
Dunstan-style Error Page Security & Risk Analysis
wordpress.org/plugins/dunstan-error-pageSee http://www.andrewferguson.net/wordpress-plugins/dunstan-style-error-page/ for the latest updates.
Is Dunstan-style Error Page Safe to Use in 2026?
Generally Safe
Score 85/100Dunstan-style Error Page has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'dunstan-error-page' v1.3.1 exhibits a mixed security posture. On the positive side, it boasts a very small attack surface with no reported AJAX handlers, REST API routes, shortcodes, or cron events, and importantly, no known CVEs in its history. All SQL queries are prepared, which is a strong security practice against SQL injection. However, significant concerns arise from the static analysis. The presence of the `unserialize` function is a critical risk, as it can lead to Remote Code Execution if used with untrusted input. Furthermore, a complete lack of output escaping is highly problematic, potentially exposing the site to Cross-Site Scripting (XSS) vulnerabilities through any data rendered on the page. The taint analysis revealing unsanitized paths, even without a critical or high severity classification, highlights potential avenues for exploitation if the plugin were to process user-supplied data in specific ways. The absence of nonce and capability checks, while not directly exploitable due to the limited attack surface, indicates a lack of fundamental security controls that would be essential if the attack surface were to expand in future versions.
Key Concerns
- Use of unserialize function
- No output escaping
- Unsanitized paths in taint analysis
- No nonce checks
- No capability checks
Dunstan-style Error Page Security Vulnerabilities
Dunstan-style Error Page Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Dunstan-style Error Page Attack Surface
WordPress Hooks 1
Maintenance & Trust
Dunstan-style Error Page Maintenance & Trust
Maintenance Signals
Community Trust
Dunstan-style Error Page Alternatives
Countdown Timer Ultimate
countdown-timer-ultimate
A quick, easy way to add and display responsive Countdown timer on your website. Also work with Gutenberg shortcode block.
Countdown Timer Block – Animated Countdown for Events or Launches
countdown-time
Display your event's date on a timer to your visitor with a countdown timer block
Countdown Timer
countdown-timer
This plugin allows you to setup a series of dates to count to or from in terms of years, months, weeks, days, hours, minutes, and/or seconds.
NS Countdown
ns-countdown
This plugin displays a countdown on a post.
Event Countdown for The Events Calendar
countdown-for-the-events-calendar
Event countdown timer addon for The Events Calendar plugin to display upcoming event countdowns anywhere using a simple shortcode.
Dunstan-style Error Page Developer Profile
7 plugins · 1K total installs
How We Detect Dunstan-style Error Page
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/dunstan-error-page/afdn-error-page.css/wp-content/plugins/dunstan-error-page/afdn-error-page.js/wp-content/plugins/dunstan-error-page/afdn-error-page.jsdunstan-error-page/afdn-error-page.css?ver=dunstan-error-page/afdn-error-page.js?ver=HTML / DOM Fingerprints
afdn-error-page-containerafdn-error-page-messageafdn-error-page-code<!-- Dunstan-style Error Page --><!-- End Dunstan-style Error Page -->data-error-messagedata-error-codeafdn_error_page_params<div class="afdn-error-page-message"><div class="afdn-error-page-code">