
Compact Admin Security & Risk Analysis
wordpress.org/plugins/compact-adminCompact Admin simply makes the posts and pages lists in the admin pages more compact.
Is Compact Admin Safe to Use in 2026?
Mostly Safe
Score 78/100Compact Admin is generally safe to use. 1 past CVE were resolved. Keep it updated.
The static analysis of the 'compact-admin' plugin v1.3.3 reveals a seemingly low attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events that lack authentication. The code signals indicate a positive adherence to secure SQL practices by exclusively using prepared statements and performing capability checks. However, a significant concern arises from the output escaping, where 100% of identified outputs are not properly escaped. This could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is reflected directly in the output without sanitization.
The vulnerability history is particularly concerning. The plugin has a known unpatched medium severity CVE, indicating a significant and persistent security risk. The common vulnerability type being Cross-Site Request Forgery (CSRF) suggests a pattern of insecure handling of user actions. While the current static analysis doesn't directly surface CSRF vectors, the historical data strongly implies a need for rigorous checks on all user-triggered actions. The overall security posture is mixed; while some fundamental security practices are present, the lack of output escaping and the presence of an unpatched CVE present substantial risks that outweigh the perceived low attack surface.
Key Concerns
- Unpatched CVE (Medium)
- 100% of outputs not properly escaped
Compact Admin Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Compact Admin <= 1.3.0 - Cross-Site Request Forgery
Compact Admin Code Analysis
Output Escaping
Compact Admin Attack Surface
WordPress Hooks 3
Maintenance & Trust
Compact Admin Maintenance & Trust
Maintenance Signals
Community Trust
Compact Admin Alternatives
LH Archived Post Status
lh-archived-post-status
Allows posts and pages to be archived so you can remove content from the main loop and feed without having to trash it.
Sortable Word Count Reloaded
sortable-word-count-reloaded
Adds a sortable column to the posts and pages admin list with the word count of each page/post.
Bulk Edit YOAST SEO fields in Spreadsheet
wp-sheet-editor-yoast-seo
Bulk Edit posts, pages, and WooCommerce products YOAST SEO fields using a spreadsheet.
Filter Admin Published Default
filter-admin-published-default
Enables all public post types (posts, pages, etc) in wp-admin to show the Published filter by default.
Post Descriptions
post-descriptions
A lightweight WordPress plugin that lets you add quick descriptions or personal notes to your posts and pages — perfect for reminders, to-do's, o …
Compact Admin Developer Profile
1 plugin · 80 total installs
How We Detect Compact Admin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/compact-admin/media/css/compact-admin.css/wp-content/plugins/compact-admin/media/js/compact-admin.js/wp-content/plugins/compact-admin/media/js/compact-admin.jscompact-admin/media/css/compact-admin.css?ver=compact-admin/media/js/compact-admin.js?ver=