
Code Quality Control Tool Security & Risk Analysis
wordpress.org/plugins/code-quality-control-toolPlugin that allows you to see all PHP errors and helps you troubleshoot a misbehaving theme or plugin.
Is Code Quality Control Tool Safe to Use in 2026?
Generally Safe
Score 99/100Code Quality Control Tool has a strong security track record. Known vulnerabilities have been patched promptly.
The 'code-quality-control-tool' v2.2 plugin exhibits a mixed security posture. On the positive side, static analysis reveals no direct attack surface exposed through AJAX, REST API, shortcodes, or cron events. The absence of dangerous functions, external HTTP requests, and raw SQL queries are also strong indicators of good coding practices. Taint analysis shows no critical or high severity flows, suggesting that user-supplied data is not being mishandled in a way that would lead to immediate compromise.
However, significant concerns arise from the low percentage of properly escaped output (10%). This indicates a high likelihood of cross-site scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the site. The presence of a past medium-severity vulnerability related to exposure of sensitive information, even though currently patched, suggests a history of potential security oversights. While the plugin's attack surface is minimal, the lack of capability checks on the entry points it does have is a notable weakness that could be exploited if any new entry points are introduced or if existing ones are discovered.
In conclusion, while the plugin demonstrates strengths in areas like SQL handling and minimizing its attack surface, the substantial output escaping deficiency and the past vulnerability history warrant caution. The risk is moderate, primarily driven by the potential for XSS and the lingering possibility of undiscovered issues given the past security incident.
Key Concerns
- Low output escaping percentage (10%)
- Past medium vulnerability (Exposure of Sensitive Information)
- No capability checks on entry points
Code Quality Control Tool Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Code Quality Control Tool <= 2.1 - Unauthenticated Information Exposure via Log Files
Code Quality Control Tool Code Analysis
Output Escaping
Data Flow Analysis
Code Quality Control Tool Attack Surface
WordPress Hooks 5
Maintenance & Trust
Code Quality Control Tool Maintenance & Trust
Maintenance Signals
Community Trust
Code Quality Control Tool Alternatives
LogIQ
log-iq
A powerful and user-friendly debug log viewer for WordPress with editor integration.
Debug Suite
debug-suite
A powerful, enterprise-grade debugging toolkit for WordPress developers with advanced log management, error tracking, and development tools.
Developer Debug Mode
developer-debug-mode
Toggle WordPress debug mode instantly. No wp-config.php editing needed. Features auto-save, admin bar quick toggle, and debug log viewer.
PAS Debug Log Manager
pas-debug-log-manager
A simple WordPress plugin that allows users to view and manage the WordPress debug log. Provides options to clear the log, toggle debug logging, and d …
Error Log Viewer by BestWebSoft
error-log-viewer
Get latest error log messages to diagnose website problems. Define and fix issues faster.
Code Quality Control Tool Developer Profile
1 plugin · 50 total installs
How We Detect Code Quality Control Tool
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/code-quality-control-tool/css/style.cssHTML / DOM Fingerprints
cqctphp-headercqctphp-cardcqctphp-info-blockcqctphp-info-itemnumcircgreennumcirccode-control-top-toolbardata-plugin-name="code-quality-control-tool"