
Show Me The Admin Security & Risk Analysis
wordpress.org/plugins/show-me-the-adminHides your admin toolbar and enables you to make it appear, and disappear, using a variety of methods.
Is Show Me The Admin Safe to Use in 2026?
Generally Safe
Score 100/100Show Me The Admin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "show-me-the-admin" plugin v1.2.1 exhibits a concerning security posture primarily due to its unprotected AJAX endpoints. While the plugin demonstrates good practices by avoiding dangerous functions, file operations, and external HTTP requests, the presence of two AJAX handlers without authentication checks presents a significant attack surface. This means any unauthenticated user could potentially interact with these endpoints, leading to unintended consequences or information disclosure.
The static analysis also highlights a SQL query that is not using prepared statements, which, while only one instance, increases the risk of SQL injection if the query is exposed to user-supplied input. The taint analysis indicates two flows with unsanitized paths, which, despite not being classified as critical or high severity, still represent potential areas where data could be manipulated or misused.
The absence of any recorded vulnerability history is a positive sign, suggesting the plugin has not been historically prone to security flaws. However, this should not lead to complacency, especially given the identified unprotected entry points and the raw SQL query. The plugin has strengths in its minimal external dependencies and lack of dangerous functions, but the immediate risks associated with its entry points require careful consideration.
Key Concerns
- AJAX handlers without auth checks
- SQL query not using prepared statements
- Flows with unsanitized paths
- Low percentage of properly escaped output
Show Me The Admin Security Vulnerabilities
Show Me The Admin Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Show Me The Admin Attack Surface
AJAX Handlers 2
WordPress Hooks 16
Maintenance & Trust
Show Me The Admin Maintenance & Trust
Maintenance Signals
Community Trust
Show Me The Admin Alternatives
Hide Admin Bar from Non-Admins
hide-admin-bar-from-non-admins
Hides the WordPress toolbar (admin bar) for all non-admin users. Simple plugin with no settings to configure.
Disable Toolbar
disable-toolbar
Control who sees the WP Toolbar when viewing your site.
iBar
ibar
This is a Mac OSX Menubar like WordPres adminbar/toolbar theme, designed for Mac and WordPress lovers.
Limecall
limecall-widget
Limecall is a callback widget that enable your customers to speak to you instantly within few seconds and help you increase your web conversions.
SBL Admin Bar
sbl-admin-bar
SBL Admin Bar allows you to dynamically turn the Admin Bar on/off using the hotkeys CONTROL-SHIFT-A. Can be enabled and disabled by user role.
Show Me The Admin Developer Profile
3 plugins · 410 total installs
How We Detect Show Me The Admin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/show-me-the-admin/assets/css/show-me-the-admin.css/wp-content/plugins/show-me-the-admin/assets/js/show-me-the-admin.js/wp-content/plugins/show-me-the-admin/assets/js/show-me-the-admin.jsshow-me-the-admin/assets/css/show-me-the-admin.css?ver=show-me-the-admin/assets/js/show-me-the-admin.js?ver=HTML / DOM Fingerprints
<!-- Show Me The Admin --><!-- BEGIN Show Me The Admin -->data-mouseleave-delayshow_me_the_admin_script_vars