
WP Tidy Dashboard Widgets Security & Risk Analysis
wordpress.org/plugins/wp-tidy-dashboard-widgetsLets you selectively tidy up the WordPress dashboard widgets for all users.
Is WP Tidy Dashboard Widgets Safe to Use in 2026?
Generally Safe
Score 85/100WP Tidy Dashboard Widgets has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-tidy-dashboard-widgets" v1.0 plugin exhibits a generally good security posture with no reported vulnerabilities in its history and a clean taint analysis. The static analysis reveals a very limited attack surface with no exposed AJAX handlers, REST API routes, shortcodes, or cron events, and importantly, none of these entry points lack authentication or permission checks. The absence of dangerous functions, file operations, and external HTTP requests further contributes to a robust security profile. The plugin also exclusively uses prepared statements for its SQL queries, which is a strong security practice.
However, a significant concern arises from the output escaping. With 2 total outputs and 0% properly escaped, this indicates a potential for cross-site scripting (XSS) vulnerabilities. Any dynamic data displayed by the plugin that is not properly escaped could be exploited by attackers. Furthermore, the complete lack of nonce checks and capability checks across any potential entry points, while currently theoretical given the zero entry points, leaves the plugin vulnerable if its attack surface were to expand in future versions or through misconfiguration.
In conclusion, while the plugin's current design and historical record are commendable, the lack of output escaping is a critical weakness that needs immediate attention. The absence of known vulnerabilities and a small attack surface are strengths, but the unescaped output represents a tangible risk that could be exploited. It is crucial for developers to address this output escaping issue to prevent potential security breaches.
Key Concerns
- 0% output escaping
- No nonce checks
- No capability checks
WP Tidy Dashboard Widgets Security Vulnerabilities
WP Tidy Dashboard Widgets Code Analysis
Output Escaping
WP Tidy Dashboard Widgets Attack Surface
WordPress Hooks 3
Maintenance & Trust
WP Tidy Dashboard Widgets Maintenance & Trust
Maintenance Signals
Community Trust
WP Tidy Dashboard Widgets Alternatives
Widget Disable
wp-widget-disable
Disable sidebar and dashboard widgets with an easy to use interface.
Dashboard Commander
dashboard-commander
Command your admin dashboard. Manage built-in widgets and dynamically registered widgets. Hide widgets depending upon user capabilities.
Dashboard Widget Sidebar
dashboard-widget-sidebar
Enable regulare widgets to be used as Dashboard Widgets in admin.
ABD Dashboard Widget Manager
abd-dashboard-widget-manager
Customize your WordPress administrator dashboard. You can choose which admin widgets to display, the user roles, and add your own dashboard content.
Right Now Reloaded
right-now-reloaded
A more relevant and dynamic version of the "Right Now" dashboard widget.
WP Tidy Dashboard Widgets Developer Profile
4 plugins · 810 total installs
How We Detect WP Tidy Dashboard Widgets
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-tidy-dashboard-widgets/tidy-dashboard-widgets.phpwp-tidy-dashboard-widgets/tidy-dashboard-widgets.php?ver=HTML / DOM Fingerprints
Plugin Name: Tidy Dashboard WidgetsPlugin URI: http://www.stormconsultancy.co.ukDescription: Lets you select widgets to remove from the dashboardVersion: 1.0+7 more