
Dashi Security & Risk Analysis
wordpress.org/plugins/dashiUseful classes for creating a custom post type. Creates Page Parts custom post type. Designed for theme developers.
Is Dashi Safe to Use in 2026?
Generally Safe
Score 99/100Dashi has a strong security track record. Known vulnerabilities have been patched promptly.
The 'dashi' v3.4.6 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by extensively using prepared statements for SQL queries and implementing nonce checks. The absence of dangerous functions, critical/high taint flows, and unpatched CVEs are also strengths. However, a significant concern lies in its attack surface, specifically one AJAX handler lacking authorization checks. While the taint analysis found no unsanitized paths, the presence of unauthenticated entry points always poses a risk. The vulnerability history indicates a past medium-severity issue, likely related to missing authorization, which aligns with the current static analysis finding. While the plugin has addressed past vulnerabilities and shows good internal code practices, the identified unprotected AJAX endpoint warrants attention.
Key Concerns
- Unprotected AJAX handler
- Medium severity vulnerability history (Missing Authorization)
- Moderate output escaping (68% properly escaped)
Dashi Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Dashi <= 3.1.8 - Missing Authorization
Dashi Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Dashi Attack Surface
AJAX Handlers 3
Shortcodes 4
WordPress Hooks 100
Scheduled Events 3
Maintenance & Trust
Dashi Maintenance & Trust
Maintenance Signals
Community Trust
Dashi Alternatives
Meta Box
meta-box
Meta Box plugin is a powerful, professional developer toolkit to create custom meta boxes and custom fields for your custom post types in WordPress.
Pods – Custom Content Types and Fields
pods
Pods is a framework for creating, managing, and deploying customized content types and fields for any project.
Sydney Toolbox
sydney-toolbox
Registers custom post types and custom fields for the Sydney theme
Custom Post Types and Custom Fields creator – WCK
wck-custom-fields-and-custom-post-types-creator
A must have tool for creating custom fields, custom post types and taxonomies, fast and without any programming knowledge.
CubeWP Framework
cubewp-framework
CubeWP is an end-to-end dynamic content framework for WordPress to help you shrink time and cut cost of development up to 90%.
Dashi Developer Profile
5 plugins · 210 total installs
How We Detect Dashi
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/dashi/js/jquery.jscroll-master/jquery.jscroll.min.js/wp-content/plugins/dashi/js/dashi.jsHTML / DOM Fingerprints
dashi-options-pagedashi-admin-body-classdashi-tabledata-dashi-iddashi_ajaxurl[loggedin]