UpdraftCentral Dashboard Security & Risk Analysis

wordpress.org/plugins/updraftcentral

Remote, single-dashboard management for WordPress/theme/plugin updates and UpdraftPlus backups across all your WP sites

6K active installs v0.8.30 PHP 5.6+ WP 4.6+ Updated Mar 25, 2026
management-dashboardmultiple-site-managementremote-controlremote-dashboardremote-management
99
A · Safe
CVEs total1
Unpatched0
Last CVEDec 6, 2022
Safety Verdict

Is UpdraftCentral Dashboard Safe to Use in 2026?

Generally Safe

Score 99/100

UpdraftCentral Dashboard has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Dec 6, 2022Updated 1mo ago
Risk Assessment

The UpdraftCentral plugin v0.8.30 exhibits a mixed security posture. While it demonstrates good practices in many areas, including a low number of unprotected entry points and a high percentage of properly escaped outputs and prepared SQL statements, several significant concerns warrant attention. The presence of 'exec' in dangerous functions, coupled with two taint flows with unsanitized paths (both flagged as high severity), indicates a potential for serious security breaches if these flows are exploitable. The vulnerability history, specifically the past high-severity SSRF vulnerability, further highlights the plugin's susceptibility to network-related attacks. The fact that there are no currently unpatched CVEs is a positive sign, suggesting active maintenance, but the history of a high-severity vulnerability indicates a need for continued vigilance and rigorous security testing.

Key Concerns

  • High severity taint flows with unsanitized paths
  • Use of dangerous 'exec' function
  • Past high severity SSRF vulnerability
  • Bundled DataTables library
  • Bundled Select2 library
  • Bundled Guzzle library
Vulnerabilities
1 published

UpdraftCentral Dashboard Security Vulnerabilities

CVEs by Year

1 CVE in 2022
2022
Patched Has unpatched

Severity Breakdown

High
1

1 total CVE

WF-ef1468eb-9b98-4d45-b357-70998ba17de7-updraftcentralhigh · 8.3Server-Side Request Forgery (SSRF)

UpdraftCentral Dashboard 0.8.23 - Server-Side Request Forgery

Dec 6, 2022 Patched in 0.8.24 (413d)
Code Analysis
Analyzed Mar 16, 2026

UpdraftCentral Dashboard Code Analysis

Dangerous Functions
3
Raw SQL Queries
18
64 prepared
Unescaped Output
30
188 escaped
Nonce Checks
4
Capability Checks
4
File Operations
11
External Requests
1
Bundled Libraries
3

Dangerous Functions Found

execexec('cp -r '.escapeshellarg($modules_dir.'/'.$e.'/templates').' '.escapeshellarg($e));templates\handlebars-compiler.php:24
execexec('rm -rf '.escapeshellarg($module));templates\handlebars-compiler.php:62
execexec($path_to_handlebars.' '.escapeshellarg($templates_dir.'/'.$copy_file).' --namespace UpdraftCenttemplates\handlebars-compiler.php:82

Bundled Libraries

DataTablesSelect2Guzzle

SQL Query Safety

78% prepared82 total queries

Output Escaping

86% escaped218 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

6 flows2 with unsanitized paths
plupload_action (classes\class-uploader.php:169)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

