Using that code could let anyone access your mySQL database for phpvms as they could just download the sidebar_dashboard.tpl file (http://www.yourdomain.com/admi/templates/sidebar_dashboard.tpl). Unless of course, you have the .htaccess file which stops people from downloading files from your site