Simple Client Dashboard Security & Risk Analysis

wordpress.org/plugins/webmaster-user-role

Restrict permissions with Simple Client Dashboard. Our new "Admin" user role between Administrator and Editor is perfect for clients and Webmasters.

2K active installs v2.1.7.25 PHP + WP 3.5+ Updated Feb 10, 2026
adminclientrestrict-accessroleuser
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Simple Client Dashboard Safe to Use in 2026?

Generally Safe

Score 100/100

Simple Client Dashboard has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "webmaster-user-role" plugin, version 2.1.7.25, presents a generally strong security posture based on the provided static analysis and vulnerability history. The absence of any known CVEs, including unpatched ones, and the lack of identified critical or high severity vulnerabilities in its history are significant strengths. Furthermore, the static analysis reveals a very limited attack surface with no AJAX handlers, REST API routes, shortcodes, or cron events exposed. All SQL queries are properly prepared, and nonce and capability checks are implemented, indicating good development practices in these areas.

However, a critical concern arises from the output escaping analysis. With one total output identified and 0% properly escaped, this indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities. Any data displayed to users that originates from or passes through this plugin's code could potentially be injected with malicious scripts. While taint analysis showed no flows, this is likely due to the minimal number of flows analyzed (0 total), not necessarily a guarantee of safety.

In conclusion, while the plugin benefits from a clean vulnerability history and a minimal attack surface, the complete lack of output escaping is a severe weakness that significantly elevates its risk profile. This single issue creates a substantial attack vector for XSS. The plugin demonstrates good practices in SQL handling and authorization checks, but the output sanitization needs immediate attention to mitigate this critical security flaw.

Key Concerns

  • Unescaped output detected
Vulnerabilities
None known

Simple Client Dashboard Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Simple Client Dashboard Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
1
0 escaped
Nonce Checks
1
Capability Checks
4
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

