WP Admin UI Customize Security & Risk Analysis

wordpress.org/plugins/wp-admin-ui-customize

Customize the management screen UI.

30K active installs v1.5.14 PHP + WP 4.2+ Updated Nov 20, 2024
adminoptionpagepostposts
91
A · Safe
CVEs total2
Unpatched0
Last CVENov 26, 2024
Safety Verdict

Is WP Admin UI Customize Safe to Use in 2026?

Generally Safe

Score 91/100

WP Admin UI Customize has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

2 known CVEsLast CVE: Nov 26, 2024Updated 1yr ago
Risk Assessment

The "wp-admin-ui-customize" v1.5.14 plugin presents a generally strong security posture with no critical or high-severity vulnerabilities identified in the static analysis. The absence of any direct entry points like AJAX handlers, REST API routes, or shortcodes significantly reduces the attack surface. Furthermore, the code demonstrates good practices by utilizing prepared statements for all SQL queries, performing output escaping on a high percentage of outputs, and including nonce and capability checks. There are also no identified dangerous functions, file operations, or external HTTP requests, which are positive indicators.

However, the plugin's vulnerability history reveals two medium-severity Common Vulnerabilities and Exposures (CVEs), both of which are historical and currently unpatched. The common vulnerability type being Cross-Site Scripting (XSS) suggests a past tendency for improper input sanitization. While the current version does not exhibit these issues according to the static analysis, the historical pattern warrants caution. The fact that two medium vulnerabilities have occurred, even if patched in later versions not analyzed here, indicates potential for such issues to arise, especially concerning input handling.

In conclusion, the static analysis indicates a secure current version of the plugin with minimal direct attack vectors. The extensive use of security best practices like prepared statements and output escaping is commendable. The primary concern stems from the historical vulnerability data, specifically the presence of two medium-severity XSS vulnerabilities in the past. While these are not present in the analyzed version, they highlight areas where the plugin may have required hardening. Users should ensure they are on the latest version of the plugin and monitor for any future security advisories.

Key Concerns

  • Historical unpatched medium CVEs
  • Historical XSS vulnerability pattern
Vulnerabilities
2 published

WP Admin UI Customize Security Vulnerabilities

CVEs by Year

1 CVE in 2022
2022
1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2024-53278medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

WP Admin UI Customize <= 1.5.13 - Authenticated (Admin+) Stored Cross-Site Scripting

Nov 26, 2024 Patched in 1.5.14 (17d)
CVE-2022-3824medium · 5.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

WP Admin UI Customize <= 1.5.12 - Authenticated (Administrator+) Cross-Site Scripting

Nov 6, 2022 Patched in 1.5.13 (443d)
Version History

WP Admin UI Customize Release Timeline

Code Analysis
Analyzed Mar 16, 2026

WP Admin UI Customize Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
97
403 escaped
Nonce Checks
13
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

81% escaped500 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

14 flows
update_reset (wp-admin-ui-customize.php:1403)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

