LH Custom Dashboard Security & Risk Analysis

wordpress.org/plugins/lh-custom-dashboard

Customise your Wordpress dashboard backend

10 active installs v1.25 PHP + WP 3.5+ Updated Oct 17, 2020
custom-dashboarddashboardwordpress-custom-dashboardwp-admin
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is LH Custom Dashboard Safe to Use in 2026?

Generally Safe

Score 85/100

LH Custom Dashboard has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "lh-custom-dashboard" plugin version 1.25 presents a generally positive security posture based on the static analysis provided. The complete absence of known vulnerabilities in its history is a significant strength, suggesting a well-maintained and security-conscious development process. Furthermore, the code analysis reveals a remarkably small attack surface, with no AJAX handlers, REST API routes, shortcodes, or cron events that could serve as entry points for attackers. The developer also demonstrates good practices by exclusively using prepared statements for SQL queries and implementing nonce and capability checks. However, a notable weakness lies in the output escaping. With 68 total outputs and only 21% properly escaped, there is a significant risk of cross-site scripting (XSS) vulnerabilities. This means that potentially malicious data could be rendered directly in the user's browser without proper sanitization, opening the door for attackers to inject arbitrary code.

Key Concerns

  • Low percentage of properly escaped output
Vulnerabilities
None known

LH Custom Dashboard Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

LH Custom Dashboard Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
54
14 escaped
Nonce Checks
2
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

21% escaped68 total outputs
Attack Surface

LH Custom Dashboard Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 16
filteradmin_footer_textlh-custom-dashboard.php:523
filterupdate_footerlh-custom-dashboard.php:524
actionadmin_headlh-custom-dashboard.php:525
actionadmin_menulh-custom-dashboard.php:526
actionadmin_enqueue_scriptslh-custom-dashboard.php:527
actionwp_before_admin_bar_renderlh-custom-dashboard.php:528
filterplugin_action_linkslh-custom-dashboard.php:529
filtersite_icon_image_sizeslh-custom-dashboard.php:531
filtersite_icon_meta_tagslh-custom-dashboard.php:535
actionadmin_headlh-custom-dashboard.php:538
actionnetwork_admin_menulh-custom-dashboard.php:542
actionadmin_headlh-custom-dashboard.php:547
actionwp_headlh-custom-dashboard.php:548
filterwpmu_blogs_columnslh-custom-dashboard.php:551
actionmanage_sites_custom_columnlh-custom-dashboard.php:552
actionplugins_loadedlh-custom-dashboard.php:579
Maintenance & Trust

LH Custom Dashboard Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedOct 17, 2020
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

LH Custom Dashboard Developer Profile

shawfactor

77 plugins · 15K total installs

91
trust score
Avg Security Score
87/100
Avg Patch Time
7 days
View full developer profile
Detection Fingerprints

How We Detect LH Custom Dashboard

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/lh-custom-dashboard/scripts/uploader.js
Script Paths
/wp-content/plugins/lh-custom-dashboard/scripts/uploader.js
Version Parameters
lh-custom-dashboard/scripts/uploader.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about LH Custom Dashboard