
WPShapere Lite Security & Risk Analysis
wordpress.org/plugins/wpshapere-liteWPShapere is a WordPress plugin to customize the WordPress Admin theme and elements as your wish.
Is WPShapere Lite Safe to Use in 2026?
Mostly Safe
Score 78/100WPShapere Lite is generally safe to use. 1 past CVE were resolved.
The "wpshapere-lite" v1.4.1 plugin exhibits a mixed security posture. On the positive side, the static analysis reveals a remarkably small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events that are exposed without authentication or permission checks. Furthermore, all SQL queries are securely handled using prepared statements, and there are no file operations or external HTTP requests that pose an immediate threat. The presence of nonce and capability checks, though limited, is a good practice.
However, significant concerns arise from the presence of dangerous functions, specifically `unserialize`, which is often a precursor to deserialization vulnerabilities if user-controlled data is involved. The low percentage of properly escaped output (8%) is a critical weakness, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities, especially since the taint analysis found no unsanitized paths, suggesting the vulnerability might be in how data is handled *after* reaching an entry point or within the unescaped outputs themselves. The vulnerability history further reinforces these concerns, with one unpatched medium-severity CVE indicating a past issue that has not been remediated.
In conclusion, while the plugin's attack surface is commendably small and its SQL handling is robust, the reliance on `unserialize` and the widespread lack of output escaping, coupled with an unpatched CVE, present substantial security risks. Users should be aware of the potential for XSS and deserialization vulnerabilities, and the need for immediate patching or mitigation of the existing CVE is paramount.
Key Concerns
- Unpatched CVE exists (medium severity)
- High percentage of unescaped output (8%)
- Presence of dangerous function (unserialize)
WPShapere Lite Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WPShapere - WordPress admin theme <= 1.4.1 - Cross-Site Request Forgery
WPShapere Lite Release Timeline
WPShapere Lite Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
WPShapere Lite Attack Surface
WordPress Hooks 41
Maintenance & Trust
WPShapere Lite Maintenance & Trust
Maintenance Signals
Community Trust
WPShapere Lite Alternatives
Slate Admin Theme
slate-admin-theme
A clean, simplified WordPress Admin theme.
Clean WP Admin Theme – Simple design
wp-clean-admin-theme
Beautiful design for WP Admin, Clean Admin Theme for wp-admin.
Webseo Admin Theme
webseo-admin-theme
Webseo provides a clean, simplified design for your WordPress Admin area.
Cool Admin Theme Lite for WP
cool-admin-theme-lite-for-wp
Use the Cool Admin Theme Lite for WP to make your administration area cleaner, more fresh and cool, ofcourse.
Aquila Admin Theme
aquila-admin-theme
Material Design inspired admin theme with a customisable color scheme. Add your own custom logo to match your website.
WPShapere Lite Developer Profile
3 plugins · 330 total installs
How We Detect WPShapere Lite
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpshapere-lite/assets/css/default/wp-content/plugins/wpshapere-lite/assets/css/pomegranate/wp-content/plugins/wpshapere-lite/assets/css/black-white/wp-content/plugins/wpshapere-lite/assets/css/beach/wp-content/plugins/wpshapere-lite/assets/css/africa/wp-content/plugins/wpshapere-lite/assets/js/loginjs.jswpshapere-lite/assets/css/default?ver=wpshapere-lite/assets/css/pomegranate?ver=wpshapere-lite/assets/css/black-white?ver=wpshapere-lite/assets/css/beach?ver=wpshapere-lite/assets/css/africa?ver=wpshapere-lite/assets/js/loginjs.js?ver=HTML / DOM Fingerprints
wps-login-containerwps-login-bgwps-icon-loginwps-icon-emailwps-icon-pwdwps_kb_linkWPSHAPERE