Compare hosting performance Security & Risk Analysis

wordpress.org/plugins/compare-hosting-performance

Тест производительности вашего сервера/хостинга

10 active installs v1.2 PHP + WP 4.0+ Updated Jan 2, 2017
mysqlperformancephp
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Compare hosting performance Safe to Use in 2026?

Generally Safe

Score 85/100

Compare hosting performance has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The 'compare-hosting-performance' plugin v1.2 presents a significant security risk due to its unprotected entry points and lack of fundamental security checks. With four AJAX handlers identified and none of them incorporating authentication or authorization, these handlers are wide open to exploitation. This means any unauthenticated user could potentially trigger these functions, leading to unintended actions or data leakage. Furthermore, the complete absence of nonce checks and capability checks on these AJAX handlers exacerbates the risk, making it trivial to execute arbitrary code or manipulate plugin functionality. The code analysis also reveals a concerning lack of output escaping, with 0% of outputs being properly escaped. This opens the door to cross-site scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the website. While the plugin has no recorded vulnerability history, this should not be seen as a sign of robust security but rather a potential indicator that it hasn't been thoroughly scrutinized or that past vulnerabilities have been overlooked. The limited use of prepared statements for SQL queries also raises concerns about potential SQL injection vulnerabilities, though the specific queries are not detailed enough to confirm. Overall, the plugin's security posture is weak, with numerous critical security hygiene issues that require immediate attention.

Key Concerns

  • Unprotected AJAX handlers
  • Missing nonce checks on AJAX handlers
  • Missing capability checks on AJAX handlers
  • No output escaping
  • Low percentage of prepared SQL statements
Vulnerabilities
None known

Compare hosting performance Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Compare hosting performance Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

Compare hosting performance Code Analysis

Dangerous Functions
0
Raw SQL Queries
7
1 prepared
Unescaped Output
50
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
8
External Requests
2
Bundled Libraries
0

SQL Query Safety

13% prepared8 total queries

Output Escaping

0% escaped50 total outputs
Attack Surface
4 unprotected

Compare hosting performance Attack Surface

Entry Points4
Unprotected4

AJAX Handlers 4

authwp_ajax_getTestinc\javascript-class.php:24
noprivwp_ajax_getTestinc\javascript-class.php:25
authwp_ajax_getPageZixninc\javascript-class.php:27
noprivwp_ajax_getPageZixninc\javascript-class.php:28
WordPress Hooks 5
actionadmin_menuinc\core-class.php:44
filterplugin_action_linksinc\core-class.php:45
actionplugins_loadedindex.php:31
actionplugins_loadedindex.php:32
actionadmin_noticesindex.php:54
Maintenance & Trust

Compare hosting performance Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.33
Last updatedJan 2, 2017
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

Compare hosting performance Developer Profile

Djo

3 plugins · 330 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Compare hosting performance

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/compare-hosting-performance/bootstrap/js/bootstrap.js/wp-content/plugins/compare-hosting-performance/bootstrap/css/bootstrap.css/wp-content/plugins/compare-hosting-performance/css/adminpag.css/wp-content/plugins/compare-hosting-performance/js/admin_order.js
Script Paths
/wp-content/plugins/compare-hosting-performance/bootstrap/js/bootstrap.js/wp-content/plugins/compare-hosting-performance/js/admin_order.js
Version Parameters
compare-hosting-performance/bootstrap/js/bootstrap.js?ver=compare-hosting-performance/bootstrap/css/bootstrap.css?ver=compare-hosting-performance/css/adminpag.css?ver=compare-hosting-performance/js/admin_order.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- Copyright 2016 Djo (email: izm@zixn.ru)<!-- This program is free software; you can redistribute it and/or modify it under the terms of the GNU General Public License as published by+10 more
JS Globals
window.chp_zixnru
FAQ

Frequently Asked Questions about Compare hosting performance