
Kalimah Dashboard Security & Risk Analysis
wordpress.org/plugins/kalimah-dashboardImprove WordPress dashboard style and functions
Is Kalimah Dashboard Safe to Use in 2026?
Generally Safe
Score 85/100Kalimah Dashboard has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The kalimah-dashboard plugin v1.0.3 exhibits a mixed security posture. On the positive side, it has no known vulnerabilities (CVEs) and demonstrates good practices in its SQL query handling, utilizing prepared statements exclusively. The absence of external HTTP requests and bundled libraries also reduces potential attack vectors. However, there are significant concerns regarding output escaping and file operations. A very low percentage of outputs are properly escaped, indicating a high risk of cross-site scripting (XSS) vulnerabilities. Furthermore, the presence of file operations without apparent robust sanitization or validation in the taint analysis (one flow with unsanitized paths) suggests potential for directory traversal or arbitrary file write vulnerabilities.
The lack of readily apparent entry points like AJAX handlers, REST API routes, and shortcodes without proper authentication or capability checks is a strength. The plugin also implements some capability checks. However, the absence of nonce checks on any entry points, combined with the poor output escaping and potential file path sanitization issues, creates a notable risk profile. The vulnerability history being completely clean is positive, but it does not negate the risks identified in the static and taint analysis. A comprehensive review of file operations and output handling is strongly recommended to mitigate potential security flaws.
Key Concerns
- Poor output escaping (23% properly escaped)
- Taint flow with unsanitized paths
- File operations present without clear sanitization
- Zero nonce checks on entry points
Kalimah Dashboard Security Vulnerabilities
Kalimah Dashboard Code Analysis
Output Escaping
Data Flow Analysis
Kalimah Dashboard Attack Surface
WordPress Hooks 19
Maintenance & Trust
Kalimah Dashboard Maintenance & Trust
Maintenance Signals
Community Trust
Kalimah Dashboard Alternatives
Admin Menu Editor
admin-menu-editor
Lets you edit the WordPress admin menu. You can re-order, hide or rename menus, add custom menus and more.
White Label CMS
white-label-cms
Customise dashboard panels and branding, hide menus plus lots more.
Ultimate Dashboard – Custom WordPress Dashboard
ultimate-dashboard
The #1 Plugin to Customize the WordPress Dashboard!
Display PHP Version
display-php-version
Displays the currently installed PHP/MySQL version in the "At a Glance" admin dashboard widget.
Remove Dashboard Access
remove-dashboard-access-for-non-admins
Disable Dashboard access for users of a specific role or capability. Disallowed users are redirected to a chosen URL. Get set up in seconds.
Kalimah Dashboard Developer Profile
4 plugins · 1K total installs
How We Detect Kalimah Dashboard
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/kalimah-dashboard/css/settings.css/wp-content/plugins/kalimah-dashboard/css/font-awesome.css/wp-content/plugins/kalimah-dashboard/js/kalimah-js.js/wp-content/plugins/kalimah-dashboard/css/style-material.css/wp-content/plugins/kalimah-dashboard/css/style-flat.css/wp-content/plugins/kalimah-dashboard/css/login-style-material.css/wp-content/plugins/kalimah-dashboard/css/login-style-flat.css/wp-content/plugins/kalimah-dashboard/js/login.jsHTML / DOM Fingerprints
dahsboard-site-brandtoggle-sidemenudata-kalimah-admin-theme-typekalimah_admin_settings