kontur Admin Style Security & Risk Analysis

wordpress.org/plugins/kontur-admin-style

A light admin theme & custom login. Easy to customize- with live-preview. Set your admin toolbar logo, colors, login-link, login background.

50 active installs v1.0.5 PHP 7.0+ WP 5.0+ Updated Oct 4, 2025
adminadmin-themecustom-admincustom-loginwhite-label
99
A · Safe
CVEs total1
Unpatched0
Last CVESep 26, 2025
Safety Verdict

Is kontur Admin Style Safe to Use in 2026?

Generally Safe

Score 99/100

kontur Admin Style has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Sep 26, 2025Updated 7mo ago
Risk Assessment

The plugin "kontur-admin-style" v1.0.5 exhibits a generally good security posture based on the static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points significantly limits the attack surface. Furthermore, the code signals show no dangerous functions, no raw SQL queries, and no file operations or external HTTP requests, which are all positive indicators of secure coding practices. The 100% use of prepared statements for SQL queries is particularly commendable.

However, there are areas for improvement. The "Capability checks" and "Nonce checks" are reported as zero, which, in conjunction with the 0% of AJAX handlers and REST API routes having permission callbacks, suggests a potential for authorization bypass vulnerabilities if any of these entry points were to be introduced or exist in a less obvious manner. The 79% of output escaping is good, but the remaining 21% of unescaped outputs, although not flagged as critical in taint analysis, could still pose a Cross-Site Scripting (XSS) risk, especially given the plugin's history of XSS vulnerabilities.

The vulnerability history reveals one past CVE, specifically related to Improper Neutralization of Input During Web Page Generation (XSS). While this CVE is currently unpatched, its presence and type, coupled with the incomplete output escaping, indicates a recurring risk pattern. The fact that the "Last vulnerability" is in the future (2025-09-26) is likely a data anomaly and should be disregarded. In conclusion, while the plugin demonstrates strong defensive coding in several areas, the lack of capability and nonce checks, combined with a history and potential for XSS, warrants careful monitoring and potential remediation.

Key Concerns

  • Missing capability checks
  • Missing nonce checks
  • Unescaped output detected
  • Past XSS vulnerability
Vulnerabilities
1 published

kontur Admin Style Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-60185medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

kontur Admin Style <= 1.0.4 - Authenticated (Administrator+) Stored Cross-Site Scripting

Sep 26, 2025 Patched in 1.0.5 (13d)
Version History

kontur Admin Style Release Timeline

v1.0.5Current
v1.0.41 CVE
v1.0.31 CVE
Code Analysis
Analyzed Mar 16, 2026

kontur Admin Style Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
11
42 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

79% escaped53 total outputs
Attack Surface

kontur Admin Style Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 22
actionwp_before_admin_bar_renderadmin\add-ons\kontur-admin-style-adminbar-logo.php:51
actionadmin_headadmin\add-ons\kontur-admin-style-adminbar-logo.php:54
filterlogin_headerurladmin\add-ons\kontur-admin-style-login.php:25
filterlogin_headertextadmin\add-ons\kontur-admin-style-login.php:32
actionlogin_enqueue_scriptsadmin\add-ons\kontur-admin-style-login.php:71
filterlogin_redirectadmin\add-ons\kontur-admin-style-login.php:89
filterlogin_footeradmin\add-ons\kontur-admin-style-login.php:92
actioninitadmin\add-ons\kontur-admin-style-login.php:94
actionwp_before_admin_bar_renderadmin\add-ons\kontur-admin-style-werbekontur-dashicons.php:51
actionadmin_headincludes\kontur-admin-style-backend.php:21
actionwp_enqueue_scriptsincludes\kontur-admin-style-frontend.php:38
actionadmin_noticeskontur-admin-style.php:52
actionadmin_noticeskontur-admin-style.php:255
actionplugins_loadedkontur-admin-style.php:280
actionadmin_menukontur-admin-style.php:299
actioninitkontur-admin-style.php:306
actionadmin_enqueue_scriptskontur-admin-style.php:330
actionadmin_initkontur-admin-style.php:406
actionkontur_admin_style_default_optionskontur-admin-style.php:442
actioninitkontur-admin-style.php:473
actioninitkontur-admin-style.php:485
actioninitkontur-admin-style.php:496
Maintenance & Trust

kontur Admin Style Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 4, 2025
PHP min version7.0
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs50
Developer Profile

kontur Admin Style Developer Profile

kontur.us

4 plugins · 280 total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
13 days
View full developer profile
Detection Fingerprints

How We Detect kontur Admin Style

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/kontur-admin-style/dist/css/kontur-admin-style.min.css/wp-content/plugins/kontur-admin-style/dist/js/kontur-admin-style.min.js
Script Paths
/wp-content/plugins/kontur-admin-style/dist/js/kontur-admin-style.min.js
Version Parameters
kontur-admin-style/dist/css/kontur-admin-style.min.css?ver=kontur-admin-style/dist/js/kontur-admin-style.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
kontur-admin-activation-noticekontur-info-buttons-rowkontur-notice-panel-iconkontur-postboxkontur-info-largekontur-notice-info-header
Data Attributes
id="kontur-admin-activation-notice"
FAQ

Frequently Asked Questions about kontur Admin Style