Dashboard User profile Detais-(DUPD) Security & Risk Analysis

wordpress.org/plugins/dashboard-user-profile-detais-dupd

A smart, easy way to add Dashboard User Profile Widget to your Wordpress Site.

10 active installs v2.0 PHP + WP 3.8+ Updated Oct 1, 2019
dashboard-user-profile-detaisprofile-detaisprofile-widgetuserwp-admin-profile
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Dashboard User profile Detais-(DUPD) Safe to Use in 2026?

Generally Safe

Score 85/100

Dashboard User profile Detais-(DUPD) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The static analysis of the "dashboard-user-profile-detais-dupd" v2.0 plugin reveals a generally positive security posture, particularly concerning its limited attack surface and proper handling of SQL queries. The absence of AJAX handlers, REST API routes, shortcodes, cron events, and dangerous functions significantly reduces the potential for common exploitation vectors. Furthermore, all SQL queries observed utilize prepared statements, a crucial security best practice.

However, a significant concern arises from the complete lack of output escaping for all identified output points. This means that any data displayed by the plugin, if it originates from user input or external sources, is susceptible to cross-site scripting (XSS) attacks. While the plugin has a capability check, this alone does not mitigate XSS if the data is not properly escaped before rendering. The plugin also lacks nonce checks, which, while not directly flagged as a vulnerability in the provided data (as there are no AJAX handlers or similar entry points requiring them), is a standard security measure that is entirely absent.

Given the plugin's zero recorded vulnerabilities and CVEs, it suggests a history of secure development or limited exposure. However, this does not excuse the critical oversight in output escaping. The absence of any taint flow analysis results is also noteworthy, though this could indicate either the absence of such flows or limitations in the static analysis tool used. In conclusion, while the plugin demonstrates strengths in SQL handling and attack surface reduction, the critical failure in output escaping presents a significant XSS risk that requires immediate attention.

Key Concerns

  • All outputs are unescaped
  • No nonce checks implemented
Vulnerabilities
None known

Dashboard User profile Detais-(DUPD) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Dashboard User profile Detais-(DUPD) Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

Dashboard User profile Detais-(DUPD) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
23
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped23 total outputs
Attack Surface

Dashboard User profile Detais-(DUPD) Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_initindex.php:83
actionadmin_menuindex.php:84
actionwp_dashboard_setupindex.php:192
Maintenance & Trust

Dashboard User profile Detais-(DUPD) Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedOct 1, 2019
PHP min version
Downloads5K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Dashboard User profile Detais-(DUPD) Developer Profile

Mahamodul Hasan Khan

2 plugins · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Dashboard User profile Detais-(DUPD)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/dashboard-user-profile-detais-dupd/options.php

HTML / DOM Fingerprints

CSS Classes
dup-texttuner-namett_dts-type-switchtt_dts-active
Shortcode Output
<div id="dup"><div class="top-holder"><div class="image-holder"><p class="instruction"><a href="http://www.bdtunes.com/wp-admin/profile.php"<div class="name-status-holder"><p class="tuner-name"><table width="100%" border="0"> <tr> <td><strong><a href="post-new.php" class="button button-primary button-large">টিওন লিখুন</a></strong></td> <td></td> <td><strong><a href="upload.php" class="button insert-media add_media">সকল মিডিয়া</a></strong></td> </tr> <tr> <td><strong><a href="edit-comments.php" class="button"> সকল মন্তব্য</a></strong></td> <td></td> <td><strong><a href="media-new.php" class="button insert-media add_media">ছবি আপলোড</a></strong></td> </tr> <tr> <td><strong><a href="http://www.bdtunes.com" target="_blank" class="button"> সাইটে &nbsp;যান</a></strong></td> <td></td> <td><strong><a href="profile.php" class="button"> &nbsp;প্রোফাইল</a></strong></td> </tr> </table></a></div>
FAQ

Frequently Asked Questions about Dashboard User profile Detais-(DUPD)