WP Admin UI Customize Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 40
actionplugins_loadedwp-admin-ui-customize.php:104
filterplugin_action_linkswp-admin-ui-customize.php:107
filternetwork_admin_plugin_action_linkswp-admin-ui-customize.php:110
actionadmin_menuwp-admin-ui-customize.php:113
actionadmin_noticeswp-admin-ui-customize.php:116
actionwp_loadedwp-admin-ui-customize.php:119
actionadmin_initwp-admin-ui-customize.php:122
actionwp_before_admin_bar_renderwp-admin-ui-customize.php:125
actionadmin_menuwp-admin-ui-customize.php:128
actionadmin_headwp-admin-ui-customize.php:131
actionwp_dashboard_setupwp-admin-ui-customize.php:134
actionwp_loadedwp-admin-ui-customize.php:1736
filterlogin_headerurlwp-admin-ui-customize.php:1737
filterlogin_headertitlewp-admin-ui-customize.php:1738
actionlogin_headwp-admin-ui-customize.php:1739
actionlogin_footerwp-admin-ui-customize.php:1740
actionwp_loadedwp-admin-ui-customize.php:1743
actionwp_loadedwp-admin-ui-customize.php:1749
actionwp_before_admin_bar_renderwp-admin-ui-customize.php:1767
actionwp_loadedwp-admin-ui-customize.php:1768
actionadmin_headwp-admin-ui-customize.php:1769
filteradmin_footer_textwp-admin-ui-customize.php:1770
actionadmin_print_styleswp-admin-ui-customize.php:1771
actionwp_dashboard_setupwp-admin-ui-customize.php:1772
actionadmin_headwp-admin-ui-customize.php:1773
filteradmin_headwp-admin-ui-customize.php:1774
filterget_sample_permalink_htmlwp-admin-ui-customize.php:1775
filteredit_form_after_titlewp-admin-ui-customize.php:1776
actionadmin_print_styles-nav-menus.phpwp-admin-ui-customize.php:1777
filteradmin_titlewp-admin-ui-customize.php:1778
actionadmin_footerwp-admin-ui-customize.php:1779
actionwp_footerwp-admin-ui-customize.php:1799
actionwp_loadedwp-admin-ui-customize.php:1800
filtershow_admin_barwp-admin-ui-customize.php:1806
actionwp_before_admin_bar_renderwp-admin-ui-customize.php:1808
filterupdate_footerwp-admin-ui-customize.php:2232
filtersite_transient_update_corewp-admin-ui-customize.php:2233
filtersite_transient_update_pluginswp-admin-ui-customize.php:2237
filtersite_transient_update_themeswp-admin-ui-customize.php:2240
filterscreen_options_show_screenwp-admin-ui-customize.php:2289
Maintenance & Trust

WP Admin UI Customize Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedNov 20, 2024
PHP min version
Downloads391K

Community Trust

Rating92/100
Number of ratings59
Active installs30K
Developer Profile

WP Admin UI Customize Developer Profile

gqevu6bsiz

12 plugins · 47K total installs

70
trust score
Avg Security Score
87/100
Avg Patch Time
183 days
View full developer profile
Detection Fingerprints

How We Detect WP Admin UI Customize

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-admin-ui-customize/css/admin.css/wp-content/plugins/wp-admin-ui-customize/css/admin-bar.css/wp-content/plugins/wp-admin-ui-customize/css/dashboard.css/wp-content/plugins/wp-admin-ui-customize/css/login.css/wp-content/plugins/wp-admin-ui-customize/css/post.css/wp-content/plugins/wp-admin-ui-customize/css/site.css/wp-content/plugins/wp-admin-ui-customize/css/welcome.css/wp-content/plugins/wp-admin-ui-customize/js/admin.js+6 more
Script Paths
/wp-content/plugins/wp-admin-ui-customize/js/admin.js/wp-content/plugins/wp-admin-ui-customize/js/admin-bar.js/wp-content/plugins/wp-admin-ui-customize/js/dashboard.js/wp-content/plugins/wp-admin-ui-customize/js/login.js/wp-content/plugins/wp-admin-ui-customize/js/post.js/wp-content/plugins/wp-admin-ui-customize/js/site.js+1 more
Version Parameters
wp-admin-ui-customize/css/admin.css?ver=wp-admin-ui-customize/css/admin-bar.css?ver=wp-admin-ui-customize/css/dashboard.css?ver=wp-admin-ui-customize/css/login.css?ver=wp-admin-ui-customize/css/post.css?ver=wp-admin-ui-customize/css/site.css?ver=wp-admin-ui-customize/css/welcome.css?ver=wp-admin-ui-customize/js/admin.js?ver=wp-admin-ui-customize/js/admin-bar.js?ver=wp-admin-ui-customize/js/dashboard.js?ver=wp-admin-ui-customize/js/login.js?ver=wp-admin-ui-customize/js/post.js?ver=wp-admin-ui-customize/js/site.js?ver=wp-admin-ui-customize/js/welcome.js?ver=

HTML / DOM Fingerprints

CSS Classes
wauc_user_role_settingwauc_site_settingwauc_admin_general_settingwauc_dashboard_settingwauc_regist_dashboard_metaboxwauc_admin_bar_menu_settingwauc_sidemenu_settingwauc_manage_metabox_setting+5 more
Data Attributes
data-wauc-plugin-slugdata-wauc-current-plugin-slug
JS Globals
wauc_admin_optionswauc_admin_color_optionswauc_admin_customizewauc_customize_sitewauc_customize_dashboard
FAQ

Frequently Asked Questions about WP Admin UI Customize