
Hide Dashboard Notifications Security & Risk Analysis
wordpress.org/plugins/wp-hide-backed-noticesWarnings and notices can be helpful for developers as they notify them for debugging issues with their code. Though these notices can be sometimes inf …
Is Hide Dashboard Notifications Safe to Use in 2026?
Generally Safe
Score 99/100Hide Dashboard Notifications has a strong security track record. Known vulnerabilities have been patched promptly.
The "wp-hide-backed-notices" v1.4.6 plugin presents a mixed security posture. On one hand, the static analysis reveals strong adherence to secure coding practices. There are no dangerous functions, all SQL queries are prepared, file operations and external HTTP requests are absent, and there's a single nonce check and capability check, indicating an effort to secure its limited entry points. The taint analysis also shows no critical or high severity issues related to unsanitized paths. However, the plugin's history of known vulnerabilities, specifically two medium severity CVEs related to Missing Authorization and Cross-Site Request Forgery (CSRF), is a significant concern. While currently unpatched CVEs are zero, the recurring presence of these vulnerability types suggests potential systemic weaknesses in how user input or actions are validated and authorized within the plugin's codebase. The presence of a shortcode as the sole entry point, while seemingly small, necessitates robust security checks, especially given the historical vulnerability patterns.
Despite the positive signs in static analysis, the vulnerability history cannot be ignored. The past occurrences of Missing Authorization and CSRF vulnerabilities indicate that while the current version might be clean, there's a higher likelihood of such issues re-emerging or being present in less thoroughly analyzed areas. The absence of critical or high severity taint flows is encouraging, but the past medium vulnerabilities suggest that potential flaws might exist that are not caught by the current taint analysis scope or have been fixed but highlight past shortcomings. Therefore, while the immediate code may appear relatively secure, the plugin's track record warrants caution and ongoing vigilance.
Key Concerns
- Two past medium severity CVEs (Missing Auth, CSRF)
- 61% of output escaping is not properly escaped
Hide Dashboard Notifications Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Hide Dashboard Notifications <= 1.3 - Missing Authorization to Authenticated(Contributor+) Plugin Settings Modification
Hide Dashboard Notifications <= 1.2.3 - Cross-Site Request Forgery
Hide Dashboard Notifications Code Analysis
Output Escaping
Data Flow Analysis
Hide Dashboard Notifications Attack Surface
Shortcodes 1
WordPress Hooks 10
Maintenance & Trust
Hide Dashboard Notifications Maintenance & Trust
Maintenance Signals
Community Trust
Hide Dashboard Notifications Alternatives
Hide Admin Notices
hide-admin-notices
Hide – or show – WordPress Dashboard Notices, Messages, Update Nags etc. ... for everything!
Disable Admin Dashboard Notices – Get a distraction free WordPress backend
disable-admin-dashboard-notices
"Disable Admin Dashboard Notices" is a handy WordPress plugin designed to streamline and enhance the user experience for WordPress website a …
Disable Admin Notices – Hide Dashboard Notifications
disable-admin-notices
Disable admin notices and hide dashboard notifications from plugins, themes and core. Hide all notices, selected ones, or show them in a single line.
Admin Notices Manager
admin-notices-manager
Better manage admin notices & never miss important developer messages!
Remove Admin Notices
remove-admin-notices
With this plugin you can remove all admin notices.
Hide Dashboard Notifications Developer Profile
4 plugins · 20K total installs
How We Detect Hide Dashboard Notifications
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-hide-backed-notices/admin/css/style.css/wp-content/plugins/wp-hide-backed-notices/admin/js/main.js/wp-content/plugins/wp-hide-backed-notices/admin/js/main.jswp-hide-backed-notices/admin/css/style.css?ver=wp-hide-backed-notices/admin/js/main.js?ver=HTML / DOM Fingerprints
hide-tablinks-noticeshide-tabcontent-noticescheckboxes-managesave_post_gallery_box_cls<!-- If this file is called directly, abort. -->data-tabopenSettings