UpdraftCentral Dashboard Attack Surface

Entry Points4
Unprotected0

AJAX Handlers 1

authwp_ajax_updraftcentral_dashboard_ajaxsite-management.php:153

Shortcodes 3

[updraftcentral_licences_in_use] classes\licence-manager.php:49
[updraftcentral_licences_total] classes\licence-manager.php:50
[updraft_central] site-management.php:104
WordPress Hooks 116
filterrest_pre_dispatchclasses\class-editor.php:29
actionupdraftcentral_load_dashboard_jsclasses\class-editor.php:30
filterscreen_options_show_screenclasses\class-editor.php:113
actionadd_meta_boxesclasses\class-editor.php:1095
filterupdraftcentral_dashboard_ajaxaction_newsiteclasses\user.php:41
filterupdraftcentral_dashboard_ajaxaction_import_settingsclasses\user.php:42
filterupdraftcentral_dashboard_ajaxaction_export_settingsclasses\user.php:43
filterupdraftcentral_dashboard_ajaxaction_edit_site_configurationclasses\user.php:44
filterupdraftcentral_dashboard_ajaxaction_edit_site_connection_methodclasses\user.php:45
filterupdraftcentral_dashboard_ajaxaction_delete_siteclasses\user.php:46
filterupdraftcentral_dashboard_ajaxaction_sites_htmlclasses\user.php:47
filterupdraftcentral_dashboard_ajaxaction_site_rpcclasses\user.php:48
filterupdraftcentral_dashboard_ajaxaction_manage_site_orderclasses\user.php:49
filterupdraftcentral_load_user_sitesclasses\user.php:51
filterupdraftcentral_dashboard_ajaxaction_manage_site_metaclasses\user.php:52
filterupdraftcentral_dashboard_ajaxaction_shortcutsclasses\user.php:55
filterupdraftcentral_main_navigation_itemsclasses\user.php:58
filterupdraftcentral_dashboard_ajaxaction_module_visibilityclasses\user.php:59
filterupdraftcentral_dashboard_ajaxaction_reset_modules_visibilityclasses\user.php:60
filterupdraftcentral_dashboard_ajaxaction_save_timeoutclasses\user.php:63
filterupdraftcentral_dashboard_ajaxaction_cache_responseclasses\user.php:65
filterupdraftcentral_dashboard_ajaxaction_save_settingsclasses\user.php:66
filterupdraftcentral_site_alert_iconclasses\user.php:67
filterupdraftcentral_dashboard_ajaxaction_log_eventclasses\user.php:68
filterupdraftcentral_dashboard_ajaxaction_eventsclasses\user.php:69
filterupdraftcentral_site_data_attributesclasses\user.php:70
filterupdraftcentral_dashboard_ajaxaction_load_event_sitesclasses\user.php:71
actionupdraftcentral_load_dashboard_jsmodules\advancedtools\loader.php:21
actionupdraftcentral_load_dashboard_cssmodules\advancedtools\loader.php:22
actionupdraftcentral_dashboard_post_navigationmodules\advancedtools\loader.php:23
actionupdraftcentral_site_row_after_buttonsmodules\advancedtools\loader.php:24
filterupdraftcentral_main_navigation_itemsmodules\advancedtools\loader.php:25
filterupdraftcentral_udrclionmodules\advancedtools\loader.php:26
filterupdraftcentral_template_directoriesmodules\advancedtools\loader.php:27
filterupdraftcentral_keyboard_shortcutsmodules\advancedtools\loader.php:30
actionupdraftcentral_load_dashboard_jsmodules\eum\loader.php:25
actionupdraftcentral_load_dashboard_cssmodules\eum\loader.php:26
actionupdraftcentral_dashboard_post_navigationmodules\eum\loader.php:27
actionupdraftcentral_site_row_after_buttonsmodules\eum\loader.php:28
filterupdraftcentral_main_navigation_itemsmodules\eum\loader.php:29
filterupdraftcentral_udrclionmodules\eum\loader.php:30
filterupdraftcentral_template_directoriesmodules\eum\loader.php:31
actionupdraftcentral_load_dashboard_cssmodules\events\loader.php:20
actionupdraftcentral_dashboard_post_navigationmodules\events\loader.php:21
actionupdraftcentral_dashboard_post_contentmodules\events\loader.php:22
filterupdraftcentral_main_navigation_itemsmodules\events\loader.php:23
filterupdraftcentral_template_directoriesmodules\events\loader.php:24
actionupdraftcentral_load_dashboard_jsmodules\events\loader.php:25
filterupdraftcentral_udrclionmodules\events\loader.php:26
filterupdraftcentral_keyboard_shortcutsmodules\events\loader.php:29
actionupdraftcentral_load_dashboard_cssmodules\notices\loader.php:18
actionupdraftcentral_dashboard_post_navigationmodules\notices\loader.php:19
actionupdraftcentral_dashboard_pre_headermodules\notices\loader.php:20
