
Dashboard Widgets Suite Security & Risk Analysis
wordpress.org/plugins/dashboard-widgets-suiteAdds 9 awesome widgets to your WP Dashboard. Includes User Notes, Social Buttons, System Info, Debug/Error Logs, and more!
Is Dashboard Widgets Suite Safe to Use in 2026?
Generally Safe
Score 98/100Dashboard Widgets Suite has a strong security track record. Known vulnerabilities have been patched promptly.
The "dashboard-widgets-suite" v3.5 plugin exhibits a mixed security posture. On the positive side, there are no reported unpatched CVEs, and the static analysis indicates a strong adherence to secure coding practices regarding SQL queries, which are all prepared. The plugin also implements a reasonable number of nonce and capability checks, suggesting an awareness of common WordPress security vulnerabilities. The absence of critical or high-severity taint flows is also reassuring.
However, a significant concern arises from the output escaping. With only 41% of outputs properly escaped, there's a substantial risk of Cross-Site Scripting (XSS) vulnerabilities, especially given the plugin's history of three medium-severity XSS CVEs. While the last known vulnerability was recently patched, this pattern indicates a recurring weakness in sanitizing user-supplied data before it's displayed. The presence of unsanitized paths in taint analysis, although not classified as critical or high, warrants attention as it could be a vector for other types of injection attacks.
In conclusion, while the plugin has a good track record of addressing vulnerabilities and employs secure practices for database interactions, the persistent issue with output escaping is a notable weakness. The historical prevalence of XSS vulnerabilities, even if currently patched, suggests that developers should prioritize rigorous output sanitization to mitigate future risks and improve the overall security posture.
Key Concerns
- Significant portion of outputs not properly escaped
- Taint analysis found unsanitized paths
- History of medium severity XSS vulnerabilities
Dashboard Widgets Suite Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Dashboard Widgets Suite <= 3.4.3 - Reflected Cross-Site Scripting
Dashboard Widgets Suite <= 3.4.1 - Authenticated (Administrator+) Stored Cross-Site Scripting
Dashboard Widgets Suite <= 3.2.1 - Authenticated (Administrator+) Stored Cross-Site Scripting
Dashboard Widgets Suite Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Dashboard Widgets Suite Attack Surface
Shortcodes 3
WordPress Hooks 23
Maintenance & Trust
Dashboard Widgets Suite Maintenance & Trust
Maintenance Signals
Community Trust
Dashboard Widgets Suite Alternatives
Simple Log Viewer
simple-log-viewer
A simple plugin to log errors in real time in a metabox in the admin panel, too integrated with WP-CLI
Dashboard Notepad
dashboard-notepad
The very simplest of notepads for your Dashboard.
Admin Users Logged In
admin-users-logged-in
Dashboard widget that shows admin users and when they were last logged in.
JS Error Logger
js-error-logger
Logs front-end javascript errors, and displays them in a dashboard widget
Dashboard Scratch Pad
dashboard-scratch-pad
A plugin that adds a scratch pad to your dashboard
Dashboard Widgets Suite Developer Profile
30 plugins · 1.2M total installs
How We Detect Dashboard Widgets Suite
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/dashboard-widgets-suite/css/dws-admin.css/wp-content/plugins/dashboard-widgets-suite/css/dws-frontend.css/wp-content/plugins/dashboard-widgets-suite/js/dws-admin.js/wp-content/plugins/dashboard-widgets-suite/js/dws-admin.jsdashboard-widgets-suite/css/dws-admin.css?ver=dashboard-widgets-suite/css/dws-frontend.css?ver=dashboard-widgets-suite/js/dws-admin.js?ver=HTML / DOM Fingerprints
dws-feed-boxdws-social-boxdws-user-notesdws-admin-notice<!-- Dashboard Widgets Suite --><!-- END Dashboard Widgets Suite -->data-dws-widget-iddata-dws-widget-typedws_admin_params[dws_feed_box][dws_social_box][dws_user_notes]