like zero SQL injection risks and a controlled entry point surface, the severe issues with XSS and the use of a dangerous function create a substantial security risk that requires immediate attention and remediation.

Key Concerns

  • Use of dangerous create_function
  • 100% of outputs not properly escaped
  • Only 2 capability checks found
Vulnerabilities
None known

CMS admin area Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

CMS admin area Code Analysis

Dangerous Functions
4
Raw SQL Queries
0
0 prepared
Unescaped Output
38
0 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

create_functionadd_action( 'plugins_loaded', create_function( '', '$admin_area_class = new Admin_Area_Class;' ) );adminarea.php:21
create_functionadd_filter( 'site_transient_update_core', create_function( '$a', "return null;" ) );classes\admin_area_class.php:286
create_functionadd_filter( 'site_transient_update_plugins', create_function( '$a', "return null;" ) );classes\admin_area_class.php:290
create_functionadd_filter( 'site_transient_update_themes', create_function( '$a', "return null;" ) );classes\admin_area_class.php:293

Output Escaping

0% escaped38 total outputs
Attack Surface

CMS admin area Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 24
actioninitadminarea.php:18
actionplugins_loadedadminarea.php:21
actionadmin_enqueue_scriptsclasses\admin_area_class.php:60
actionadmin_print_stylesclasses\admin_area_class.php:61
actionlogin_headclasses\admin_area_class.php:62
filterlogin_headertitleclasses\admin_area_class.php:68
filterlogin_headerurlclasses\admin_area_class.php:69
actionadmin_menuclasses\admin_area_class.php:74
actionadmin_initclasses\admin_area_class.php:80
actionadmin_initclasses\admin_area_class.php:81
actionadmin_initclasses\admin_area_class.php:82
actioninitclasses\admin_area_class.php:85
actioninitclasses\admin_area_class.php:86
actionwp_before_admin_bar_renderclasses\admin_area_class.php:89
actionwp_dashboard_setupclasses\admin_area_class.php:90
actionwp_dashboard_setupclasses\admin_area_class.php:91
filteradmin_footer_textclasses\admin_area_class.php:228
filterthe_generatorclasses\admin_area_class.php:266
filterupdate_footerclasses\admin_area_class.php:285
filtersite_transient_update_coreclasses\admin_area_class.php:286
filtersite_transient_update_pluginsclasses\admin_area_class.php:290
filtersite_transient_update_themesclasses\admin_area_class.php:293
filterscreen_options_show_screenclasses\admin_area_class.php:301
actionadmin_headclasses\admin_area_class.php:305
Maintenance & Trust

CMS admin area Maintenance & Trust

Maintenance Signals

WordPress version tested3.6.1
Last updatedJun 24, 2013
PHP min version
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

CMS admin area Developer Profile

netbiel

3 plugins · 310 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect CMS admin area

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cms-admin-area/assets/cms_admin_area.js/wp-content/plugins/cms-admin-area/assets/common.js/wp-content/plugins/cms-admin-area/assets/cms_admin_area.css/wp-content/plugins/cms-admin-area/assets/cms_admin_area_legacy.css/wp-content/plugins/cms-admin-area/assets/main.css
Script Paths
/wp-content/plugins/cms-admin-area/assets/cms_admin_area.js/wp-content/plugins/cms-admin-area/assets/common.js
Version Parameters
cms-admin-area/assets/cms_admin_area.js?ver=cms-admin-area/assets/common.js?ver=cms-admin-area/assets/cms_admin_area.css?ver=cms-admin-area/assets/cms_admin_area_legacy.css?ver=cms-admin-area/assets/main.css?ver=

HTML / DOM Fingerprints

JS Globals
cms_admin_area_common
FAQ

Frequently Asked Questions about CMS admin area