
Compare hosting performance Security & Risk Analysis
wordpress.org/plugins/compare-hosting-performanceТест производительности вашего сервера/хостинга
Is Compare hosting performance Safe to Use in 2026?
Generally Safe
Score 85/100Compare hosting performance has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'compare-hosting-performance' plugin v1.2 presents a significant security risk due to its unprotected entry points and lack of fundamental security checks. With four AJAX handlers identified and none of them incorporating authentication or authorization, these handlers are wide open to exploitation. This means any unauthenticated user could potentially trigger these functions, leading to unintended actions or data leakage. Furthermore, the complete absence of nonce checks and capability checks on these AJAX handlers exacerbates the risk, making it trivial to execute arbitrary code or manipulate plugin functionality. The code analysis also reveals a concerning lack of output escaping, with 0% of outputs being properly escaped. This opens the door to cross-site scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the website. While the plugin has no recorded vulnerability history, this should not be seen as a sign of robust security but rather a potential indicator that it hasn't been thoroughly scrutinized or that past vulnerabilities have been overlooked. The limited use of prepared statements for SQL queries also raises concerns about potential SQL injection vulnerabilities, though the specific queries are not detailed enough to confirm. Overall, the plugin's security posture is weak, with numerous critical security hygiene issues that require immediate attention.
Key Concerns
- Unprotected AJAX handlers
- Missing nonce checks on AJAX handlers
- Missing capability checks on AJAX handlers
- No output escaping
- Low percentage of prepared SQL statements
Compare hosting performance Security Vulnerabilities
Compare hosting performance Release Timeline
Compare hosting performance Code Analysis
SQL Query Safety
Output Escaping
Compare hosting performance Attack Surface
AJAX Handlers 4
WordPress Hooks 5
Maintenance & Trust
Compare hosting performance Maintenance & Trust
Maintenance Signals
Community Trust
Compare hosting performance Alternatives
Index WP MySQL For Speed
index-wp-mysql-for-speed
Speed up your WordPress site by adding high-performance keys (database indexes) to your MariaDB / MySQL database tables.
WP phpMyAdmin
wp-phpmyadmin-extension
[ ✅ 𝐒𝐄𝐂𝐔𝐑𝐄 𝐏𝐋𝐔𝐆𝐈𝐍𝐒 𝐵𝓎 𝒫𝓊𝓋𝑜𝓍 ] phpMyAdmin - Database Browser & Manager (for MySQL & MariaDB)
Version Info – Server Health Monitor, PHP & MySQL Version Display, Environment Indicators
version-info
The #1 technical dashboard for WordPress professionals. Display PHP, MySQL, WP & server versions anywhere in admin. Monitor CPU, RAM, DB size & …
WP-ServerInfo
wp-serverinfo
Display your host's PHP, MYSQL & memcached (if installed) information on your WordPress dashboard.
SQL Executioner
sql-executioner
Execute arbitrary SQL queries against your WordPress database from the Admin.
Compare hosting performance Developer Profile
3 plugins · 330 total installs
How We Detect Compare hosting performance
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/compare-hosting-performance/bootstrap/js/bootstrap.js/wp-content/plugins/compare-hosting-performance/bootstrap/css/bootstrap.css/wp-content/plugins/compare-hosting-performance/css/adminpag.css/wp-content/plugins/compare-hosting-performance/js/admin_order.js/wp-content/plugins/compare-hosting-performance/bootstrap/js/bootstrap.js/wp-content/plugins/compare-hosting-performance/js/admin_order.jscompare-hosting-performance/bootstrap/js/bootstrap.js?ver=compare-hosting-performance/bootstrap/css/bootstrap.css?ver=compare-hosting-performance/css/adminpag.css?ver=compare-hosting-performance/js/admin_order.js?ver=HTML / DOM Fingerprints
<!-- Copyright 2016 Djo (email: izm@zixn.ru)<!-- This program is free software; you can redistribute it and/or modify it under the terms of the GNU General Public License as published by+10 morewindow.chp_zixnru