0% escaped1 total outputs
Attack Surface

Simple Client Dashboard Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 127
actionadmin_initincludes\class-pro.php:29
actionupdated_optionincludes\class-pro.php:30
filterscd_settings_schemaincludes\class-settings.php:175
filterscd_settings_computed_schemaincludes\class-settings.php:176
filtersimple_client_dashboard/config/sectionsincludes\class-upgrade.php:30
actionadmin_initincludes\class-wp-admin.php:47
actionadmin_enqueue_scriptsincludes\class-wp-admin.php:48
actionadmin_body_classincludes\class-wp-admin.php:49
actionadmin_print_scriptsincludes\class-wp-admin.php:51
actionadmin_menuincludes\class-wp-admin.php:53
filtersimple_client_dashboard/config/sectionsincludes\module-acf.php:22
actionadmin_menuincludes\module-acf.php:33
filtersimple_client_dashboard/config/sectionsincludes\module-business-profile.php:22
actionadmin_menuincludes\module-business-profile.php:33
actionadmin_initincludes\module-business-profile.php:34
filtersimple_client_dashboard/config/sectionsincludes\module-cf7.php:22
filtertd_webmaster_capabilitiesincludes\module-cf7.php:25
actionplugins_loadedincludes\module-cf7.php:37
filtersimple_client_dashboard/config/sectionsincludes\module-draw-attention.php:22
actionadmin_menuincludes\module-draw-attention.php:33
actioninitincludes\module-events-calendar.php:39
filtersimple_client_dashboard/config/sectionsincludes\module-events-calendar.php:73
filtertd_webmaster_capabilitiesincludes\module-events-calendar.php:76
filtersimple_client_dashboard/config/sectionsincludes\module-gravity-forms.php:24
filtertd_webmaster_capabilitiesincludes\module-gravity-forms.php:27
actionadmin_footerincludes\module-gravity-forms.php:39
filtersimple_client_dashboard/config/sectionsincludes\module-itsec.php:22
filtersimple_client_dashboard/config/sectionsincludes\module-jetpack.php:19
actionadmin_menuincludes\module-jetpack.php:30
actionadmin_initincludes\module-jetpack.php:31
filtersimple_client_dashboard/config/sectionsincludes\module-learndash.php:28
actionadmin_menuincludes\module-learndash.php:39
actionadmin_initincludes\module-learndash.php:40
filtersimple_client_dashboard/config/sectionsincludes\module-ninja-forms.php:16
filterninja_forms_admin_import_export_capabilitiesincludes\module-ninja-forms.php:24
filterninja_forms_admin_settings_capabilitiesincludes\module-ninja-forms.php:25
filterninja_forms_admin_extend_capabilitiesincludes\module-ninja-forms.php:26
filterninja_forms_admin_status_capabilitiesincludes\module-ninja-forms.php:27
filterninja_forms_admin_submissions_capabilitiesincludes\module-ninja-forms.php:28
filterninja_forms_admin_all_forms_capabilitiesincludes\module-ninja-forms.php:29
filterninja_forms_admin_add_new_capabilitiesincludes\module-ninja-forms.php:30
actionadmin_menuincludes\module-ninja-forms.php:31
filtersimple_client_dashboard/config/sectionsincludes\module-plugins.php:19
filtertd_webmaster_capabilitiesincludes\module-plugins.php:20
filtersimple_client_dashboard/config/sectionsincludes\module-redirection.php:23
filterredirection_roleincludes\module-redirection.php:34
filtersimple_client_dashboard/config/sectionsincludes\module-sgcachepress.php:22
actionadmin_menuincludes\module-sgcachepress.php:33
actionadmin_initincludes\module-sgcachepress.php:34
filtersimple_client_dashboard/config/sectionsincludes\module-simple-css.php:22
actionadmin_menuincludes\module-simple-css.php:33
filtersimple_client_dashboard/config/sectionsincludes\module-table-press.php:15
filtersimple_client_dashboard/config/sectionsincludes\module-themes.php:23
filtersimple_client_dashboard/config/sectionsincludes\module-tools.php:23
actionadmin_menuincludes\module-tools.php:35
filtersimple_client_dashboard/config/sectionsincludes\module-users.php:23
filtertd_webmaster_capabilitiesincludes\module-users.php:24
filtereditable_rolesincludes\module-users.php:35
filtersimple_client_dashboard/config/sectionsincludes\module-woocommerce.php:22
filtertd_webmaster_capabilitiesincludes\module-woocommerce.php:25
actionwp_user_dashboard_setupincludes\module-woocommerce.php:37
actionwp_dashboard_setupincludes\module-woocommerce.php:38
filtersimple_client_dashboard/config/sectionsincludes\module-wordfence.php:27
actionwp_user_dashboard_setupincludes\module-wordfence.php:38
actionwp_dashboard_setupincludes\module-wordfence.php:39
filtersimple_client_dashboard/config/sectionsincludes\module-wpai.php:22
actionadmin_menuincludes\module-wpai.php:33
filtersimple_client_dashboard/config/sectionsincludes\module-yoast.php:22
actionplugins_loadedincludes\module-yoast.php:33
actionadmin_menuincludes\module-yoast.php:34
actionadmin_bar_menuincludes\module-yoast.php:35
filterwebmaster_supported_themeincludes\themes\avada-theme-module.php:7
filterwebmaster_supported_theme_setting_fieldsincludes\themes\avada-theme-module.php:8
