Manage all your WordPress sites in one place - updates, uptime, backups & security.

1K active installs v5.5.4 PHP 7.4+ WP 4.9+ Updated Mar 2, 2026
backupdashboardmanagesecurityumbrella
88
A · Safe
CVEs total2
Unpatched0
Last CVEApr 7, 2026
Safety Verdict

Is iControlWP Safe to Use in 2026?

Generally Safe

Score 88/100

iControlWP has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

2 known CVEsLast CVE: Apr 7, 2026Updated 2mo ago
Risk Assessment

The "worpit-admin-dashboard-plugin" v5.5.4 exhibits a mixed security posture. On one hand, the static analysis reveals strong adherence to secure coding practices, with all SQL queries utilizing prepared statements, a high percentage of output escaping, and the presence of nonce and capability checks. Furthermore, the absence of any identified taint flows or dangerous functions suggests a well-sanitized codebase.

However, the plugin's vulnerability history is a significant concern. The presence of one critical vulnerability in the past, specifically related to "Deserialization of Untrusted Data," indicates a historical weakness that, while currently patched according to the data, warrants caution. The fact that this critical vulnerability was recent (2025-01-30) means that even if patched, it highlights a potential area of risk that may require ongoing scrutiny and robust security testing for future versions. The current lack of unpatched vulnerabilities is a positive sign, but the historical critical flaw should not be overlooked.

In conclusion, while the current version of the plugin demonstrates good internal security hygiene, the historical critical vulnerability casts a shadow. Users should remain vigilant for future updates and any emerging security advisories, given the potential for complex deserialization flaws to reappear in different forms.

Key Concerns

  • Historical critical vulnerability (Deserialization)
Vulnerabilities
2 published

iControlWP Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
1 CVE in 2026
2026
Patched Has unpatched

Severity Breakdown

Critical
2

2 total CVEs

CVE-2026-34901critical · 9.8Incorrect Privilege Assignment

iControlWP <= 5.5.3 - Unauthenticated Privilege Escalation

Apr 7, 2026 Patched in 5.5.4 (9d)
CVE-2024-13742critical · 9.8Deserialization of Untrusted Data

iControlWP – Multiple WordPress Site Manager <= 4.4.5 - Unauthenticated PHP Object Injection

Jan 30, 2025 Patched in 4.5.0 (2d)
Version History

iControlWP Release Timeline

v5.5.4Current
v5.5.31 CVE
v5.5.11 CVE
v5.5.01 CVE
v5.4.41 CVE
v5.4.31 CVE
v5.4.21 CVE
v5.4.11 CVE
v5.4.01 CVE
v5.3.61 CVE
v5.3.41 CVE
v5.3.31 CVE
v5.3.21 CVE
v5.3.01 CVE
v5.2.51 CVE
v5.2.31 CVE
v5.2.21 CVE
v5.2.11 CVE
v5.2.01 CVE
v5.1.31 CVE
Code Analysis
Analyzed Mar 16, 2026

iControlWP Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
3 prepared
Unescaped Output
4
101 escaped
Nonce Checks
1
Capability Checks
1
File Operations
1
External Requests
1
Bundled Libraries
0

SQL Query Safety

100% prepared3 total queries

Output Escaping

96% escaped105 total outputs
Attack Surface

iControlWP Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 16
actionadmin_noticessrc\common\wp-admin-notices.php:27
actionnetwork_admin_noticessrc\common\wp-admin-notices.php:28
actionwp_loadedsrc\common\wp-admin-notices.php:29
actionplugins_loadedsrc\features\base.php:72
actionwp_loadedsrc\features\plugin.php:20
filterauto_update_pluginsrc\processors\autoupdates.php:8
filterauto_update_themesrc\processors\autoupdates.php:9
filterwpss_misc_form_spam_check_bypasssrc\processors\compatibility.php:208
actionwpsrc\processors\google_analytics.php:11
actionwp_enqueue_scriptssrc\processors\google_analytics.php:19
actionwp_body_opensrc\processors\google_analytics.php:39
actioninitsrc\processors\plugin.php:15
filterodp-shield-2fa_skipsrc\processors\plugin_api_login.php:61
filteruser_has_capsrc\processors\security.php:10
filterplugin_row_metasrc\processors\whitelabel.php:7
actionadmin_noticesworpit.php:35
Maintenance & Trust

iControlWP Maintenance & Trust

Maintenance Signals

WordPress version tested7.0
Last updatedMar 2, 2026
PHP min version7.4
Downloads287K

Community Trust

Rating96/100
Number of ratings63
Active installs1K
Developer Profile

iControlWP Developer Profile

Paul

5 plugins · 141K total installs

71
trust score
Avg Security Score
88/100
Avg Patch Time
116 days
View full developer profile
Detection Fingerprints

How We Detect iControlWP

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/worpit-admin-dashboard-plugin/assets/css/bootstrap-wpadmin-fixes.css/wp-content/plugins/worpit-admin-dashboard-plugin/assets/css/bootstrap-wpadmin.css/wp-content/plugins/worpit-admin-dashboard-plugin/assets/css/plugin-admin.css/wp-content/plugins/worpit-admin-dashboard-plugin/assets/css/global-plugin.css
Version Parameters
worpit-admin-dashboard-plugin/assets/css/bootstrap-wpadmin-fixes.css?ver=worpit-admin-dashboard-plugin/assets/css/bootstrap-wpadmin.css?ver=worpit-admin-dashboard-plugin/assets/css/plugin-admin.css?ver=worpit-admin-dashboard-plugin/assets/css/global-plugin.css?ver=

HTML / DOM Fingerprints

CSS Classes
icwp-admin-menu-pageicwp-admin-page-headericwp-admin-mainicwp-admin-main-contenticwp-admin-main-content-area
Data Attributes
data-plugin-slug
JS Globals
icwp_vars
FAQ

Frequently Asked Questions about iControlWP