
Digitalsignagepress Lite Security & Risk Analysis
wordpress.org/plugins/digitalsignagepress-liteDigitalsignagepress lets you create, manage, and deliver messages and media to advertising displays.
Is Digitalsignagepress Lite Safe to Use in 2026?
Generally Safe
Score 85/100Digitalsignagepress Lite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The digital signage press lite plugin version 1.5.1 exhibits a concerning security posture primarily due to a significant number of unprotected AJAX handlers and vulnerabilities identified in taint analysis. While the plugin shows good practices like the extensive use of prepared statements for SQL queries and some capability checks, these are overshadowed by the broad attack surface exposed without authentication. The taint analysis revealing 15 high-severity flows with unsanitized paths is particularly alarming, indicating a strong likelihood of exploitable vulnerabilities that could lead to arbitrary file operations or other malicious actions.
The plugin's vulnerability history being clear of any known CVEs might suggest a lack of historical exploitation or disclosure. However, this does not negate the inherent risks identified in the static code analysis. The presence of the `move_uploaded_file` function, a known source of potential vulnerabilities when not handled with extreme care, further amplifies these concerns. The low percentage of properly escaped output also contributes to potential cross-site scripting (XSS) risks.
In conclusion, while the plugin demonstrates some positive security implementations, the high number of unprotected entry points and critical taint analysis findings present a significant risk. The lack of historical CVEs should not be interpreted as a guarantee of security, especially given the identified code-level weaknesses. Immediate attention is required to address the unprotected AJAX handlers and the identified taint flow vulnerabilities.
Key Concerns
- 14 unprotected AJAX handlers
- 15 high-severity unsanitized taint flows
- 1 dangerous function (move_uploaded_file)
- Low percentage of properly escaped output
- Bundled outdated jQuery library
Digitalsignagepress Lite Security Vulnerabilities
Digitalsignagepress Lite Release Timeline
Digitalsignagepress Lite Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Digitalsignagepress Lite Attack Surface
AJAX Handlers 14
Shortcodes 1
WordPress Hooks 32
Maintenance & Trust
Digitalsignagepress Lite Maintenance & Trust
Maintenance Signals
Community Trust
Digitalsignagepress Lite Alternatives
Foyer – Digital Signage for WordPress
foyer
A free Digital Signage plugin for WordPress. Create and show off slideshows on your networked displays.
WPScreens
wpscreens
The friendliest free digital signage system for WordPress, enabling easy screen management for shops, waiting rooms, and more.
Digital Signage
digital-signage
Create a dedicated digital signage display that automatically rotates through images from your WordPress posts.
ScreenCloud
screencloud
Push content from WordPress to your screens seamlessly with ScreenCloud, auto-transforming data into designs for digital signage.
Popup Ads Management
popup-ads-management
Popup Ads Management plugin helps you to save your advertisement script category wise and let them show to specifica category post and category page.
Digitalsignagepress Lite Developer Profile
1 plugin · 30 total installs
How We Detect Digitalsignagepress Lite
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/digitalsignagepress-lite/icons/icon.png/wp-content/plugins/digitalsignagepress-lite/css/dsplite_style.css/wp-content/plugins/digitalsignagepress-lite/css/dsplite_responsive.css/wp-content/plugins/digitalsignagepress-lite/css/dsplite_dashboard.css/wp-content/plugins/digitalsignagepress-lite/js/dsplite_admin.js/wp-content/plugins/digitalsignagepress-lite/js/dsplite_settings.js/wp-content/plugins/digitalsignagepress-lite/js/dsplite_admin_functions.js/wp-content/plugins/digitalsignagepress-lite/js/dsplite_common.jswp-content/plugins/digitalsignagepress-lite/js/dsplite_admin.jswp-content/plugins/digitalsignagepress-lite/js/dsplite_settings.jswp-content/plugins/digitalsignagepress-lite/js/dsplite_admin_functions.jswp-content/plugins/digitalsignagepress-lite/js/dsplite_common.jsdigitalsignagepress-lite/css/dsplite_style.css?ver=digitalsignagepress-lite/css/dsplite_responsive.css?ver=digitalsignagepress-lite/css/dsplite_dashboard.css?ver=digitalsignagepress-lite/js/dsplite_admin.js?ver=digitalsignagepress-lite/js/dsplite_settings.js?ver=digitalsignagepress-lite/js/dsplite_admin_functions.js?ver=digitalsignagepress-lite/js/dsplite_common.js?ver=HTML / DOM Fingerprints
dsplite_wrapperdsplite_admin_wrapperdsplite_settings_formdsplite_program_listdsplite_device_list<!-- Digitalsignagepress Lite Admin --><!-- Digitalsignagepress Lite Settings Form --><!-- Digitalsignagepress Lite Program List --><!-- Digitalsignagepress Lite Device List -->data-dsplite-playlist-iddata-dsplite-device-iddsplite_varsDSPLITE_SIGNAGE_PLUGIN_NAMEDSPLITE_SIGNAGE_PLUGIN_DIRDSPLITE_SIGNAGE_PLUGIN_DIR_PATHDSPLITE_SIGNAGE_PLUGIN_MENU_SLUGDSPLITE_BLANK_THEME+2 more