Obfuscate Admin Security & Risk Analysis

wordpress.org/plugins/obfuscate-admin

You want to stop users from accessing the wp-admin of your WordPress installation. Obfoscate WordPress admin url and prevent casual discovery.

0 active installs v1.0.1 PHP 5.6+ WP 5.0+ Updated Apr 21, 2019
hidehide-adminhide-wp-adminobfuscate-admin
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Obfuscate Admin Safe to Use in 2026?

Generally Safe

Score 85/100

Obfuscate Admin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The "obfuscate-admin" v1.0.1 plugin exhibits a strong security posture based on the provided static analysis. There are no identified attack vectors through AJAX, REST API, shortcodes, or cron events, and no unprotected entry points are present. The code adheres to good security practices by utilizing prepared statements for all SQL queries, properly escaping all output, and including a nonce check. The absence of file operations and external HTTP requests further reduces the potential for external manipulation.

Taint analysis revealed no critical or high severity flows, indicating that data input is not being improperly handled or exposed. The plugin's vulnerability history is entirely clear, with no known CVEs, which suggests a consistent track record of secure development or minimal exposure. While the plugin demonstrates robust security measures, the absence of capability checks on any entry points (though there are no entry points) is a minor area to note for completeness, but not a current risk. Overall, this plugin appears to be well-developed from a security perspective with no immediate, evidence-backed concerns.

Vulnerabilities
None known

Obfuscate Admin Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Obfuscate Admin Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
4 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped4 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<oa_settings> (oa_settings.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Obfuscate Admin Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionadmin_menuijasonwhite-obfuscate-admin.php:19
actionlogin_headijasonwhite-obfuscate-admin.php:33
Maintenance & Trust

Obfuscate Admin Maintenance & Trust

Maintenance Signals

WordPress version tested5.1.22
Last updatedApr 21, 2019
PHP min version5.6
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Obfuscate Admin Developer Profile

Jason White

2 plugins · 0 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Obfuscate Admin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/obfuscate-admin/obfuscate-admin.css/wp-content/plugins/obfuscate-admin/obfuscate-admin.js
Script Paths
/wp-content/plugins/obfuscate-admin/obfuscate-admin.js
Version Parameters
obfuscate-admin/obfuscate-admin.css?ver=obfuscate-admin/obfuscate-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
obfuscate-admin-settings-wrapper
FAQ

Frequently Asked Questions about Obfuscate Admin