
wp-admin classic Security & Risk Analysis
wordpress.org/plugins/wp-admin-classicClassic WordPress Admin theme (prior 3.8 style).
Is wp-admin classic Safe to Use in 2026?
Generally Safe
Score 85/100wp-admin classic has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-admin-classic" v1.0.8 plugin demonstrates a strong security posture based on the provided static analysis and vulnerability history. The absence of any identified attack surface points, dangerous functions, or critical taint flows is highly positive. The code also shows good practices, with 100% of SQL queries utilizing prepared statements and a single capability check present, indicating an attempt to secure administrative functions. The plugin has no recorded vulnerability history, including CVEs, which suggests a stable and well-maintained codebase.
However, there are areas for improvement that introduce minor risks. A significant portion of the output (33%) is not properly escaped, which could lead to Cross-Site Scripting (XSS) vulnerabilities if the unescaped output contains user-supplied data. Furthermore, the complete lack of nonce checks, while not directly indicated as an issue due to the absence of AJAX handlers, is a general best practice for preventing Cross-Site Request Forgery (CSRF) in WordPress plugins. The plugin's minimal attack surface and lack of critical findings are strengths, but the unescaped output represents a tangible, albeit potentially low-impact, risk.
Key Concerns
- Unescaped output detected
- No nonce checks implemented
wp-admin classic Security Vulnerabilities
wp-admin classic Code Analysis
Output Escaping
wp-admin classic Attack Surface
WordPress Hooks 9
Maintenance & Trust
wp-admin classic Maintenance & Trust
Maintenance Signals
Community Trust
wp-admin classic Alternatives
Redux Framework
redux-framework
Redux is a simple, truly extensible, and fully responsive options framework for WordPress themes and plugins. It ships with an integrated demo.
All In One Favicon
all-in-one-favicon
Easily add a Favicon to your site and the WordPress admin pages. Complete with upload functionality. Supports all three Favicon types (ico,png,gif).
Cryout Serious Theme Settings
cryout-theme-settings
This plugin is designed to inter-operate with our Mantra, Parabola, Tempera, Nirvana themes to enable their settings pages.
WP Updates Notifier
wp-updates-notifier
Sends email to notify you if there are any updates for your WordPress site. Can notify about core, plugin and theme updates.
Add Admin CSS
add-admin-css
Easily define additional CSS (inline and/or by URL) to be added to all administration pages.
wp-admin classic Developer Profile
3 plugins · 40 total installs
How We Detect wp-admin classic
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-admin-classic/wp-admin-css/wp-admin.min.css/wp-content/plugins/wp-admin-classic/wp-admin-css/ie.min.css/wp-content/plugins/wp-admin-classic/wp-includes-css/buttons.min.css/wp-content/plugins/wp-admin-classic/wp-admin-css/colors-classic.min.css/wp-content/plugins/wp-admin-classic/wp-admin-css/colors-fresh.min.css/wp-content/plugins/wp-admin-classic/wp-includes-css/editor.min.css/wp-content/plugins/wp-admin-classic/wp-admin-css/media.min.css/wp-content/plugins/wp-admin-classic/wp-includes-css/media-views.min.css+1 moreHTML / DOM Fingerprints
<select name="wp_admin_class_color_scheme" id="wp_admin_class_color_scheme">