
WP Frontend Admin – Display WP Admin Pages in the Frontend Security & Risk Analysis
wordpress.org/plugins/display-admin-page-on-frontendShow Gutenberg Editor in the Frontend. Display WP Admin Pages in the Frontend. Create custom dashboards in the front end, Allow to Edit in the Fronten …
Is WP Frontend Admin – Display WP Admin Pages in the Frontend Safe to Use in 2026?
Generally Safe
Score 99/100WP Frontend Admin – Display WP Admin Pages in the Frontend has a strong security track record. Known vulnerabilities have been patched promptly.
The "display-admin-page-on-frontend" plugin v1.22.8 exhibits a generally good security posture, with a robust implementation of WordPress security best practices. The absence of unprotected entry points and a significant majority of SQL queries utilizing prepared statements are positive indicators. Furthermore, the high percentage of properly escaped output and the presence of numerous capability and nonce checks suggest a deliberate effort to secure the plugin against common web vulnerabilities.
However, the static analysis does reveal some areas for concern. The taint analysis shows four high-severity flows with unsanitized paths, indicating potential vulnerabilities where user-supplied data might not be sufficiently validated or escaped before being used in a sensitive operation. While the plugin has a history of one medium severity CVE related to Cross-site Scripting, the fact that it's listed with a future date (2025-09-22) suggests either this is a known upcoming vulnerability or a reporting anomaly; regardless, past XSS vulnerabilities warrant continued vigilance.
In conclusion, the plugin demonstrates strong foundational security. The primary risks lie within the identified high-severity taint flows, which need thorough investigation and remediation. The past CVE, though medium, highlights the importance of ongoing security reviews and diligent patching for any future vulnerabilities. The plugin's strengths in authentication and escaping are commendable, but the taint analysis findings prevent a perfect score and require attention.
Key Concerns
- High severity taint flows with unsanitized paths
- Past medium severity CVE (XSS)
- File operations detected
- External HTTP requests detected
- Bundled library (Freemius v1.0)
WP Frontend Admin – Display WP Admin Pages in the Frontend Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WP Frontend Admin <= 1.22.7 - Authenticated (Contributor+) Stored Cross-Site Scripting
WP Frontend Admin – Display WP Admin Pages in the Frontend Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Frontend Admin – Display WP Admin Pages in the Frontend Attack Surface
AJAX Handlers 1
Shortcodes 7
WordPress Hooks 76
Scheduled Events 1
Maintenance & Trust
WP Frontend Admin – Display WP Admin Pages in the Frontend Maintenance & Trust
Maintenance Signals
Community Trust
WP Frontend Admin – Display WP Admin Pages in the Frontend Alternatives
Rimplates
rimplates
Rimplates is a dashboard maker for wordpress. Using this Plugin is simple, install it, Rimplates will appear on your admin dashboard menu (with abilit …
Ultimate Dashboard – Custom WordPress Dashboard
ultimate-dashboard
The #1 Plugin to Customize the WordPress Dashboard!
AGCA – Custom Dashboard & Login Page
ag-custom-admin
CHANGE: admin menu, login page, admin bar, dashboard widgets, custom colors, custom CSS & JS, logo & images
Branda – White Label & Branding, Free Login Page Customizer
branda-white-labeling
White label & rebrand your login page & WordPress dashboard. Customize system emails & get everything to rebrand WordPress with Branda.
Frontend Admin by DynamiApps
acf-frontend-form-element
This awesome plugin allows you to easily display frontend forms on your site so your clients can easily edit content by themselves from the frontend.
WP Frontend Admin – Display WP Admin Pages in the Frontend Developer Profile
20 plugins · 30K total installs
How We Detect WP Frontend Admin – Display WP Admin Pages in the Frontend
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/display-admin-page-on-frontend/assets/css/backend.css/wp-content/plugins/display-admin-page-on-frontend/assets/css/frontend.css/wp-content/plugins/display-admin-page-on-frontend/assets/css/style.css/wp-content/plugins/display-admin-page-on-frontend/assets/js/backend.js/wp-content/plugins/display-admin-page-on-frontend/assets/js/frontend.js/wp-content/plugins/display-admin-page-on-frontend/assets/js/vg-admin-to-frontend.js/wp-content/plugins/display-admin-page-on-frontend/assets/js/backend.js/wp-content/plugins/display-admin-page-on-frontend/assets/js/frontend.js/wp-content/plugins/display-admin-page-on-frontend/assets/js/vg-admin-to-frontend.jsdisplay-admin-page-on-frontend/assets/css/backend.css?ver=display-admin-page-on-frontend/assets/css/frontend.css?ver=display-admin-page-on-frontend/assets/css/style.css?ver=display-admin-page-on-frontend/assets/js/backend.js?ver=display-admin-page-on-frontend/assets/js/frontend.js?ver=display-admin-page-on-frontend/assets/js/vg-admin-to-frontend.js?ver=HTML / DOM Fingerprints
vgfa-admin-pagevgfa-login-pagevgfa-register-pagevgfa-lost-password-pagevgfa-admin-menu-itemvgfa-admin-bar-nodevgfa-post-editor<!-- VG_Admin_To_Frontend Start --><!-- VG_Admin_To_Frontend End -->data-vgfa-post-iddata-vgfa-post-typedata-vgfa-current-screendata-vgfa-current-post-typeVG_Admin_To_Frontend_Objvgfa_global_vars/wp-json/vgfa/v1/get_user_permissions/wp-json/vgfa/v1/get_post_permissions/wp-json/vgfa/v1/save_post[vg_display_admin_page][vg_display_admin_login][vg_display_admin_register][vg_display_admin_lost_password]