WP Dash Message Security & Risk Analysis

wordpress.org/plugins/wp-dash-message

Add a welcome message dashboard widget and remove any WordPress dashboard widgets with this plugin.

300 active installs v1.1.2 PHP + WP 3.1.3+ Updated Dec 22, 2011
dashdashboarddashboard-widgetwelcomewidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is WP Dash Message Safe to Use in 2026?

Generally Safe

Score 85/100

WP Dash Message has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 14yr ago
Risk Assessment

The wp-dash-message v1.1.2 plugin exhibits a generally strong security posture based on the static analysis, with no apparent direct attack vectors through common entry points like AJAX handlers, REST API, or shortcodes. The complete absence of dangerous functions, file operations, and external HTTP requests is also a positive indicator. Furthermore, all SQL queries utilize prepared statements, and the plugin has no recorded vulnerability history, suggesting a potentially well-maintained and secure codebase.

However, a significant concern arises from the complete lack of proper output escaping across all 13 identified output points. This represents a critical weakness that could lead to cross-site scripting (XSS) vulnerabilities if malicious data were to be introduced into these outputs. While the plugin does have one capability check, the absence of nonce checks on any potential (though not identified) entry points and the overall lack of taint flow analysis leave room for undiscovered vulnerabilities. The lack of recorded vulnerabilities could also be due to the plugin's obscurity or a lack of in-depth security auditing in the past.

In conclusion, while the plugin's architecture appears robust with no immediately exploitable direct entry points and secure database practices, the pervasive issue of unescaped output presents a substantial risk. This oversight could be exploited to inject malicious scripts, compromising user sessions or data. The absence of further security measures like nonce checks and the limited scope of the taint analysis, despite the lack of history, means caution is still warranted.

Key Concerns

  • All outputs are unescaped
Vulnerabilities
None known

WP Dash Message Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP Dash Message Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
13
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped13 total outputs
Attack Surface

WP Dash Message Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionadmin_menuwp-dash-message.php:79
actionwpmu_optionswp-dash-message.php:82
actionupdate_wpmu_optionswp-dash-message.php:85
actionadmin_initwp-dash-message.php:88
actionwp_dashboard_setupwp-dash-message.php:91
actionwp_network_dashboard_setupwp-dash-message.php:94
actionwp_user_dashboard_setupwp-dash-message.php:97
actionwp_dashboard_setupwp-dash-message.php:109
actionwp_user_dashboard_setupwp-dash-message.php:112
Maintenance & Trust

WP Dash Message Maintenance & Trust

Maintenance Signals

WordPress version tested3.3.2
Last updatedDec 22, 2011
PHP min version
Downloads10K

Community Trust

Rating100/100
Number of ratings2
Active installs300
Developer Profile

WP Dash Message Developer Profile

Aleksandar Arsovski

3 plugins · 350 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP Dash Message

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-dash-message/css/style.css/wp-content/plugins/wp-dash-message/js/script.js
Script Paths
/wp-content/plugins/wp-dash-message/js/script.js
Version Parameters
wp-dash-message/style.css?ver=wp-dash-message/js/script.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about WP Dash Message