
Screen Options and Help Show Customize Security & Risk Analysis
wordpress.org/plugins/screen-options-and-help-show-customizeCustomization of the Screen options and Help.
Is Screen Options and Help Show Customize Safe to Use in 2026?
Generally Safe
Score 85/100Screen Options and Help Show Customize has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "screen-options-and-help-show-customize" v1.3.3 exhibits a generally positive security posture based on the static analysis. The absence of direct entry points like AJAX handlers, REST API routes, shortcodes, and cron events significantly limits its attack surface. Furthermore, the plugin demonstrates good practices by using prepared statements for all SQL queries and including nonce and capability checks for its identified code signals. There are no known vulnerabilities (CVEs) associated with this plugin, and its vulnerability history is clean, suggesting a commitment to secure development or a lack of historical issues.
However, a notable concern arises from the taint analysis, which indicates four flows with unsanitized paths. While no critical or high-severity issues were flagged in this area, four unsanitized paths present a potential risk of unexpected behavior or data manipulation if these paths are ever exposed or exploited. Additionally, the output escaping is poorly implemented, with only 7% of outputs being properly escaped. This indicates a high risk of cross-site scripting (XSS) vulnerabilities, as user-controlled data or dynamic content is likely being rendered without adequate sanitization, allowing attackers to inject malicious scripts.
In conclusion, while the plugin scores well on attack surface and vulnerability history, the significant number of unsanitized paths and the extremely low percentage of properly escaped outputs are critical weaknesses. The lack of direct entry points is a strength, but the identified code-level issues could still lead to significant security problems, particularly XSS, if the plugin's functionality involves rendering dynamic content.
Key Concerns
- Four flows with unsanitized paths
- Only 7% of outputs properly escaped
Screen Options and Help Show Customize Security Vulnerabilities
Screen Options and Help Show Customize Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Screen Options and Help Show Customize Attack Surface
WordPress Hooks 23
Maintenance & Trust
Screen Options and Help Show Customize Maintenance & Trust
Maintenance Signals
Community Trust
Screen Options and Help Show Customize Alternatives
Dashboard Option Menu Customize
dashboard-option-menu-customize
Customization options and help
Restore Columns
restore-columns
The plugin restores the possibility to select the number of columns displayed on the dashboard.
Sticky Postbox
sticky-postbox
Add sticky feature to administration meta boxes.
Easy WP Admin Customizer
easy-wp-admin-customizer
Faster and simple way to clean and customize your admin dashboard!
Redux Framework
redux-framework
Redux is a simple, truly extensible, and fully responsive options framework for WordPress themes and plugins. It ships with an integrated demo.
Screen Options and Help Show Customize Developer Profile
10 plugins · 47K total installs
How We Detect Screen Options and Help Show Customize
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/screen-options-and-help-show-customize/inc/css/manager.css/wp-content/plugins/screen-options-and-help-show-customize/inc/css/style.css/wp-content/plugins/screen-options-and-help-show-customize/inc/js/manager.js/wp-content/plugins/screen-options-and-help-show-customize/inc/js/menu.jsscreen-options-and-help-show-customize/inc/css/manager.css?ver=screen-options-and-help-show-customize/inc/css/style.css?ver=screen-options-and-help-show-customize/inc/js/manager.js?ver=screen-options-and-help-show-customize/inc/js/menu.js?ver=HTML / DOM Fingerprints
sohc_listsohc_parentsohc_childCopyright 2012 gqevu6bsiz (email : gqevu6bsiz@gmail.com)This program is free software; you can redistribute it and/or modifyit under the terms of the GNU General Public License, version 2, aspublished by the Free Software Foundation.+123 moredata-sohc-settingsSohc