AWEOS PHP Server Info Security & Risk Analysis

wordpress.org/plugins/aweos-php-server-info

Brief dashboard overview. Use this plugin to get all important server and PHP information. Useful tool for developer that need information about their …

2K active installs v1.3 PHP 7.0+ WP 4.5+ Updated Jul 18, 2024
aweosdashboardinfophpserver
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is AWEOS PHP Server Info Safe to Use in 2026?

Generally Safe

Score 92/100

AWEOS PHP Server Info has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "aweos-php-server-info" plugin, version 1.3, demonstrates a generally strong security posture based on the static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events, coupled with zero identified dangerous functions, indicates a minimal attack surface. Furthermore, all SQL queries utilize prepared statements, and there are no file operations or external HTTP requests, which are positive indicators. However, a significant concern arises from the complete lack of output escaping, meaning that any data processed by this plugin could be rendered directly to the user without sanitization, posing a Cross-Site Scripting (XSS) risk. The lack of nonce and capability checks on potential, albeit currently non-existent, entry points is also a missed opportunity for robust security, as it leaves room for future vulnerabilities if the plugin evolves.

Key Concerns

  • All outputs are unescaped
  • No nonce checks present
  • No capability checks present
Vulnerabilities
None known

AWEOS PHP Server Info Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

AWEOS PHP Server Info Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
9
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped9 total outputs
Attack Surface

AWEOS PHP Server Info Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionadmin_enqueue_scriptsaw-php-server-info.php:62
actionwp_dashboard_setupaw-php-server-info.php:63
Maintenance & Trust

AWEOS PHP Server Info Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedJul 18, 2024
PHP min version7.0
Downloads29K

Community Trust

Rating100/100
Number of ratings1
Active installs2K
Developer Profile

AWEOS PHP Server Info Developer Profile

AWEOS GmbH

10 plugins · 6K total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
13 days
View full developer profile
Detection Fingerprints

How We Detect AWEOS PHP Server Info

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/aweos-php-server-info/style.css
Version Parameters
aweos-php-server-info/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
awpi-info
Shortcode Output
<p>System: <b><p>PHP Version: <b><p>Memory Limit: <b>Unlimited</b><br></p>
FAQ

Frequently Asked Questions about AWEOS PHP Server Info