WP Custom Admin Dashboard Security & Risk Analysis

wordpress.org/plugins/wp-custom-admin-dashboard

Custom Admin Dashboard Plugin Description A basic All-in-one plugin that allows users to customize the Wordpress Administration dashboard.

50 active installs v1.2 PHP + WP 3.1.0+ Updated Unknown
custom-admincustom-dashboardcustomizerdashboard-customizerwp-dashboard-customize
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is WP Custom Admin Dashboard Safe to Use in 2026?

Generally Safe

Score 100/100

WP Custom Admin Dashboard has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The wp-custom-admin-dashboard plugin v1.2 exhibits a generally good security posture with no known vulnerabilities or critical findings in static analysis or taint flows. The absence of dangerous functions, file operations, external HTTP requests, and raw SQL queries, combined with the use of prepared statements, is highly commendable. The presence of a nonce check on one of the two AJAX handlers further strengthens its defenses. However, a significant concern arises from the complete lack of output escaping across all identified outputs. This leaves the plugin vulnerable to Cross-Site Scripting (XSS) attacks, as any user-controlled data that makes its way into these outputs could be maliciously crafted. While the attack surface is small and has no unprotected entry points, the universal lack of output escaping represents a critical oversight that undermines otherwise robust security practices.

Key Concerns

  • All outputs unescaped
Vulnerabilities
None known

WP Custom Admin Dashboard Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP Custom Admin Dashboard Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
32
0 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped32 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
cad_reset_settings (includes\ajax\ajax.php:20)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

WP Custom Admin Dashboard Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_cad_reset_settingsincludes\ajax\ajax.php:18
noprivwp_ajax_cad_reset_settingsincludes\ajax\ajax.php:19
WordPress Hooks 31
actionlogin_enqueue_scriptsincludes\main\main-functions.php:33
actionlogin_enqueue_scriptsincludes\main\main-functions.php:56
filterlogin_headerurlincludes\main\main-functions.php:70
filterlogin_headertitleincludes\main\main-functions.php:84
actionlogin_enqueue_scriptsincludes\main\main-functions.php:104
filterlogin_messageincludes\main\main-functions.php:122
actionlogin_enqueue_scriptsincludes\main\main-functions.php:142
actionlogin_enqueue_scriptsincludes\main\main-functions.php:172
filtercontextual_helpincludes\main\main-functions.php:188
filterscreen_options_show_screenincludes\main\main-functions.php:197
actionload-index.phpincludes\main\main-functions.php:207
actionwp_dashboard_setupincludes\main\main-functions.php:231
actionwp_dashboard_setupincludes\main\main-functions.php:248
actionwp_dashboard_setupincludes\main\main-functions.php:264
actionwp_dashboard_setupincludes\main\main-functions.php:280
actionwp_dashboard_setupincludes\main\main-functions.php:295
actionadmin_menuincludes\main\main-functions.php:302
actionwp_dashboard_setupincludes\main\main-functions.php:316
actionwp_before_admin_bar_renderincludes\main\main-functions.php:332
actionwp_before_admin_bar_renderincludes\main\main-functions.php:348
actionwp_before_admin_bar_renderincludes\main\main-functions.php:363
filteradmin_bar_menuincludes\main\main-functions.php:382
filteradmin_footer_textincludes\main\main-functions.php:394
actionadmin_initincludes\main\main-functions.php:402
filteradmin_footer_textincludes\main\main-functions.php:413
actionadmin_initincludes\main\main-functions.php:421
actionadmin_menuincludes\main\main-functions.php:435
actionadmin_menuincludes\options\options-functions.php:29
actionadmin_initincludes\options\options-functions.php:451
actionadmin_enqueue_scriptsincludes\src\src-functions.php:19
actionadmin_enqueue_scriptsincludes\src\src-functions.php:40
Maintenance & Trust

WP Custom Admin Dashboard Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedUnknown
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs50
Developer Profile

WP Custom Admin Dashboard Developer Profile

inceva

1 plugin · 50 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP Custom Admin Dashboard

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-custom-admin-dashboard/includes/src/css/styles.css/wp-content/plugins/wp-custom-admin-dashboard/includes/src/libraries/spectrum/spectrum.css/wp-content/plugins/wp-custom-admin-dashboard/includes/src/libraries/spectrum/spectrum.js/wp-content/plugins/wp-custom-admin-dashboard/includes/src/libraries/switchery/switchery.min.css/wp-content/plugins/wp-custom-admin-dashboard/includes/src/libraries/switchery/switchery.min.js/wp-content/plugins/wp-custom-admin-dashboard/includes/src/js/scripts.js
Script Paths
/wp-content/plugins/wp-custom-admin-dashboard/includes/src/libraries/spectrum/spectrum.js/wp-content/plugins/wp-custom-admin-dashboard/includes/src/libraries/switchery/switchery.min.js/wp-content/plugins/wp-custom-admin-dashboard/includes/src/js/scripts.js
Version Parameters
wp-custom-admin-dashboard/includes/src/css/styles.css?ver=wp-custom-admin-dashboard/includes/src/libraries/spectrum/spectrum.css?ver=wp-custom-admin-dashboard/includes/src/libraries/spectrum/spectrum.js?ver=wp-custom-admin-dashboard/includes/src/libraries/switchery/switchery.min.css?ver=wp-custom-admin-dashboard/includes/src/libraries/switchery/switchery.min.js?ver=wp-custom-admin-dashboard/includes/src/js/scripts.js?ver=

HTML / DOM Fingerprints

CSS Classes
cad_login_custom_message
HTML Comments
<!--Plugin Name: WP Custom Admin Dashboard--><!--Version: 1.2--><!--Author: Inceva--><!--Author URI: https://www.inceva.co.th -->+32 more
JS Globals
plugin_obj
FAQ

Frequently Asked Questions about WP Custom Admin Dashboard