
Dashboard Widgets Control Security & Risk Analysis
wordpress.org/plugins/dashboard-widgets-controlDisplays all registered dashboard widgets and enables to remove them individually for all or for selected roles (clients or other site contributors).
Is Dashboard Widgets Control Safe to Use in 2026?
Generally Safe
Score 100/100Dashboard Widgets Control has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'dashboard-widgets-control' v1.2.2.0 exhibits a generally good security posture based on the provided static analysis. The absence of any identified CVEs, along with a clean vulnerability history, suggests that the developers have a strong track record in addressing security concerns. Furthermore, the code signals are encouraging: there are no dangerous functions, all SQL queries use prepared statements, no file operations or external HTTP requests are made, and there are no taint flows indicating potential vulnerabilities.
However, there are areas for improvement. The low percentage of properly escaped output (16%) is a significant concern. This indicates that user-supplied data or dynamic content might be rendered directly to the browser without adequate sanitization, potentially leading to Cross-Site Scripting (XSS) vulnerabilities. While the plugin doesn't have a large attack surface of entry points, the lack of nonce checks and a low number of capability checks on the few identified entry points (even though static analysis shows 0 unprotected) could still pose risks if new entry points are introduced or if existing ones are not sufficiently protected.
In conclusion, the plugin is strong in its avoidance of known dangerous practices like raw SQL or dangerous functions. The lack of historical vulnerabilities is a positive sign. The primary weakness lies in the inadequate output escaping, which requires immediate attention to prevent potential XSS attacks. The limited attack surface and lack of critical taint flows are good, but the output escaping issue needs to be prioritized.
Key Concerns
- Low percentage of properly escaped output
- Lack of nonce checks on entry points
- Low number of capability checks
Dashboard Widgets Control Security Vulnerabilities
Dashboard Widgets Control Release Timeline
Dashboard Widgets Control Code Analysis
Output Escaping
Dashboard Widgets Control Attack Surface
WordPress Hooks 8
Maintenance & Trust
Dashboard Widgets Control Maintenance & Trust
Maintenance Signals
Community Trust
Dashboard Widgets Control Alternatives
Remove WP Dashboard Extra Widgets
wp-remove-dashboard-extra-widgets
Removes the WordPress dashboard widgets that are extra and useless for some users i.e. plugins, wp blog news etc
Disable Dashboard Widgets
disable-dashboard-widgets
Easily Remove All Widgets from Dashboard for all users except the Administrator.
Zen Dash
zen-dash
Disable dashboard widgets, menu items and update notifications. Declutter your dashboard with Feng Shui magic. Less is more.
Classic Editor +
classic-editor-addon
The "Classic Editor +" plugin disables the block editor, removes enqueued scripts/styles and brings back classic Widgets.
Disable WP Notification
disable-wp-notification
Best wordpress plugin to remove all the admin panel notifications in just one click. Including the theme and plugin update notification.
Dashboard Widgets Control Developer Profile
3 plugins · 30 total installs
How We Detect Dashboard Widgets Control
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/dashboard-widgets-control/styles/mfdwc.css/wp-content/plugins/dashboard-widgets-control/js/mfdwc_tooltips.js/wp-content/plugins/dashboard-widgets-control/js/mfdwc_tooltips.jsdashboard-widgets-control/styles/mfdwc.css?ver=dashboard-widgets-control/js/mfdwc_tooltips.js?ver=HTML / DOM Fingerprints
mf_dashboard_widgets_control_table<!-- The table can be moved horizontally on small screens -->data-widget-namedata-widget-contextdata-widget-rolemfdwc_hint