actionupdraftcentral_dashboard_post_contentmodules\notices\loader.php:21
filterupdraftcentral_main_navigation_itemsmodules\notices\loader.php:22
filterupdraftcentral_template_directoriesmodules\notices\loader.php:23
actionupdraftcentral_dashboard_ajaxaction_dismiss_noticemodules\notices\loader.php:24
filterupdraftcentral_keyboard_shortcutsmodules\notices\loader.php:27
actionupdraftcentral_load_dashboard_jsmodules\site_search\loader.php:12
actionupdraftcentral_load_dashboard_cssmodules\site_search\loader.php:13
filterupdraftcentral_udrclionmodules\site_search\loader.php:14
filterupdraftcentral_template_directoriesmodules\site_search\loader.php:15
actionupdraftcentral_dashboard_pre_headermodules\site_search\loader.php:16
actionupdraftcentral_load_dashboard_jsmodules\updates\loader.php:9
actionupdraftcentral_load_dashboard_cssmodules\updates\loader.php:10
filterupdraftcentral_udrclionmodules\updates\loader.php:11
actionupdraftcentral_dashboard_post_navigationmodules\updates\loader.php:12
filterupdraftcentral_main_navigation_itemsmodules\updates\loader.php:13
actionupdraftcentral_site_row_after_buttonsmodules\updates\loader.php:14
filterupdraftcentral_template_directoriesmodules\updates\loader.php:15
filterupdraftcentral_keyboard_shortcutsmodules\updates\loader.php:18
filterupdraftcentral_scheduled_commandsmodules\updates\loader.php:21
filterupdraftcentral_sub_menusmodules\updates\loader.php:22
actionupdraftcentral_load_dashboard_jsmodules\updraftplus\loader.php:9
actionupdraftcentral_load_dashboard_cssmodules\updraftplus\loader.php:10
filterupdraftcentral_udrclionmodules\updraftplus\loader.php:11
actionupdraftcentral_dashboard_post_navigationmodules\updraftplus\loader.php:12
filterupdraftcentral_main_navigation_itemsmodules\updraftplus\loader.php:13
actionupdraftcentral_site_row_after_buttonsmodules\updraftplus\loader.php:14
filterupdraftcentral_template_directoriesmodules\updraftplus\loader.php:15
filterupdraftcentral_keyboard_shortcutsmodules\updraftplus\loader.php:18
actionupdraftcentral_load_dashboard_jsmodules\updraftvault\loader.php:12
actionupdraftcentral_load_dashboard_cssmodules\updraftvault\loader.php:13
actionupdraftcentral_dashboard_post_navigationmodules\updraftvault\loader.php:14
actionupdraftcentral_site_row_after_buttonsmodules\updraftvault\loader.php:15
filterupdraftcentral_main_navigation_itemsmodules\updraftvault\loader.php:16
filterupdraftcentral_udrclionmodules\updraftvault\loader.php:17
filterupdraftcentral_template_directoriesmodules\updraftvault\loader.php:18
filterupdraftcentral_keyboard_shortcutsmodules\updraftvault\loader.php:21
actionupdraftcentral_load_dashboard_jsmodules\wpo\loader.php:25
actionupdraftcentral_load_dashboard_cssmodules\wpo\loader.php:26
actionupdraftcentral_dashboard_post_navigationmodules\wpo\loader.php:27
actionupdraftcentral_site_row_after_buttonsmodules\wpo\loader.php:28
filterupdraftcentral_main_navigation_itemsmodules\wpo\loader.php:29
filterupdraftcentral_udrclionmodules\wpo\loader.php:30
filterupdraftcentral_template_directoriesmodules\wpo\loader.php:31
actionenqueue_block_assetssite-management.php:106
actionall_admin_noticessite-management.php:109
actionall_admin_noticessite-management.php:115
actionplugins_loadedsite-management.php:131
actioninitsite-management.php:132
actionadmin_menusite-management.php:137
actionwoocommerce_login_redirectsite-management.php:145
actionupdraftcentral_print_dashboard_noticessite-management.php:147
actioninitsite-management.php:150
actionupdraftcentral_initedsite-management.php:156
actionupdraftcentral_cronsite-management.php:158
actionshutdownsite-management.php:159
actiondelete_usersite-management.php:161
filtercron_schedulessite-management.php:164
filterwp_privacy_personal_data_exporterssite-management.php:167
filterget_site_metadatasite-management.php:616
filterget_site_metadata_createdsite-management.php:617
actionwp_footersite-management.php:888
actionwoocommerce_login_formtemplates\dashboard\not-authorised.php:15
actionwoocommerce_login_formtemplates\dashboard\not-logged-in.php:15

