
WP AdminTools Security & Risk Analysis
wordpress.org/plugins/wp-admintoolsControl additional Wordpress, SEO and Database features with this swiss army knife for WordPress.
Is WP AdminTools Safe to Use in 2026?
Generally Safe
Score 85/100WP AdminTools has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-admintools" plugin version 1.3.9 exhibits a generally good security posture with no recorded vulnerabilities in its history. The static analysis shows no identified CVEs, and the code demonstrates strong practices in areas like SQL query preparation, with all queries utilizing prepared statements. Furthermore, the plugin avoids external HTTP requests and file operations, reducing potential attack vectors. The presence of nonce and capability checks, although modest in number, indicates an awareness of WordPress security mechanisms.
However, a significant concern arises from the use of the `create_function` PHP function, which is considered deprecated and insecure due to its inherent risks of code injection if not handled with extreme caution. While the taint analysis did not reveal any unsanitized paths, the mere presence of `create_function` is a red flag. Additionally, the static analysis highlights a severe deficiency in output escaping, with only 1% of outputs being properly escaped. This could lead to Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the website's content or administration area.
In conclusion, while "wp-admintools" benefits from a clean vulnerability history and secure SQL handling, the critical issues of extensive unescaped output and the use of `create_function` introduce significant security risks. Addressing these specific coding practices is paramount to improving the plugin's overall security and preventing potential XSS and code execution vulnerabilities.
Key Concerns
- Extensive unescaped output (99%)
- Use of dangerous function: create_function
WP AdminTools Security Vulnerabilities
WP AdminTools Release Timeline
WP AdminTools Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
WP AdminTools Attack Surface
WordPress Hooks 20
Maintenance & Trust
WP AdminTools Maintenance & Trust
Maintenance Signals
Community Trust
WP AdminTools Alternatives
Advanced Database Cleaner – Optimize & Clean Database to Speed Up Site Performance
advanced-database-cleaner
Clean database by deleting orphaned data such as 'revisions', 'expired transients', optimize database and more...
WP Bulk Delete
wp-bulk-delete
Delete posts, pages, comments, users, taxonomy terms and meta fields in bulk with different powerful filters and conditions.
Optimize Database after Deleting Revisions
rvg-optimize-database
One-click database optimization with precise revision cleanup and flexible scheduling. Speeding up sites since 2011!
BoldGrid Easy SEO – Simple and Effective SEO
boldgrid-easy-seo
Easy SEO helps you easily create keyword rich content and rank higher in the search engines.
Bulk Delete
bulk-delete
Bulk delete posts, pages, users, attachments, and meta fields based on complex bulk conditions & filters.
WP AdminTools Developer Profile
1 plugin · 100 total installs
How We Detect WP AdminTools
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-admintools/css/style.css/wp-content/plugins/wp-admintools/css/style.min.css/wp-content/plugins/wp-admintools/js/script.js/wp-content/plugins/wp-admintools/js/script.min.jswp-admintools/style.css?ver=wp-admintools/script.js?ver=HTML / DOM Fingerprints
window.sisat_settings