Simple Dashboard Todo Security & Risk Analysis

wordpress.org/plugins/dash-todo

A simple todo management plugin for WordPress site admins. Stay consistent and never forget anything.

100 active installs v1.1.5 PHP 7.4+ WP 6.0+ Updated Jun 10, 2024
dashboardproductivitytodoutilitywidget
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Simple Dashboard Todo Safe to Use in 2026?

Generally Safe

Score 92/100

Simple Dashboard Todo has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The static analysis of dash-todo v1.1.5 reveals an exceptionally clean codebase with no identified dangerous functions, raw SQL queries, unescaped output, file operations, external HTTP requests, or critical taint flows. The absence of AJAX handlers, REST API routes, shortcodes, and cron events means there are virtually no direct entry points into the plugin for attackers to exploit. The plugin also has no recorded vulnerability history, which is a strong indicator of its security maturity over time. This plugin exhibits excellent security practices by not exposing dangerous functions and by adhering to secure coding standards where functionality does exist. However, the complete lack of entry points also means there is no evidence of how authentication and authorization are handled when features *are* present, which could be a potential blind spot. While the current state is highly reassuring, further scrutiny of the plugin's actual functionality and user interactions would be beneficial to confirm the absence of any indirect attack vectors.

Vulnerabilities
None known

Simple Dashboard Todo Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Simple Dashboard Todo Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Simple Dashboard Todo Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actioninitdash-todo.php:56
actionadmin_menudash-todo.php:57
actionwp_dashboard_setupdash-todo.php:58
actionadmin_enqueue_scriptsdash-todo.php:59
filteradmin_footer_textdash-todo.php:106
actionadmin_enqueue_scriptsdash-todo.php:107
filteradmin_body_classdash-todo.php:108
Maintenance & Trust

Simple Dashboard Todo Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedJun 10, 2024
PHP min version7.4
Downloads6K

Community Trust

Rating100/100
Number of ratings5
Active installs100
Developer Profile

Simple Dashboard Todo Developer Profile

Sharif ME

2 plugins · 100 total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Simple Dashboard Todo

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/dash-todo/build/index.js/wp-content/plugins/dash-todo/build/index.css
Script Paths
/wp-content/plugins/dash-todo/build/index.js
Version Parameters
dash-todo/build/index.js?ver=dash-todo/build/index.css?ver=

HTML / DOM Fingerprints

CSS Classes
dash-todo
REST Endpoints
/wp-json/wp/v2/todo
Shortcode Output
<div id="TodoApp"></div>
FAQ

Frequently Asked Questions about Simple Dashboard Todo