
Dashboard Instruction Guide Security & Risk Analysis
wordpress.org/plugins/dashboard-instruction-guideThis is a simple plugin- Which will allow you to add instruction for the individual post types like- page, post etc.
Is Dashboard Instruction Guide Safe to Use in 2026?
Generally Safe
Score 85/100Dashboard Instruction Guide has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "dashboard-instruction-guide" plugin v1.0.0 presents a significant security risk primarily due to its unprotected AJAX endpoints. With 3 AJAX handlers identified, all lacking authentication checks, an unauthenticated attacker could potentially exploit these entry points to perform unauthorized actions or disrupt site functionality. The absence of nonce checks on these handlers further exacerbates this risk, making them vulnerable to CSRF attacks. While the plugin shows good practices in terms of avoiding dangerous functions, file operations, and external HTTP requests, and its output escaping is largely adequate, these strengths are overshadowed by the critical flaw in its AJAX security.
The static analysis did not reveal any critical or high-severity taint flows, which is a positive sign. Furthermore, the plugin has no known vulnerability history, suggesting it has not been a target for past exploits or has had a relatively clean security record. However, the complete lack of vulnerability history can also mean it hasn't been thoroughly scrutinized. The plugin's reliance on raw SQL queries without prepared statements is a concern, although the limited number of queries might mitigate the immediate risk. The overall security posture is weak due to the direct exposure of AJAX endpoints. While the absence of known vulnerabilities and a clean taint analysis are strengths, the fundamental security oversight in handling AJAX requests makes this plugin a high-risk candidate for immediate attention and remediation.
Key Concerns
- 3 AJAX handlers without authentication checks
- 0 Nonce checks on AJAX handlers
- 7 SQL queries, 0% using prepared statements
Dashboard Instruction Guide Security Vulnerabilities
Dashboard Instruction Guide Release Timeline
Dashboard Instruction Guide Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Dashboard Instruction Guide Attack Surface
AJAX Handlers 3
WordPress Hooks 4
Maintenance & Trust
Dashboard Instruction Guide Maintenance & Trust
Maintenance Signals
Community Trust
Dashboard Instruction Guide Alternatives
T4P Dashboard Notes
t4p-dashboard-notes
Add colored, formatted dashboard notes with titles and drag-and-drop widgets for internal admin documentation and reminders.
Dashboard Beacon
wp-dashboard-beacon
Easily integrate a Help Scout beacon in your site's dashboard.
MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy)
google-analytics-for-wordpress
The best free Google Analytics plugin for WordPress. See how visitors find and use your website so you can grow your business with powerful analytics.
Admin Menu Editor
admin-menu-editor
Lets you edit the WordPress admin menu. You can re-order, hide or rename menus, add custom menus and more.
ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin)
google-analytics-dashboard-for-wp
Connects Google Analytics with your WordPress site. Displays stats to help you understand your users and site content on a whole new level!
Dashboard Instruction Guide Developer Profile
4 plugins · 10 total installs
How We Detect Dashboard Instruction Guide
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/dashboard-instruction-guide/assets/js/backend-main.js/wp-content/plugins/dashboard-instruction-guide/assets/css/style.css/wp-content/plugins/dashboard-instruction-guide/assets/js/backend-main.jsdashboard-instruction-guide/assets/js/backend-main.js?ver=dashboard-instruction-guide/assets/css/style.css?ver=HTML / DOM Fingerprints
dig-popup-wrapper-outerdig-popup-innerpopup-titlepopup-contentclose-diginstruction-listdata-iddig_ajax_global