
System Dashboard Security & Risk Analysis
wordpress.org/plugins/system-dashboardCentral dashboard to monitor various WordPress components, processes and data, including the server.
Is System Dashboard Safe to Use in 2026?
Generally Safe
Score 94/100System Dashboard has a strong security track record. Known vulnerabilities have been patched promptly.
The 'system-dashboard' plugin, version 2.8.21, presents a significant security risk primarily due to its extensive attack surface lacking proper authorization checks. With 32 AJAX handlers, all identified as unprotected, an attacker could potentially trigger unauthorized actions. While the code signals indicate a good general practice of using prepared statements for SQL queries and a decent rate of output escaping, the presence of dangerous functions like 'exec', 'shell_exec', and 'unserialize' alongside unsanitized paths in taint analysis is concerning. The high number of known CVEs (11), although none are currently unpatched, with a history of critical types like Missing Authorization and Path Traversal, suggests a recurring pattern of security weaknesses. The plugin's past vulnerabilities, particularly those involving authorization and path manipulation, combined with the current lack of authentication on a large portion of its entry points, creates a favorable environment for attackers. Despite strengths in SQL and output handling, the fundamental flaws in authorization and the historical vulnerability profile demand immediate attention.
Key Concerns
- 32 unprotected AJAX handlers
- Dangerous functions found (exec, shell_exec, unserialize)
- Flows with unsanitized paths (1 critical, 1 high)
- 11 known CVEs with historical authorization/path issues
- Missing nonce checks on 32 AJAX handlers
- Low rate of output escaping (79%)
- Bundled DataTables library (potential for outdated versions)
System Dashboard Security Vulnerabilities
CVEs by Year
Severity Breakdown
11 total CVEs
System Dashboard <= 2.8.20 - Cross-Site Request Forgery
System Dashboard <= 2.8.18 - Authenticated (Subscriber+) Sensitive Information Exposure
System Dashboard <= 2.8.17 - Reflected Cross-Site Scripting via Filename Parameter
System Dashboard <= 2.8.14 - Unauthenticated Stored Cross-Site Scripting
System Dashboard <= 2.8.14 - Authenticated (Admin+) Arbitrary File Read
System Dashboard <= 2.8.9 - Reflected Cross-Site Scripting via X-Forwarded-For
System Dashboard <= 2.8.8 - Missing Authorization to Information Disclosure (sd_php_info)
System Dashboard <= 2.8.7 - Missing Authorization to Information Disclosure (sd_db_specs)
System Dashboard <= 2.8.7 - Missing Authorization to Information Disclosure (sd_global_value)
System Dashboard <= 2.8.7 - Missing Authorization to Information Disclosure (sd_option_value)
System Dashboard <= 2.8.7 - Missing Authorization to Information Disclosure (sd_constants)
System Dashboard Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
System Dashboard Attack Surface
AJAX Handlers 32
WordPress Hooks 11
Maintenance & Trust
System Dashboard Maintenance & Trust
Maintenance Signals
Community Trust
System Dashboard Alternatives
Version Info – Server Health Monitor, PHP & MySQL Version Display, Environment Indicators
version-info
The #1 technical dashboard for WordPress professionals. Display PHP, MySQL, WP & server versions anywhere in admin. Monitor CPU, RAM, DB size & …
ServerMonitor
servermonitor
A simple plugin to view server resource usage (ram, cpu, disk), check your PHP error log, and more.
Temporary Login Without Password
temporary-login-without-password
Create self-expiring, temporary admin accounts. Easily share direct login links (no need for username/password) with your developers or editors.
Elementor Beta (Developer Edition)
elementor-beta
Elementor Beta (Developer Edition) gives you direct access into Elementor's development process, and lets you take an active part in perfecting o …
Server IP & Memory Usage Display
server-ip-memory-usage
Show the memory limit, current memory usage and IP address in the admin footer.
System Dashboard Developer Profile
7 plugins · 211K total installs
How We Detect System Dashboard
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/system-dashboard/css/system-dashboard-admin.css/wp-content/plugins/system-dashboard/css/jquery.json-viewer.css/wp-content/plugins/system-dashboard/css/datatables.min.css/wp-content/plugins/system-dashboard/css/fomantic-ui/accordion.css/wp-content/plugins/system-dashboard/js/system-dashboard-admin.js/wp-content/plugins/system-dashboard/js/jquery.json-viewer.js/wp-content/plugins/system-dashboard/js/datatables.min.js/wp-content/plugins/system-dashboard/js/fomantic-ui/accordion.js/wp-content/plugins/system-dashboard/js/system-dashboard-admin.js/wp-content/plugins/system-dashboard/js/jquery.json-viewer.js/wp-content/plugins/system-dashboard/js/datatables.min.js/wp-content/plugins/system-dashboard/js/fomantic-ui/accordion.jssystem-dashboard?ver=system-dashboard-json-viewer?ver=system-dashboard-datatables?ver=system-dashboard-fomantic-ui-accordion?ver=system-dashboard-admin.js?ver=jquery.json-viewer.js?ver=datatables.min.js?ver=accordion.js?ver=HTML / DOM Fingerprints
mc-collapsiblesearch-filterfield-partsfirst-partfull-widthsearch-filter-additional-infodata-controlsSystem_DashboardjQuery