
Zedna Custom Dashboard Messages Security & Risk Analysis
wordpress.org/plugins/custom-dashboard-messagesAllow admin to write messages on user dashboard.
Is Zedna Custom Dashboard Messages Safe to Use in 2026?
Generally Safe
Score 85/100Zedna Custom Dashboard Messages has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "custom-dashboard-messages" v2.2.2 plugin exhibits a generally positive security posture based on the provided static analysis. Notably, it has a zero attack surface with no AJAX handlers, REST API routes, shortcodes, or cron events that are exposed and unprotected. The code also demonstrates good practices by utilizing prepared statements for all SQL queries and avoiding file operations or external HTTP requests, which are common vectors for vulnerabilities. The absence of known CVEs and a clean vulnerability history further contribute to this positive assessment, suggesting a well-maintained and secure plugin over time.
However, a significant concern arises from the output escaping. With 15 total outputs and only 40% properly escaped, there's a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. Unsanitized user input that is later displayed to other users without proper encoding can be exploited to inject malicious scripts, potentially leading to account takeovers or data theft. Additionally, the complete absence of nonce checks and a low number of capability checks (though no unprotected entry points were found) might indicate a lack of defense-in-depth, relying solely on the absence of direct entry points rather than validating user intent and permissions within any potential future or less obvious interaction points.
In conclusion, while the plugin scores well on attack surface and SQL security, the low percentage of properly escaped output presents a tangible and potentially severe risk. The lack of any recorded vulnerabilities in its history is a strength, but this should not overshadow the identified output escaping deficiency. Prioritizing the remediation of unescaped output is crucial for mitigating XSS risks.
Key Concerns
- Low percentage of properly escaped output
- No nonce checks implemented
Zedna Custom Dashboard Messages Security Vulnerabilities
Zedna Custom Dashboard Messages Code Analysis
Output Escaping
Zedna Custom Dashboard Messages Attack Surface
WordPress Hooks 15
Maintenance & Trust
Zedna Custom Dashboard Messages Maintenance & Trust
Maintenance Signals
Community Trust
Zedna Custom Dashboard Messages Alternatives
Simple Membership Custom Messages
simple-membership-custom-messages
Simple Membership Addon to customize various content protection messages.
WP Custom Admin Bar
wp-custom-admin-bar
A really simple and easy to use plugin to help gain control of the new Admin Bar.
Send FCM notifications
ss-fcm-notifications
Send notifications to all your Android app user without paying fees as it does not use third-party servers.
Edit Profile Fields
edit-profile-fields
Create, show, hide and delete custom contact info fields on your users profiles.
Post Updated Messages
post-updated-messages
Tailored updated messages for custom post types.
Zedna Custom Dashboard Messages Developer Profile
15 plugins · 570 total installs
How We Detect Zedna Custom Dashboard Messages
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/custom-dashboard-messages/style.csscustom-dashboard-messages/style.css?ver=HTML / DOM Fingerprints
dashboard-message1name='cd_min_role_to_see'value='manage_options'value='publish_pages'value='publish_posts'value='read'value='all'