
ATR Server Status Security & Risk Analysis
wordpress.org/plugins/atr-server-statusImportant notice
Is ATR Server Status Safe to Use in 2026?
Generally Safe
Score 92/100ATR Server Status has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The atr-server-status plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by not using dangerous functions, performing all SQL queries using prepared statements, and not making external HTTP requests or performing file operations. The absence of known vulnerabilities and bundled libraries is also a strength. However, significant concerns arise from the static analysis. The plugin has a total of four AJAX handlers, and alarmingly, all four lack authentication checks, presenting a substantial attack surface for unauthenticated users. While taint analysis didn't reveal critical or high-severity unsanitized paths, the fact that all analyzed flows had unsanitized paths is a red flag and suggests potential for issues if input validation is not robust enough.
The vulnerability history is currently clean, with no recorded CVEs, which is a positive indicator for this version. This suggests the developers may have learned from past mistakes or that the plugin has not been a target. Nevertheless, the lack of proper output escaping on a significant portion of outputs (85 total, only 15% properly escaped) presents a risk of Cross-Site Scripting (XSS) vulnerabilities. The presence of nonce checks on all AJAX handlers is good, but this is undermined by the absence of capability checks on the AJAX handlers themselves.
In conclusion, while the plugin has some strong security foundations, the unprotected AJAX handlers and poor output escaping are critical weaknesses that expose it to significant risks, particularly XSS and unauthorized functionality execution. The taint analysis also warrants attention despite the absence of critical findings. A thorough review of input sanitization and output escaping for all AJAX handlers is strongly recommended.
Key Concerns
- Unprotected AJAX handlers
- Low percentage of properly escaped output
- All taint flows have unsanitized paths
- Missing capability checks on AJAX
ATR Server Status Security Vulnerabilities
ATR Server Status Code Analysis
Output Escaping
Data Flow Analysis
ATR Server Status Attack Surface
AJAX Handlers 4
WordPress Hooks 15
Maintenance & Trust
ATR Server Status Maintenance & Trust
Maintenance Signals
Community Trust
ATR Server Status Alternatives
Server Info
server-info
This plugin will show you very useful information about your hosting server such as PHP version, Server OS, Server IP etc.
Apache Status & Info
htaccess-server-info-server-status
Apache server-info and server-status monitoring right in your WordPress admin.
Heartbeat Control
heartbeat-control
Allows you to easily manage the frequency of the WordPress heartbeat API.
Media Sync
media-sync
Simple plugin to scan "uploads" directory and bring those files into Media Library.
Display PHP Version
display-php-version
Displays the currently installed PHP/MySQL version in the "At a Glance" admin dashboard widget.
ATR Server Status Developer Profile
1 plugin · 100 total installs
How We Detect ATR Server Status
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/atr-server-status/stylesheets/admin-servers.css/wp-content/plugins/atr-server-status/javascript/server-functions.js/wp-content/plugins/atr-server-status/stylesheets/frontend-servers.css/wp-content/plugins/atr-server-status/javascript/frontend-check-servers-/wp-content/plugins/atr-server-status/templates/admin-servers.php/wp-content/plugins/atr-server-status/templates/admin-config.php/wp-content/plugins/atr-server-status/templates/view-servers.php/wp-content/plugins/atr-server-status/templates/wp-footer.php+1 more/wp-content/plugins/atr-server-status/javascript/server-functions.js/wp-content/plugins/atr-server-status/javascript/frontend-check-servers-.jsHTML / DOM Fingerprints
data-atr-server-status-iddata-atr-server-status-urlwindow.ATRwindow.ATR.Settings[server-statusserver-status