atec Profiler Security & Risk Analysis

wordpress.org/plugins/atec-profiler

Measure plugins & theme execution time plus page processing time

60 active installs v1.1.32 PHP 7.4+ WP 4.9+ Updated Jan 8, 2026
measure-plugins-theme-execution-time-plus-page-processing-time
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is atec Profiler Safe to Use in 2026?

Generally Safe

Score 100/100

atec Profiler has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "atec-profiler" plugin v1.1.32 exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding SQL queries, with 100% using prepared statements, and a high percentage (99%) of output being properly escaped, significantly mitigating common web vulnerabilities like SQL injection and XSS. The absence of known CVEs and a clean vulnerability history also suggest a generally well-maintained codebase.

However, a significant concern is the presence of an unprotected AJAX handler, representing a critical entry point into the plugin's functionality without any authentication or authorization checks. While the taint analysis did reveal flows with unsanitized paths, the severity was noted as none (critical/high), which is a positive sign, but the mere presence of unsanitized paths warrants attention. The limited number of known vulnerabilities could be a testament to good development or simply a lack of extensive public scrutiny. Therefore, while the plugin has strong foundations in secure coding for database interactions and output handling, the unprotected AJAX endpoint poses a direct and immediate risk that needs to be addressed.

Key Concerns

  • Unprotected AJAX handler
Vulnerabilities
None known

atec Profiler Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

atec Profiler Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
335 escaped
Nonce Checks
2
Capability Checks
5
File Operations
19
External Requests
1
Bundled Libraries
0

Output Escaping

99% escaped340 total outputs
Data Flows
4 unsanitized

Data Flow Analysis

4 flows4 with unsanitized paths
onShutdown (install\_atec-mu-hooks-profiler.php:82)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

atec Profiler Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_atec_admin_notice_dismissincludes\ATEC\LOADER.php:109
WordPress Hooks 20
actionadmin_menuatec-profiler.php:29
filterall_pluginsatec-profiler.php:31
actionadmin_enqueue_scriptsincludes\ATEC\INIT.php:564
actionadmin_noticesincludes\ATEC\INIT.php:647
actionadmin_footerincludes\ATEC\INIT.php:688
actionadmin_noticesincludes\ATEC\INIT.php:720
filterpre_determine_localeinstall\_atec-mu-hooks-profiler.php:30
actionallinstall\_atec-mu-hooks-profiler.php:31
filterpre_http_requestinstall\_atec-mu-hooks-profiler.php:32
actionrequests-curl.after_sendinstall\_atec-mu-hooks-profiler.php:33
actionshutdowninstall\_atec-mu-hooks-profiler.php:34
actionshutdowninstall\_atec-mu-pages-profiler.php:41
actionplugin_loadedinstall\_atec-mu-processes-profiler.php:34
actionsetup_themeinstall\_atec-mu-processes-profiler.php:36
actionafter_setup_themeinstall\_atec-mu-processes-profiler.php:37
actionshutdowninstall\_atec-mu-processes-profiler.php:39
actionplugins_loadedinstall\_atec-mu-processes-profiler.php:41
filtergettextinstall\_atec-mu-translations-profiler.php:28
filteroverride_load_textdomaininstall\_atec-mu-translations-profiler.php:29
actionshutdowninstall\_atec-mu-translations-profiler.php:30
Maintenance & Trust

atec Profiler Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 8, 2026
PHP min version7.4
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs60
Alternatives

atec Profiler Alternatives

No alternatives data available yet.

Developer Profile

atec Profiler Developer Profile

docjojo

16 plugins · 3K total installs

99
trust score
Avg Security Score
99/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect atec Profiler

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/atec-profiler/atec-profiler.php/wp-content/plugins/atec-profiler/includes/ATEC/LOADER.php/wp-content/plugins/atec-profiler/includes/ATEC/INIT.php

HTML / DOM Fingerprints

CSS Classes
atec-admin-bar-row
Data Attributes
data-atec
JS Globals
atec_profiler_settingsatec_profiler_admin_ajax
REST Endpoints
/wp-json/atec-profiler/v1/settings
Shortcode Output
[atec_profiler_output]
FAQ

Frequently Asked Questions about atec Profiler