IWG Hide Dashboard Security & Risk Analysis

wordpress.org/plugins/iwg-hide-dashboard

"Hide Dashboard" hides the dashboard for all users with the capability "hide_dashboard".

90 active installs v1.0.3 PHP + WP 2.1.0+ Updated Apr 28, 2008
admindashboardprofileuser
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is IWG Hide Dashboard Safe to Use in 2026?

Generally Safe

Score 85/100

IWG Hide Dashboard has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 17yr ago
Risk Assessment

The "iwg-hide-dashboard" plugin v1.0.3 exhibits a strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points suggests a minimal attack surface. Furthermore, the code signals indicate responsible development practices, with no dangerous functions, all SQL queries utilizing prepared statements, and no file operations or external HTTP requests detected. The presence of capability checks, even if only one, is also a positive sign. The lack of any recorded vulnerabilities, CVEs, or critical taint flows further reinforces the plugin's current secure state. However, a notable concern arises from the fact that 0% of the three identified output operations are properly escaped. This means that any data being displayed to users could potentially be vulnerable to cross-site scripting (XSS) attacks if that data originates from an untrusted source and is not sanitized before output. While the plugin has a clean vulnerability history, this unescaped output is a direct indication of a potential weakness that requires immediate attention.

Key Concerns

  • 0% of outputs are properly escaped
Vulnerabilities
None known

IWG Hide Dashboard Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

IWG Hide Dashboard Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped3 total outputs
Attack Surface

IWG Hide Dashboard Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionadmin_headiwg_hide_dashboard.php:43
Maintenance & Trust

IWG Hide Dashboard Maintenance & Trust

Maintenance Signals

WordPress version tested2.5
Last updatedApr 28, 2008
PHP min version
Downloads11K

Community Trust

Rating0/100
Number of ratings0
Active installs90
Developer Profile

IWG Hide Dashboard Developer Profile

imwebgefunden

2 plugins · 100 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect IWG Hide Dashboard

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

HTML Comments
<!-- document.location.href = "//-->
FAQ

Frequently Asked Questions about IWG Hide Dashboard