
kontur Admin Style Security & Risk Analysis
wordpress.org/plugins/kontur-admin-styleA light admin theme & custom login. Easy to customize- with live-preview. Set your admin toolbar logo, colors, login-link, login background.
Is kontur Admin Style Safe to Use in 2026?
Generally Safe
Score 99/100kontur Admin Style has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The plugin "kontur-admin-style" v1.0.5 exhibits a generally good security posture based on the static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points significantly limits the attack surface. Furthermore, the code signals show no dangerous functions, no raw SQL queries, and no file operations or external HTTP requests, which are all positive indicators of secure coding practices. The 100% use of prepared statements for SQL queries is particularly commendable.
However, there are areas for improvement. The "Capability checks" and "Nonce checks" are reported as zero, which, in conjunction with the 0% of AJAX handlers and REST API routes having permission callbacks, suggests a potential for authorization bypass vulnerabilities if any of these entry points were to be introduced or exist in a less obvious manner. The 79% of output escaping is good, but the remaining 21% of unescaped outputs, although not flagged as critical in taint analysis, could still pose a Cross-Site Scripting (XSS) risk, especially given the plugin's history of XSS vulnerabilities.
The vulnerability history reveals one past CVE, specifically related to Improper Neutralization of Input During Web Page Generation (XSS). While this CVE is currently unpatched, its presence and type, coupled with the incomplete output escaping, indicates a recurring risk pattern. The fact that the "Last vulnerability" is in the future (2025-09-26) is likely a data anomaly and should be disregarded. In conclusion, while the plugin demonstrates strong defensive coding in several areas, the lack of capability and nonce checks, combined with a history and potential for XSS, warrants careful monitoring and potential remediation.
Key Concerns
- Missing capability checks
- Missing nonce checks
- Unescaped output detected
- Past XSS vulnerability
kontur Admin Style Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
kontur Admin Style <= 1.0.4 - Authenticated (Administrator+) Stored Cross-Site Scripting
kontur Admin Style Release Timeline
kontur Admin Style Code Analysis
Output Escaping
kontur Admin Style Attack Surface
WordPress Hooks 22
Maintenance & Trust
kontur Admin Style Maintenance & Trust
Maintenance Signals
Community Trust
kontur Admin Style Alternatives
AGCA – Custom Dashboard & Login Page
ag-custom-admin
CHANGE: admin menu, login page, admin bar, dashboard widgets, custom colors, custom CSS & JS, logo & images
White Label – WordPress Custom Admin, Custom Login Page, and Custom Dashboard
white-label
Our White Label WordPress plugin lets you make a custom admin experience. Create a custom login page, a custom dashboard, and much more.
White Label Builder
white-label-builder
Simple & lightweight plugin to customize WordPress to fit your brand. Easily White Label and customize client websites.
Admin Custom Login
admin-custom-login
Customize Your WordPress Login Screen Amazingly - Add Own Logo, Add Social Profiles, Login Form Positions, Background Image Slide Show
Slate Admin Theme
slate-admin-theme
A clean, simplified WordPress Admin theme.
kontur Admin Style Developer Profile
4 plugins · 280 total installs
How We Detect kontur Admin Style
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/kontur-admin-style/dist/css/kontur-admin-style.min.css/wp-content/plugins/kontur-admin-style/dist/js/kontur-admin-style.min.js/wp-content/plugins/kontur-admin-style/dist/js/kontur-admin-style.min.jskontur-admin-style/dist/css/kontur-admin-style.min.css?ver=kontur-admin-style/dist/js/kontur-admin-style.min.js?ver=HTML / DOM Fingerprints
kontur-admin-activation-noticekontur-info-buttons-rowkontur-notice-panel-iconkontur-postboxkontur-info-largekontur-notice-info-headerid="kontur-admin-activation-notice"