Dashboard Beacon Security & Risk Analysis
wordpress.org/plugins/wp-dashboard-beaconEasily integrate a Help Scout beacon in your site's dashboard.
Is Dashboard Beacon Safe to Use in 2026?
Mostly Safe
Score 78/100Dashboard Beacon is generally safe to use. 1 past CVE were resolved. Keep it updated.
The wp-dashboard-beacon plugin v1.2.0 presents a mixed security posture. On the positive side, the static analysis reveals no identified dangerous functions, no direct SQL queries outside of prepared statements, and a complete absence of file operations or external HTTP requests. The attack surface is reported as zero entry points, and importantly, zero unprotected entry points, suggesting a generally secure design in these areas. However, a significant concern arises from the low rate of output escaping (27%), indicating a high likelihood of cross-site scripting (XSS) vulnerabilities, especially when considering the plugin's vulnerability history. The absence of nonce and capability checks on the identified entry points is also a notable weakness, despite the zero count, as it suggests a lack of built-in protective measures for potential future entry points.
Key Concerns
- Unpatched CVEs
- Low output escaping percentage
- No nonce checks
- No capability checks
Dashboard Beacon Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Dashboard Beacon <= 1.2.0 - Authenticated (Administrator+) Stored Cross-Site Scripting
Dashboard Beacon Code Analysis
Output Escaping
Dashboard Beacon Attack Surface
WordPress Hooks 8
Maintenance & Trust
Dashboard Beacon Maintenance & Trust
Maintenance Signals
Community Trust
Dashboard Beacon Alternatives
WP Dash Support
wp-dash-support
A plugin that adds a contact form on the dashboard for developers to use to give clients an easier way to contact them.
Display PHP Version
display-php-version
Displays the currently installed PHP/MySQL version in the "At a Glance" admin dashboard widget.
WP Help
wp-help
Site operators can create detailed, hierarchical documentation for the site's authors, editors, and contributors, viewable in the WordPress admin …
WP Client Reports
wp-client-reports
The best maintenance reporting tool for WordPress professionals. Display update statistics directly in the WordPress admin or send reports via email.
WP PHP Version Display
wp-php-version-display
Displays the current running PHP/MySQL version inside "At a Glance" admin dashboard widget.
Dashboard Beacon Developer Profile
3 plugins · 50 total installs
How We Detect Dashboard Beacon
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-dashboard-beacon/admin/css/wp-dashboard-beacon-admin.css/wp-content/plugins/wp-dashboard-beacon/admin/js/wp-dashboard-beacon-beacon.jswp-dashboard-beacon-admin.css?ver=wp-dashboard-beacon-beacon.js?ver=HTML / DOM Fingerprints
hsb_allowed_user_roleshsb_helpscout_form_idhsb_helpscout_subdomainhsb_beacon_optionshsb_beacon_iconhsb_beacon_colour+3 morehsb_settings