Fabrica Dashboard Security & Risk Analysis

wordpress.org/plugins/fabrica-dashboard

Replaces the default Dashboard widgets to provide a much better overview of your site's content and activity as soon as you log in.

70 active installs v1.0.18 PHP 5.4+ WP 4.6+ Updated Jan 30, 2025
contentcustomdashboardeditorialworkflow
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Fabrica Dashboard Safe to Use in 2026?

Generally Safe

Score 92/100

Fabrica Dashboard has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "fabrica-dashboard" v1.0.18 plugin presents a significant security risk due to its large, unprotected attack surface. All 12 identified AJAX handlers lack authentication checks, meaning any authenticated user could potentially trigger these actions, leading to unauthorized operations. While the plugin demonstrates good practices in SQL query preparation and output escaping, the absence of nonces on AJAX actions is a critical oversight. This lack of protection against Cross-Site Request Forgery (CSRF) is a major concern. The plugin's vulnerability history is clean, with no recorded CVEs. This, combined with the well-handled SQL and output functions, suggests a potential for good coding practices in some areas. However, the current implementation of AJAX endpoints renders these strengths largely moot, as the fundamental security of these entry points is compromised.

Key Concerns

  • 12 AJAX handlers without auth checks
  • 0 Nonce checks
Vulnerabilities
None known

Fabrica Dashboard Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Fabrica Dashboard Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
110 prepared
Unescaped Output
8
310 escaped
Nonce Checks
0
Capability Checks
4
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

98% prepared112 total queries

Output Escaping

97% escaped318 total outputs
Data Flows
All sanitized

Data Flow Analysis

8 flows
<comments-activity> (inc\comments-activity.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
12 unprotected

Fabrica Dashboard Attack Surface

Entry Points12
Unprotected12

AJAX Handlers 12

authwp_ajax_fd-comments-activity-switchinc\comments-activity.php:16
authwp_ajax_fd-comments-activity-moreinc\comments-activity.php:17
authwp_ajax_fd-content-activity-filterinc\content-activity.php:16
authwp_ajax_fd-content-activity-moreinc\content-activity.php:17
authwp_ajax_fd-content-breakdowninc\content-breakdown.php:11
authwp_ajax_fd-media-breakdowninc\media-breakdown.php:11
authwp_ajax_fd-comments-activity-switchtrunk\inc\comments-activity.php:16
authwp_ajax_fd-comments-activity-moretrunk\inc\comments-activity.php:17
authwp_ajax_fd-content-activity-filtertrunk\inc\content-activity.php:16
authwp_ajax_fd-content-activity-moretrunk\inc\content-activity.php:17
authwp_ajax_fd-content-breakdowntrunk\inc\content-breakdown.php:11
authwp_ajax_fd-media-breakdowntrunk\inc\media-breakdown.php:11
WordPress Hooks 36
actionwp_dashboard_setupinc\comments-activity.php:15
actionadmin_initinc\common\base-common.php:29
actionadmin_enqueue_scriptsinc\common\base-common.php:30
actionwp_dashboard_setupinc\common\base-common.php:31
filteradmin_titleinc\common\base-common.php:32
filteresc_htmlinc\common\base-common.php:33
filtergettextinc\common\base-common.php:34
actionwp_logininc\common\logins-common.php:8
actionadmin_menuinc\common\settings-common.php:8
actionadmin_initinc\common\settings-common.php:9
actionwp_dashboard_setupinc\content-activity.php:15
actionwp_dashboard_setupinc\content-breakdown.php:10
actionwp_dashboard_setupinc\discussion-overview.php:10
actionwp_dashboard_setupinc\editorial-overview.php:10
actionwp_dashboard_setupinc\media-breakdown.php:10
filterpost_mime_typesinc\media-breakdown.php:12
actionwp_dashboard_setupinc\site.php:10
actionwp_dashboard_setupinc\you.php:10
actionwp_dashboard_setuptrunk\inc\comments-activity.php:15
actionadmin_inittrunk\inc\common\base-common.php:29
actionadmin_enqueue_scriptstrunk\inc\common\base-common.php:30
actionwp_dashboard_setuptrunk\inc\common\base-common.php:31
filteradmin_titletrunk\inc\common\base-common.php:32
filteresc_htmltrunk\inc\common\base-common.php:33
filtergettexttrunk\inc\common\base-common.php:34
actionwp_logintrunk\inc\common\logins-common.php:8
actionadmin_menutrunk\inc\common\settings-common.php:8
actionadmin_inittrunk\inc\common\settings-common.php:9
actionwp_dashboard_setuptrunk\inc\content-activity.php:15
actionwp_dashboard_setuptrunk\inc\content-breakdown.php:10
actionwp_dashboard_setuptrunk\inc\discussion-overview.php:10
actionwp_dashboard_setuptrunk\inc\editorial-overview.php:10
actionwp_dashboard_setuptrunk\inc\media-breakdown.php:10
filterpost_mime_typestrunk\inc\media-breakdown.php:12
actionwp_dashboard_setuptrunk\inc\site.php:10
actionwp_dashboard_setuptrunk\inc\you.php:10
Maintenance & Trust

Fabrica Dashboard Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedJan 30, 2025
PHP min version5.4
Downloads5K

Community Trust

Rating100/100
Number of ratings1
Active installs70
Developer Profile

Fabrica Dashboard Developer Profile

Yes We Work

3 plugins · 380 total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
12 days
View full developer profile
Detection Fingerprints

How We Detect Fabrica Dashboard

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/fabrica-dashboard/css/main.css/wp-content/plugins/fabrica-dashboard/js/main.js
Version Parameters
fabrica-dashboard/css/main.css?ver=fabrica-dashboard/js/main.js?ver=

HTML / DOM Fingerprints

CSS Classes
fd-dashboardfd-activity-overviewfd-content-breakdownfd-discussion-overviewfd-editorial-overviewfd-logins-overviewfd-media-breakdownfd-you-overview
Data Attributes
data-fd-current-userdata-fd-is-editordata-fd-is-moderatordata-fd-text-domaindata-fd-total-usersdata-fd-plugin-version
JS Globals
fdAjax
FAQ

Frequently Asked Questions about Fabrica Dashboard