Register Sidebars By Admin Security & Risk Analysis

wordpress.org/plugins/register-sidebar-by-admin

Create/Register sidebars dynamically without any code.

10 active installs v1.0 PHP + WP 3.1+ Updated Aug 27, 2019
register-dynamic-sidebarsregister-sidebars-by-admin-and-fully-manage-by-adminregister-wp-sidebarsidebarswordpress-sidebars
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Register Sidebars By Admin Safe to Use in 2026?

Generally Safe

Score 85/100

Register Sidebars By Admin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The plugin "register-sidebar-by-admin" v1.0 exhibits a mixed security posture. On one hand, it shows strengths such as a complete absence of known CVEs and a clean vulnerability history, suggesting a generally well-maintained and secure codebase. The plugin also demonstrates good practices in its handling of SQL queries, utilizing prepared statements exclusively, and avoids file operations and external HTTP requests, which are common sources of vulnerabilities. However, the static analysis reveals significant concerns, most notably the presence of 5 dangerous function calls, specifically `unserialize`. While there are 3 nonce checks, the absence of capability checks on any entry points is a critical oversight. The taint analysis indicates one flow with unsanitized paths, though it's not categorized as critical or high severity, this warrants caution. The limited output escaping (13% properly escaped) also presents a risk of Cross-Site Scripting (XSS) vulnerabilities. The lack of exploitable entry points from the static analysis is a positive, but the internal code quality issues, particularly with `unserialize` and inadequate capability checks, mean the plugin is not entirely secure and could be vulnerable to privilege escalation or data manipulation if an attacker can trigger the unsanitized paths.

Key Concerns

  • Dangerous function calls detected (unserialize)
  • Zero capability checks on entry points
  • Low output escaping percentage
  • Flows with unsanitized paths found
Vulnerabilities
None known

Register Sidebars By Admin Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Register Sidebars By Admin Code Analysis

Dangerous Functions
5
Raw SQL Queries
0
0 prepared
Unescaped Output
13
2 escaped
Nonce Checks
3
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

unserialize$_register_sidebar_areas = unserialize(get_option('_dynamic_register_sidebars'));register-sidebar-by-admin.php:46
unserialize$_old_sidebars_arr = unserialize($_old_sidebars);register-sidebar-by-admin.php:87
unserialize$_sidebars_list = unserialize(get_option('_dynamic_register_sidebars'));register-sidebar-by-admin.php:102
unserialize$_sidebars_list = unserialize(get_option('_dynamic_register_sidebars'));register-sidebar-by-admin.php:116
unserializeif(get_option('_dynamic_register_sidebars')) $_register_siderbar = unserialize(get_option('_dynamic_register-sidebar-by-admin.php:139

Output Escaping

13% escaped15 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
register_sidebars_by_admin_view_callback (register-sidebar-by-admin.php:129)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Register Sidebars By Admin Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_menuregister-sidebar-by-admin.php:34
actionadmin_enqueue_scriptsregister-sidebar-by-admin.php:35
actionwidgets_initregister-sidebar-by-admin.php:36
actionplugins_loadedregister-sidebar-by-admin.php:236
Maintenance & Trust

Register Sidebars By Admin Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedAug 27, 2019
PHP min version
Downloads1K

Community Trust

Rating100/100
Number of ratings3
Active installs10
Developer Profile

Register Sidebars By Admin Developer Profile

p4wparamjeet

2 plugins · 110 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Register Sidebars By Admin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/register-sidebar-by-admin/assets/sidebar-by-admin-css.css/wp-content/plugins/register-sidebar-by-admin/assets/sidebar-by-admin-js.js
Script Paths
/wp-content/plugins/register-sidebar-by-admin/assets/sidebar-by-admin-js.js
Version Parameters
register-sidebar-by-admin/assets/sidebar-by-admin-css.css?ver=1.0.0register-sidebar-by-admin/assets/sidebar-by-admin-js.js?ver=1.0.0

HTML / DOM Fingerprints

CSS Classes
title
Data Attributes
dynapic_register_sidebar_insert_noncedynapic_register_sidebar_update_noncedynapic_register_sidebar_delete_nonce
JS Globals
jQuery
FAQ

Frequently Asked Questions about Register Sidebars By Admin