
KDC Dashboard Security & Risk Analysis
wordpress.org/plugins/ws-dashKRAZY DEVIL CREATIONZ - Always a part of eYou : A client dashboard for KDC clients.
Is KDC Dashboard Safe to Use in 2026?
Generally Safe
Score 85/100KDC Dashboard has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "ws-dash" plugin v2.0 presents a generally positive security posture based on the provided static analysis. The absence of known CVEs and the use of prepared statements for SQL queries are strong indicators of good security practices. Furthermore, the plugin has no history of reported vulnerabilities, suggesting consistent developer attention to security or a lack of complex functionality that typically attracts attacks.
However, several significant concerns arise from the code analysis. The most notable is the complete lack of output escaping for all identified outputs. This is a critical weakness that could lead to cross-site scripting (XSS) vulnerabilities if any user-controllable data is displayed on the frontend without proper sanitization. Additionally, the absence of nonce and capability checks for the identified entry points, particularly the shortcode, means that any user, regardless of their role or permissions, could potentially trigger its functionality. This lack of authorization and input validation presents a substantial risk.
In conclusion, while the plugin benefits from a clean vulnerability history and secure SQL handling, the severe lack of output escaping and missing authorization checks for its entry points introduce significant security risks. These weaknesses need to be addressed promptly to secure the plugin against common web vulnerabilities.
Key Concerns
- Outputs not properly escaped
- Shortcode without nonce check
- Shortcode without capability check
KDC Dashboard Security Vulnerabilities
KDC Dashboard Code Analysis
Output Escaping
KDC Dashboard Attack Surface
Shortcodes 1
WordPress Hooks 14
Maintenance & Trust
KDC Dashboard Maintenance & Trust
Maintenance Signals
Community Trust
KDC Dashboard Alternatives
Favicon Rotator
favicon-rotator
Easily set site favicon and even rotate through multiple icons
WP Font Awesome
wp-font-awesome
This plugin allows you to easily embed Font Awesome icon to your site with simple shortcodes.
Dicode Icons Pack
dicode-icons-pack
Dicode Icons Pack by Designinvento provides ability to add custom font icons to your website from all time top icon libraries.
Admin Customization
admin-customization
Customize your Wordpress backend.
Post Featured Font Icon
post-featured-font-icon
it supports dashicons, genericons, font-awesome.
KDC Dashboard Developer Profile
4 plugins · 70 total installs
How We Detect KDC Dashboard
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ws-dash/assets/css/ws-icon.css/wp-content/plugins/ws-dash/assets/img/kdc-tb-icon.pngKDC : WP-https://s3.ap-south-1.amazonaws.com/kdc-wp-dash/site.jskdc-login-logo.png?ver=kdc-login-logo.svg?ver=kdc-tb-icon.png?ver=HTML / DOM Fingerprints
ws-icontarget=_kdc<span class="ws-ws-icon-ws-ws-assist