Shadow Screen Options Security & Risk Analysis

wordpress.org/plugins/shadow-screen-options

Create a shadow system of blog-specific screen layout options in a multisite environment.

10 active installs v0.4.1 PHP + WP 3.1.4+ Updated Apr 26, 2012
meta-boxesmultisitenetworkscreen-options
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Shadow Screen Options Safe to Use in 2026?

Generally Safe

Score 85/100

Shadow Screen Options has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 13yr ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the "shadow-screen-options" v0.4.1 plugin exhibits an exceptionally strong security posture. The absence of any identified attack surface, dangerous functions, direct SQL queries, unescaped output, file operations, external HTTP requests, or specific security checks like nonces and capabilities is highly unusual and suggests a very limited functionality or a highly specialized, well-secured implementation. The clean taint analysis further reinforces this, indicating no identifiable paths for malicious data injection or manipulation within the analyzed code flows.

The plugin's vulnerability history is also spotless, with no recorded CVEs of any severity. This lack of historical issues, combined with the pristine static analysis, paints a picture of a plugin that has been meticulously developed with security as a primary concern, or one that has such a minimal impact on the WordPress core that it has not attracted security scrutiny.

However, the complete lack of any entry points (AJAX, REST API, shortcodes, cron events) and security checks (nonce, capability) is a notable point. While it signifies no immediate exploitable vulnerabilities in the current version, it also means the plugin might offer no user-facing functionality or rely on external mechanisms for interaction, which could be a point of concern if its purpose is to provide features. Overall, this plugin appears to be highly secure based on the data, with its main 'weakness' being the absence of discernible functionality or security checks, which is more of an observation than a direct vulnerability.

Key Concerns

  • No capability checks found
  • No nonce checks found
Vulnerabilities
None known

Shadow Screen Options Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Shadow Screen Options Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Shadow Screen Options Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
filterget_user_metadatashadow-screen-options.php:45
filterupdate_user_metadatashadow-screen-options.php:46
Maintenance & Trust

Shadow Screen Options Maintenance & Trust

Maintenance Signals

WordPress version tested3.3.2
Last updatedApr 26, 2012
PHP min version
Downloads5K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Shadow Screen Options Developer Profile

Jennifer M. Dodd

4 plugins · 70 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Shadow Screen Options

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Shadow Screen Options