
DX Dark Site Security & Risk Analysis
wordpress.org/plugins/devrix-dark-sitePlugin to use when something on the site is broken, not fully working, or worst case scenario - the whole site is down.
Is DX Dark Site Safe to Use in 2026?
Generally Safe
Score 91/100DX Dark Site has a strong security track record. Known vulnerabilities have been patched promptly.
The 'devrix-dark-site' v1.1.1 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of exposed AJAX handlers, REST API routes, shortcodes, and cron events with insufficient authentication significantly limits the plugin's attack surface. Furthermore, the code demonstrates good security practices by using prepared statements for all SQL queries, properly escaping all output, and not performing file operations or external HTTP requests. The presence of nonce checks and capability checks, while minimal, is also a positive indicator.
However, a single known CVE for this plugin, although currently unpatched, raises a significant concern. While the specific details of the CVE are not provided, the historical data indicates a past vulnerability of the Cross-Site Request Forgery (CSRF) type. This suggests a potential for vulnerabilities that could allow attackers to trick authenticated users into performing unwanted actions. The fact that there was a medium-severity vulnerability historically, even if none are currently active, warrants careful consideration and vigilance.
In conclusion, the plugin has strong technical implementations for preventing common web vulnerabilities. The primary weakness lies in its vulnerability history, specifically the existence of a past medium-severity CSRF vulnerability. Users should be aware of this history and ensure the plugin is kept up-to-date with any future patches released to address such issues. The minimal attack surface and robust coding practices are commendable, but the historical vulnerability necessitates a degree of caution.
Key Concerns
- One known CVE exists
- Past medium severity vulnerability
DX Dark Site Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
DX Dark Site <= 1.0.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting
DX Dark Site Code Analysis
Output Escaping
Data Flow Analysis
DX Dark Site Attack Surface
WordPress Hooks 7
Maintenance & Trust
DX Dark Site Maintenance & Trust
Maintenance Signals
Community Trust
DX Dark Site Alternatives
CookieYes – Cookie Banner for Cookie Consent (Easy to setup GDPR/CCPA Compliant Cookie Notice)
cookie-law-info
Easily set up cookie banner or notice in WordPress, and policy pages for compliance with global cookie laws (GDPR, DSGVO, RGPD, CCPA/CPRA, etc).
CookieAdmin – Cookie Consent Banner
cookieadmin
CookieAdmin provides easy to configure cookie consent banner with GDPR and CCPA law support.
Cookiebot by Usercentrics – Automatic Cookie Banner for GDPR/CCPA & Google Consent Mode
cookiebot
Install your cookie banner in minutes. Automatically scan and block cookies to comply with the GDPR, CCPA, Google Consent Mode v2. Free plan option.
Simple Banner – Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website
simple-banner
Display a simple banner/bar at the top or bottom of your website. Now with multi-banner support.
Announcer – Sticky Message Banner & Notification Bar
announcer
Add customizable WordPress notification bar to display announcements, promotions, coupons, or news at the top or bottom of your website.
DX Dark Site Developer Profile
12 plugins · 670 total installs
How We Detect DX Dark Site
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/devrix-dark-site/assets/css/dx-dark-site.cssdx-dark-site-internalHTML / DOM Fingerprints
darksite-noticedarksite-notice-containerdarksite-notice-imagedarksite-notice-contentdarksite-notice-buttonid="image_url"id="upload-btn"id="dx_darksite_note"SetDarksiteCookiedx_darksite_actiondx_darksite_nonce