
Bloginfo Security & Risk Analysis
wordpress.org/plugins/bloginfoA shortcode to get some useful information from your WordPress Installation.
Is Bloginfo Safe to Use in 2026?
Generally Safe
Score 85/100Bloginfo has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the static analysis and vulnerability history, the "bloginfo" v1.0 plugin exhibits a strong security posture. The absence of dangerous functions, file operations, external HTTP requests, and the correct implementation of SQL prepared statements and output escaping are all positive indicators. Furthermore, the plugin has no known vulnerabilities, indicating a track record of secure development or timely patching.
However, a notable concern is the complete lack of nonce checks and capability checks. While the current entry points are limited to one shortcode and there are no unprotected AJAX handlers or REST API routes, this absence of authorization checks represents a potential weakness. Should the plugin's functionality expand or new entry points be introduced without these security measures, it could become vulnerable to privilege escalation or unauthorized access.
In conclusion, "bloginfo" v1.0 is currently secure due to its limited attack surface and lack of known vulnerabilities. The plugin developer has followed good practices regarding SQL and output handling. The primary area for improvement and potential future risk lies in the implementation of robust nonce and capability checks to safeguard against potential unauthorized actions, especially if the plugin's scope grows.
Key Concerns
- Missing nonce checks
- Missing capability checks
Bloginfo Security Vulnerabilities
Bloginfo Code Analysis
Bloginfo Attack Surface
Shortcodes 1
Maintenance & Trust
Bloginfo Maintenance & Trust
Maintenance Signals
Community Trust
Bloginfo Alternatives
Header Footer Code Manager
header-footer-code-manager
Easily add tracking code snippets, conversion pixels, or other scripts required by third party services for analytics, marketing, or chat features.
FluentSnippets – The High-Performance file based Custom Code Snippets Plugin
easy-code-manager
Add header and footer scripts, PHP Snippets, Custom CSS /JS snippets with advanced conditional logic, and more...
Foxtool All-in-One: Contact chat button, Custom login, Media optimize images
foxtool
Summarize the essential functions for managing a WordPress website
WP EXtra – One Click Optimize
wp-extra
Optimize your site instantly with one-click activation. WP Extra offers easy fixes and features for WordPress.
WPS Child Theme Generator
wps-child-theme-generator
Create your child theme with options. Customize it many options.
Bloginfo Developer Profile
6 plugins · 180 total installs
How We Detect Bloginfo
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
[bloginfo]