Scheduled Events 1

updraftcentral_cron
Maintenance & Trust

UpdraftCentral Dashboard Maintenance & Trust

Maintenance Signals

WordPress version tested7.0
Last updatedMar 25, 2026
PHP min version5.6
Downloads270K

Community Trust

Rating90/100
Number of ratings22
Active installs6K
Developer Profile

UpdraftCentral Dashboard Developer Profile

David Anderson / Team Updraft

16 plugins · 6.4M total installs

77
trust score
Avg Security Score
97/100
Avg Patch Time
1159 days
View full developer profile
Detection Fingerprints

How We Detect UpdraftCentral Dashboard

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/updraftcentral/assets/css/vendor/bootstrap.min.css/wp-content/plugins/updraftcentral/assets/css/vendor/bootstrap-select.min.css/wp-content/plugins/updraftcentral/assets/css/vendor/datatables.min.css/wp-content/plugins/updraftcentral/assets/css/updraftcentral-dashboard.css/wp-content/plugins/updraftcentral/assets/css/updraftcentral-dashboard-rtl.css/wp-content/plugins/updraftcentral/assets/js/vendor/bootstrap.min.js/wp-content/plugins/updraftcentral/assets/js/vendor/bootstrap-select.min.js/wp-content/plugins/updraftcentral/assets/js/vendor/datatables.min.js+5 more
Version Parameters
updraftcentral/assets/css/vendor/bootstrap.min.css?ver=updraftcentral/assets/css/vendor/bootstrap-select.min.css?ver=updraftcentral/assets/css/vendor/datatables.min.css?ver=updraftcentral/assets/css/updraftcentral-dashboard.css?ver=updraftcentral/assets/css/updraftcentral-dashboard-rtl.css?ver=updraftcentral/assets/js/vendor/bootstrap.min.js?ver=updraftcentral/assets/js/vendor/bootstrap-select.min.js?ver=updraftcentral/assets/js/vendor/datatables.min.js?ver=updraftcentral/assets/js/vendor/jquery.dataTables.rowsReorder.min.js?ver=updraftcentral/assets/js/vendor/jquery.easing.1.3.js?ver=updraftcentral/assets/js/vendor/mustache.min.js?ver=updraftcentral/assets/js/updraftcentral-dashboard.js?ver=updraftcentral/assets/js/updraftcentral-dashboard-rtl.js?ver=

HTML / DOM Fingerprints

CSS Classes
updraftcentral-dashboard-wrapperupdraftcentral-site-listupdraftcentral-site-infoupdraftcentral-site-actionsupdraftcentral-navigationupdraftcentral-content-areaupdraftcentral-modalupdraftcentral-spinner
HTML Comments
<!-- Do not delete this file, WordPress will automatically delete it --><!-- UpdraftCentral - Manage your WordPress sites from a central dashboard --><!-- UpdraftCentral Dashboard Content -->
Data Attributes
data-updraftcentral-site-iddata-updraftcentral-actiondata-updraftcentral-nonce
JS Globals
UpdraftCentralDashboardUpdraftCentralAjaxupdraftcentral_localized_data
REST Endpoints
/wp-json/updraftcentral/v1/sites/wp-json/updraftcentral/v1/site//wp-json/updraftcentral/v1/status/wp-json/updraftcentral/v1/settings
Shortcode Output
<div id="updraft_central_dashboard"></div>
FAQ

Frequently Asked Questions about UpdraftCentral Dashboard