actionadmin_menuincludes\themes\avada-theme-module.php:27
actioninitincludes\themes\avada-theme-module.php:28
filterwebmaster_supported_themeincludes\themes\avian-theme-module.php:7
filterwebmaster_supported_theme_setting_fieldsincludes\themes\avian-theme-module.php:8
actionadmin_menuincludes\themes\avian-theme-module.php:27
filterwebmaster_supported_themeincludes\themes\boss-theme-module.php:7
filterwebmaster_supported_theme_setting_fieldsincludes\themes\boss-theme-module.php:8
actionadmin_menuincludes\themes\boss-theme-module.php:27
filterwebmaster_supported_themeincludes\themes\canvas-theme-module.php:7
filterwebmaster_supported_theme_setting_fieldsincludes\themes\canvas-theme-module.php:8
actionadmin_menuincludes\themes\canvas-theme-module.php:28
filterwebmaster_supported_themeincludes\themes\cardinal-theme-module.php:7
filterwebmaster_supported_theme_setting_fieldsincludes\themes\cardinal-theme-module.php:8
actionadmin_menuincludes\themes\cardinal-theme-module.php:27
actionwp_before_admin_bar_renderincludes\themes\cardinal-theme-module.php:28
filterwebmaster_supported_themeincludes\themes\divi-theme-module.php:7
filterwebmaster_supported_theme_setting_fieldsincludes\themes\divi-theme-module.php:8
actionadmin_menuincludes\themes\divi-theme-module.php:28
filteruser_has_capincludes\themes\divi-theme-module.php:97
filterwebmaster_supported_themeincludes\themes\enfold-theme-module.php:7
filterwebmaster_supported_theme_setting_fieldsincludes\themes\enfold-theme-module.php:8
actionadmin_menuincludes\themes\enfold-theme-module.php:27
actionwp_before_admin_bar_renderincludes\themes\enfold-theme-module.php:28
filterwebmaster_supported_themeincludes\themes\genesis-theme-module.php:7
filterwebmaster_supported_theme_setting_fieldsincludes\themes\genesis-theme-module.php:8
actionafter_setup_themeincludes\themes\genesis-theme-module.php:28
filterwebmaster_supported_themeincludes\themes\invicta-theme-module.php:7
filterwebmaster_supported_theme_setting_fieldsincludes\themes\invicta-theme-module.php:8
actioninitincludes\themes\invicta-theme-module.php:27
actionadmin_menuincludes\themes\invicta-theme-module.php:74
filterwebmaster_supported_themeincludes\themes\kallyas-theme-module.php:7
filterwebmaster_supported_theme_setting_fieldsincludes\themes\kallyas-theme-module.php:8
actioninitincludes\themes\kallyas-theme-module.php:27
filterwebmaster_supported_themeincludes\themes\ken-theme-module.php:7
filterwebmaster_supported_theme_setting_fieldsincludes\themes\ken-theme-module.php:8
actionadmin_menuincludes\themes\ken-theme-module.php:27
filterwebmaster_supported_themeincludes\themes\nativechurch-theme-module.php:7
filterwebmaster_supported_theme_setting_fieldsincludes\themes\nativechurch-theme-module.php:8
actionadmin_menuincludes\themes\nativechurch-theme-module.php:27
filterwebmaster_supported_themeincludes\themes\total-theme-module.php:7
filterwebmaster_supported_theme_setting_fieldsincludes\themes\total-theme-module.php:8
actionadmin_menuincludes\themes\total-theme-module.php:27
filterwebmaster_supported_themeincludes\themes\transport-theme-module.php:7
filterwebmaster_supported_theme_setting_fieldsincludes\themes\transport-theme-module.php:8
actionadmin_menuincludes\themes\transport-theme-module.php:27
actionwp_before_admin_bar_renderincludes\themes\transport-theme-module.php:28
actionadmin_enqueue_scriptswebmaster-user-role.php:165
actionwpmu_new_blogwebmaster-user-role.php:166
actionadmin_menuwebmaster-user-role.php:169
actionadmin_initwebmaster-user-role.php:170
actionadmin_initwebmaster-user-role.php:171
actionadmin_initwebmaster-user-role.php:172
actionrest_api_initwebmaster-user-role.php:174
actionplugins_loadedwebmaster-user-role.php:734
Maintenance & Trust

Simple Client Dashboard Maintenance & Trust

Maintenance Signals

WordPress version tested7.0
Last updatedFeb 10, 2026
PHP min version
Downloads85K

Community Trust

Rating90/100
Number of ratings26
Active installs2K
Developer Profile

Simple Client Dashboard Developer Profile

TylerDigital

4 plugins · 3K total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Simple Client Dashboard

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/webmaster-user-role/assets/css/style.css/wp-content/plugins/webmaster-user-role/assets/js/scripts.js
Script Paths
/wp-content/plugins/webmaster-user-role/assets/js/scripts.js
Version Parameters
webmaster-user-role/assets/css/style.css?ver=webmaster-user-role/assets/js/scripts.js?ver=

HTML / DOM Fingerprints

CSS Classes
scd-plugin-settings
HTML Comments
<!-- Simple Client Dashboard --><!-- Simple Client Dashboard PRO -->
Data Attributes
data-scd-setting-group
JS Globals
scd_settings
REST Endpoints
/wp-json/scd/v1/settings
FAQ

Frequently Asked Questions about Simple Client Dashboard