
WP Dev Dashboard Security & Risk Analysis
wordpress.org/plugins/wp-dev-dashboardThe better tool for monitoring your plugins & themes, including support requests, download stats, version support, and more.
Is WP Dev Dashboard Safe to Use in 2026?
Generally Safe
Score 85/100WP Dev Dashboard has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-dev-dashboard plugin, in version 1.4, presents a mixed security posture. On the positive side, it avoids dangerous functions, uses prepared statements for all SQL queries, and has no recorded vulnerability history, suggesting a generally cautious development approach. However, significant security concerns arise from the static analysis. The presence of one unprotected AJAX handler is a critical finding, as it represents a direct entry point for attackers without any authentication or authorization checks. Furthermore, the low percentage of properly escaped output (5%) indicates a high risk of cross-site scripting (XSS) vulnerabilities, as user-supplied data is likely being rendered directly in the browser without adequate sanitization. Taint analysis also reveals flows with unsanitized paths, hinting at potential issues with how data is handled, even if not immediately classified as critical or high severity in the provided metrics. The absence of nonce checks and capability checks on the AJAX handler further exacerbates the risk, leaving it vulnerable to CSRF and unauthorized actions.
In conclusion, while the plugin demonstrates good practices in areas like SQL querying and has a clean vulnerability history, the unprotected AJAX handler and widespread output escaping deficiencies are serious weaknesses. These flaws create a significant attack surface that could be exploited for various malicious purposes, including unauthorized data modification, information disclosure, or XSS attacks. Developers should prioritize addressing the unprotected AJAX handler and implementing robust output escaping mechanisms throughout the plugin to improve its overall security.
Key Concerns
- Unprotected AJAX handler
- Low percentage of properly escaped output
- No nonce checks on AJAX
- No capability checks on AJAX
- Taint flows with unsanitized paths
WP Dev Dashboard Security Vulnerabilities
WP Dev Dashboard Code Analysis
Output Escaping
Data Flow Analysis
WP Dev Dashboard Attack Surface
AJAX Handlers 1
WordPress Hooks 5
Maintenance & Trust
WP Dev Dashboard Maintenance & Trust
Maintenance Signals
Community Trust
WP Dev Dashboard Alternatives
Any Mobile Theme Switcher
any-mobile-theme-switcher
This Plugin detects mobile browser and display the theme as the setting done from admin. Usefull for switch to Mobile Theme.
Disable WP Notification
disable-wp-notification
Best wordpress plugin to remove all the admin panel notifications in just one click. Including the theme and plugin update notification.
Disable Auto Update Emails and Block Updates for Plugins, WP Core, and Themes
disable-email-notification-for-auto-updates
This plugin disables email notifications for auto-updates and blocks updates for specific plugins, hide plugins, WordPress core, and themes.
WpRedesigned – Beautiful Custom Admin Theme
wpredesigned-beautiful-custom-admin-theme
Beautify your WordPress admin :)
Markdown Editor (Formerly Dark Mode)
dark-mode
Quickly edit content in your WordPress site by getting an immersive, peaceful and natural writing experience with the coolest editor.
WP Dev Dashboard Developer Profile
5 plugins · 71K total installs
How We Detect WP Dev Dashboard
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-dev-dashboard/css/wp-dev-dashboard-admin.css/wp-content/plugins/wp-dev-dashboard/js/wp-dev-dashboard-admin.js/wp-content/plugins/wp-dev-dashboard/js/wp-dev-dashboard-admin.jswp-dev-dashboard/css/wp-dev-dashboard-admin.css?ver=wp-dev-dashboard/js/wp-dev-dashboard-admin.js?ver=HTML / DOM Fingerprints
wpdd-settings-tabsTO DO
Add refresh button at top of list as well as bottom.
Consider adding list table for sortable plugin/theme view.
Make metabox plugin [count] reflect unresolved and resolved accordingly when switching setting.
Add link to main forum for plugin/theme.
Integrate github issues.
Initialize the class and set its properties.Creates or returns an instance of this class.The code that runs during plugin activation.+2 moredata-tab-namewpddSettings