
BugFu Console Debugger Security & Risk Analysis
wordpress.org/plugins/bugfu-console-debuggerLog/Debug the PHP code in your Theme/Plugin with your Browser Console (no extension needed)
Is BugFu Console Debugger Safe to Use in 2026?
Generally Safe
Score 85/100BugFu Console Debugger has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The bugfu-console-debugger plugin, v1.3.0, exhibits a mixed security posture. While it boasts a zero attack surface in terms of AJAX handlers, REST API routes, shortcodes, and cron events, and all its SQL queries are properly prepared, significant concerns arise from its code signals. The presence of the `unserialize` function is a critical red flag, especially when coupled with a concerning taint analysis result indicating a flow with unsanitized paths. Furthermore, the complete lack of output escaping on all identified outputs means that any data processed and displayed by the plugin is vulnerable to cross-site scripting (XSS) attacks. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive indicator. However, this history does not mitigate the inherent risks identified in the static analysis, particularly the `unserialize` function and unescaped output.
Key Concerns
- Dangerous function unserialize detected
- 100% of outputs unescaped
- Taint flow with unsanitized paths
- No nonce checks
- Limited capability checks
BugFu Console Debugger Security Vulnerabilities
BugFu Console Debugger Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
BugFu Console Debugger Attack Surface
WordPress Hooks 9
Maintenance & Trust
BugFu Console Debugger Maintenance & Trust
Maintenance Signals
Community Trust
BugFu Console Debugger Alternatives
Error Log Viewer by BestWebSoft
error-log-viewer
Get latest error log messages to diagnose website problems. Define and fix issues faster.
BugTrace – Debug Log Tool
debug-log-tool
Essential WordPress debug tool: View/download logs, toggle debug settings & inspect server info. Troubleshoot PHP errors & site issues faster!
LH Javascript Error log
lh-javascript-error-log
Log Javascript errors from your browser to your wordpress error log.
WP Viewer Log
wp-viewer-log
Lets see how many errors have had in the present day through a widget, configure your wp-config.php and see the file log.
ErrorLyze – Error Logger & AI Debugger
errorlyze
Detect and fix WordPress PHP errors with AI-powered analysis. Automatic error logging, monitoring, and step-by-step fix recommendations for developers …
BugFu Console Debugger Developer Profile
2 plugins · 500 total installs
How We Detect BugFu Console Debugger
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bugfu-console-debugger/css/bugfu-console-debugger.css/wp-content/plugins/bugfu-console-debugger/js/ajax-bugfu-console-debugger.js/wp-content/plugins/bugfu-console-debugger/js/ajax-bugfu-console-debugger.jsbugfu-console-debugger/style.css?ver=ajax-bugfu-console-debugger.js?ver=HTML / DOM Fingerprints
bugfu-console-debuggerbugfu_console_debugger_ajax_params