
Frontend Dashboard Pages Security & Risk Analysis
wordpress.org/plugins/frontend-dashboard-pagesFrontend Dashboard Pages is a plugin to show pages inside the Frontend Dashboard menu. The assigning page may contain content, images and even shortco …
Is Frontend Dashboard Pages Safe to Use in 2026?
Generally Safe
Score 85/100Frontend Dashboard Pages has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The frontend-dashboard-pages plugin v1.5.5 exhibits several significant security concerns, primarily stemming from its unprotected entry points and lack of proper security checks. With two AJAX handlers identified and neither protected by authentication or capability checks, there's a substantial risk of unauthorized actions being performed if an attacker can trigger these handlers. Additionally, the presence of the `unserialize` function, a known vector for remote code execution if used with untrusted input, further elevates the risk, especially in conjunction with the unprotected AJAX endpoints. The complete absence of nonce checks on these entry points makes them vulnerable to Cross-Site Request Forgery (CSRF) attacks. While the plugin has no recorded vulnerability history, this is not indicative of inherent security, but rather a lack of past public exploits or discoveries for this specific version and configuration. The extremely low percentage of properly escaped output is another critical weakness, opening the door for Cross-Site Scripting (XSS) vulnerabilities.
In summary, the plugin's overall security posture is poor due to multiple critical vulnerabilities in its handling of user input and access control. The lack of authentication and nonce checks on AJAX endpoints, combined with the use of `unserialize` and inadequate output escaping, presents a high risk of exploitation. While there are no known CVEs, this is a transient state and does not mitigate the immediate dangers posed by the current code. The plugin requires immediate attention to address these fundamental security flaws.
Key Concerns
- Unprotected AJAX handlers
- Use of unserialize()
- Raw SQL queries
- Poor output escaping
- Missing nonce checks
- Missing capability checks
Frontend Dashboard Pages Security Vulnerabilities
Frontend Dashboard Pages Release Timeline
Frontend Dashboard Pages Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Frontend Dashboard Pages Attack Surface
AJAX Handlers 2
WordPress Hooks 14
Maintenance & Trust
Frontend Dashboard Pages Maintenance & Trust
Maintenance Signals
Community Trust
Frontend Dashboard Pages Alternatives
Frontend Dashboard Custom Post and Taxonomies
frontend-dashboard-custom-post
Frontend Dashboard Custom Post is an add-on to add and customize the custom posts and taxonomies (category and tag) inside the Frontend Dashboard.
MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy)
google-analytics-for-wordpress
The best free Google Analytics plugin for WordPress. See how visitors find and use your website so you can grow your business with powerful analytics.
Admin Menu Editor
admin-menu-editor
Lets you edit the WordPress admin menu. You can re-order, hide or rename menus, add custom menus and more.
ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin)
google-analytics-dashboard-for-wp
Connects Google Analytics with your WordPress site. Displays stats to help you understand your users and site content on a whole new level!
White Label CMS
white-label-cms
Customise dashboard panels and branding, hide menus plus lots more.
Frontend Dashboard Pages Developer Profile
21 plugins · 4K total installs
How We Detect Frontend Dashboard Pages
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/frontend-dashboard-pages/admin/css/admin.css/wp-content/plugins/frontend-dashboard-pages/admin/js/admin.js/wp-content/plugins/frontend-dashboard-pages/assets/css/frontend-dashboard-pages.css/wp-content/plugins/frontend-dashboard-pages/assets/js/frontend-dashboard-pages.js/wp-content/plugins/frontend-dashboard-pages/admin/js/admin.js/wp-content/plugins/frontend-dashboard-pages/assets/js/frontend-dashboard-pages.jsfrontend-dashboard-pages/admin/css/admin.css?ver=frontend-dashboard-pages/admin/js/admin.js?ver=frontend-dashboard-pages/assets/css/frontend-dashboard-pages.css?ver=frontend-dashboard-pages/assets/js/frontend-dashboard-pages.js?ver=HTML / DOM Fingerprints
fedp-elementor-settings-sectionfed_admin_menufed_ajaxdata-fedp-elementor-settingsfedp_save_elementor_settings_ajax_object/wp-json/fedp/v1/save-elementor-settings