Zeus WordPress Admin Security & Risk Analysis

wordpress.org/plugins/zeus-admin-theme

A simple, clean admin theme with select features to extend and improve your WordPress experience.

60 active installs v2.1 PHP + WP 3.0.1+ Updated Jun 18, 2019
adminadmin-pageadmin-paneladmin-themeadmin-theme-style-plugin
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Zeus WordPress Admin Safe to Use in 2026?

Generally Safe

Score 85/100

Zeus WordPress Admin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The "zeus-admin-theme" v2.1 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries, performing proper output escaping on the vast majority of outputs, and having no recorded vulnerabilities or CVEs. The absence of dangerous functions, file operations, and external HTTP requests further contributes to a generally secure codebase.

However, a significant concern lies in its attack surface. The plugin exposes three AJAX handlers, with two of them lacking authentication checks. While the static analysis did not reveal any critical or high severity taint flows, these unprotected AJAX endpoints represent potential entry points for attackers. The presence of nonces and capability checks on these handlers is a positive mitigation, but their absence in two instances remains a notable weakness.

Overall, the plugin's lack of historical vulnerabilities is a strong indicator of responsible development. Nevertheless, the unprotected AJAX handlers are a clear area for improvement. Addressing these should be a priority to further strengthen the plugin's security.

Key Concerns

  • AJAX handlers without auth checks
  • 2 AJAX handlers, 2 without auth checks
Vulnerabilities
None known

Zeus WordPress Admin Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Zeus WordPress Admin Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
3
30 escaped
Nonce Checks
2
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

91% escaped33 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
bhm_get_menu_list (inc\hide-admin-menu\menu-list.php:16)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Zeus WordPress Admin Attack Surface

Entry Points3
Unprotected2

AJAX Handlers 3

authwp_ajax_update_menu_positionsinc\ajax-admin-menu-editor\ajax-admin-menu-editor.php:35
authwp_ajax_aame_register_sepinc\ajax-admin-menu-editor\ajax-admin-menu-editor.php:36
authwp_ajax_HWPTB_stateinc\hide-wp-toolbar\hide-wp-toolbar.php:122
WordPress Hooks 25
actionadmin_enqueue_scriptsinc\ajax-admin-menu-editor\ajax-admin-menu-editor.php:37
filtercustom_menu_orderinc\ajax-admin-menu-editor\ajax-admin-menu-editor.php:41
filtermenu_orderinc\ajax-admin-menu-editor\ajax-admin-menu-editor.php:42
actionadmin_initinc\ajax-admin-menu-editor\ajax-admin-menu-editor.php:111
actionadmin_menuinc\hide-admin-menu\init.php:40
actionadmin_enqueue_scriptsinc\hide-admin-menu\menu-list.php:4
actioninitinc\hide-admin-menu\menu-list.php:14
actionadmin_menuinc\hide-admin-menu\menu-list.php:365
actionadmin_bar_menuinc\hide-admin-menu\menu-list.php:389
actionplugins_loadedinc\hide-wp-toolbar\hide-wp-toolbar.php:16
actionadmin_bar_menuinc\hide-wp-toolbar\hide-wp-toolbar.php:27
actionwp_enqueue_scriptsinc\hide-wp-toolbar\hide-wp-toolbar.php:48
actionwp_enqueue_scriptsinc\hide-wp-toolbar\hide-wp-toolbar.php:61
actionadmin_bar_menuinc\jarvis\src\php\plugin.php:127
actionadmin_enqueue_scriptsinc\jarvis\src\php\plugin.php:128
actionadmin_initinc\jarvis\src\php\plugin.php:129
actionedit_user_profile_updateinc\jarvis\src\php\plugin.php:130
actionedit_user_profileinc\jarvis\src\php\plugin.php:131
actionpersonal_options_updateinc\jarvis\src\php\plugin.php:132
actionrest_api_initinc\jarvis\src\php\plugin.php:133
actionshow_user_profileinc\jarvis\src\php\plugin.php:134
actionadmin_enqueue_scriptszeus-admin-theme.php:19
actionadmin_initzeus-admin-theme.php:52
actionadmin_menuzeus-admin-theme.php:72
actionadmin_headzeus-admin-theme.php:100
Maintenance & Trust

Zeus WordPress Admin Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedJun 18, 2019
PHP min version
Downloads8K

Community Trust

Rating84/100
Number of ratings6
Active installs60
Developer Profile

Zeus WordPress Admin Developer Profile

Luke Hertzler

2 plugins · 60 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Zeus WordPress Admin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/zeus-admin-theme/css/theme-style.css/wp-content/plugins/zeus-admin-theme/js/theme-script.js/wp-content/plugins/zeus-admin-theme/css/colors.css
Generator Patterns
Zeus Admin Theme
Script Paths
/wp-content/plugins/zeus-admin-theme/js/theme-script.js
Version Parameters
zeus-admin-theme/css/theme-style.css?ver=zeus-admin-theme/js/theme-script.js?ver=zeus-admin-theme/css/colors.css?ver=

HTML / DOM Fingerprints

CSS Classes
zeus-admin-theme-logozeus-theme-color-scheme-options
HTML Comments
<!-- Zeus Admin Theme Version <!-- Zeus Admin Theme Footer -->
Data Attributes
data-zeus-theme-option
JS Globals
ZeusAdminTheme
FAQ

Frequently Asked Questions about Zeus WordPress Admin