Client Status Security & Risk Analysis

wordpress.org/plugins/client-status

Client Status is a dashboard that keeps tabs on your clients WordPress installations by checking for the latest updates to the WordPress core, plugins …

10 active installs v1.3.3 PHP + WP 3.0+ Updated Unknown
clientdashboardstatusupdates
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Client Status Safe to Use in 2026?

Generally Safe

Score 100/100

Client Status has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The client-status plugin v1.3.3 exhibits a mixed security posture. While the absence of known CVEs and a lack of critical taint flows are positive indicators, several code analysis signals raise significant concerns. The most alarming is the complete lack of output escaping, meaning all data outputted by the plugin is vulnerable to cross-site scripting (XSS) attacks. Additionally, the plugin performs raw SQL queries without prepared statements, increasing the risk of SQL injection vulnerabilities. The complete absence of nonce and capability checks across the analyzed code further exacerbates these risks, as it implies any entry point, if present, would be unprotected.

Key Concerns

  • 100% of outputs are not properly escaped
  • 33% of SQL queries do not use prepared statements
  • No nonce checks found
  • No capability checks found
  • 1 flow with unsanitized paths found
Vulnerabilities
None known

Client Status Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Client Status Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
1 prepared
Unescaped Output
105
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
3
Bundled Libraries
0

SQL Query Safety

33% prepared3 total queries

Output Escaping

0% escaped105 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<client-status> (client-status.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Client Status Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionadmin_initclient-status.php:23
actionadmin_menuclient-status.php:24
actionadmin_print_scriptsclient-status.php:25
actionadmin_print_stylesclient-status.php:26
actionclient_status_update_all_clients_actionclient-status.php:27
actioninitclient-status.php:28
actionmanage_client_status_client_posts_custom_columnclient-status.php:29
actionright_now_content_table_endclient-status.php:30
actionsave_postclient-status.php:31
filtermanage_edit-client_status_client_columnsclient-status.php:32
filterwp_mail_from_nameclient-status.php:33

Scheduled Events 1

client_status_update_all_clients_action
Maintenance & Trust

Client Status Maintenance & Trust

Maintenance Signals

WordPress version tested3.3.2
Last updatedUnknown
PHP min version
Downloads5K

Community Trust

Rating60/100
Number of ratings1
Active installs10
Developer Profile

Client Status Developer Profile

ericjuden

7 plugins · 210 total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Client Status

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/client-status/style.css
Version Parameters
client-status/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
statusstatus_errorstatus_okclient_meta_infoclient_meta_status
Data Attributes
client_urlclient_email
FAQ

Frequently Asked Questions about Client Status