
Dashboard To-Do List Security & Risk Analysis
wordpress.org/plugins/dashboard-to-do-listA dashboard to-do list widget with the option to show the to-do list on the website. This is a great tool for web developers building a new website.
Is Dashboard To-Do List Safe to Use in 2026?
Generally Safe
Score 99/100Dashboard To-Do List has a strong security track record. Known vulnerabilities have been patched promptly.
The static analysis of the "dashboard-to-do-list" plugin v1.3.2 indicates a generally good security posture with no identified critical or high severity code signals, taint flows, or immediate attack vectors.
The code analysis shows strong adherence to secure coding practices, with 100% of SQL queries using prepared statements and a high percentage of output being properly escaped (83%). The presence of nonce and capability checks further strengthens its defenses against common web vulnerabilities. The limited attack surface, with zero identified entry points, is a positive sign. However, the taint analysis, while showing no critical or high severity unsanitized paths, only analyzed two flows, which might not be exhaustive.
The vulnerability history reveals two past medium severity CVEs, both related to Missing Authorization and Cross-Site Request Forgery (CSRF). The fact that none are currently unpatched is reassuring. The recurring nature of these vulnerability types suggests a potential recurring weakness in how user actions are authorized or protected against CSRF, even if current code has addressed past issues. The most recent vulnerability was quite recent, indicating ongoing vigilance is necessary. Overall, the plugin exhibits strengths in secure coding fundamentals but past incidents warrant continued careful review of authorization and CSRF prevention mechanisms.
Key Concerns
- Past medium severity CVEs (2)
- Potential recurring CSRF/Authorization issues
- Limited taint flow analysis scope
Dashboard To-Do List Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Dashboard To-Do List <= 1.2.0 - Missing Authorization via ardtdw_widgetsetup()
Dashboard To-Do List <= 1.3.1 - Cross-Site Request Forgery via ardtdw_widgetupdate()
Dashboard To-Do List Code Analysis
Output Escaping
Data Flow Analysis
Dashboard To-Do List Attack Surface
WordPress Hooks 5
Maintenance & Trust
Dashboard To-Do List Maintenance & Trust
Maintenance Signals
Community Trust
Dashboard To-Do List Alternatives
Sortable Dashboard To-Do List
sortable-dashboard-to-do-list
Adds a sortable to-do list widget to your WP dashboard. Useful for developers, content writers, and team tasks. Easily assign tasks to other users.
To Do List Member
todo-lists-for-membership-sites
To Do List Member adds todolists and tasks using custom taxonomy and post type to your blog.
ZE To Do List
ze-to-do-list
ZE To Do List.
Todo for BuddyPress & BuddyBoss
bp-user-to-do-list
Transform your BuddyPress or BuddyBoss community into a powerful task management platform. Members can create personal todos, collaborate on group tas …
Simple Todo List
simple-todo-list
The missing todo list dashboard widget for WordPress.
Dashboard To-Do List Developer Profile
1 plugin · 1K total installs
How We Detect Dashboard To-Do List
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/dashboard-to-do-list/admin/assets/widgets.css/wp-content/plugins/dashboard-to-do-list/public/assets/todo-widget.cssdashboard-to-do-list/public/assets/todo-widget.css?ver=dashboard-to-do-list/admin/assets/widgets.css?ver=HTML / DOM Fingerprints
ardtdw-messageardtdw-errorardtdw-updatedfield-commentardtdw-checkboxardtdw-checkbox-editorardtdw-checkbox-admineditorardtdw-textareaardtdw-positionardtdw-save+1 more