
Multisite Dashboard Broadcast Security & Risk Analysis
wordpress.org/plugins/multisite-dashboard-broadcastPlace a widget on top of every site's dashboard under the same Multisite installation, containing whatever content the Super Admin writes.
Is Multisite Dashboard Broadcast Safe to Use in 2026?
Generally Safe
Score 100/100Multisite Dashboard Broadcast has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The multisite-dashboard-broadcast plugin v0.1 exhibits a generally positive security posture based on the provided static analysis. There are no identified dangerous functions, SQL queries are all prepared, and there are no file operations or external HTTP requests. The absence of taint analysis findings and a clean vulnerability history further contribute to this positive outlook. This suggests good coding practices and a lack of known exploitable issues.
However, a significant concern arises from the complete lack of output escaping. With 7 total outputs and 0% properly escaped, this indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities. Any user-supplied data that is displayed back to users without proper sanitization can be exploited to inject malicious scripts. Additionally, the absence of nonce checks, while not directly linked to an unprotected entry point in this analysis, is a common security best practice that is missing. The single capability check is a positive sign but doesn't mitigate the XSS risk.
Given the lack of historical vulnerabilities and a seemingly small attack surface, the plugin's core functionality might be sound. However, the critical flaw in output escaping presents a substantial security risk that overshadows these strengths. The plugin needs immediate attention to address the unescaped output to prevent potential XSS attacks.
Key Concerns
- No output escaping on 7 outputs
- No nonce checks implemented
Multisite Dashboard Broadcast Security Vulnerabilities
Multisite Dashboard Broadcast Code Analysis
Output Escaping
Multisite Dashboard Broadcast Attack Surface
WordPress Hooks 5
Maintenance & Trust
Multisite Dashboard Broadcast Maintenance & Trust
Maintenance Signals
Community Trust
Multisite Dashboard Broadcast Alternatives
Network Sites Counts Dashboard Widget
network-sites-counts-dashboard-widget
Display a list of post counts for all your sites in your network.
Network Username Restrictions Override
network-username-restrictions-override
Override restrictions on WordPress network usernames.
WPMS Sidebar Login Widget
wpms-sidebar-login-widget
Adds a sidebar widget to the main site of a WPMU/WPMS install.
Sort My Sites
sort-my-sites
Sort My Sites lets you change the ordering of the My Sites menu on the dashboard and in the admin bar.
Meet Your Commenters
meet-your-commenters
Displays web pages and social networks' profiles of your commenters in the dashboard.
Multisite Dashboard Broadcast Developer Profile
1 plugin · 10 total installs
How We Detect Multisite Dashboard Broadcast
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
id="broadcast_message_title"id="broadcast_message"window.location