
Debug Bar Actions and Filters Addon Security & Risk Analysis
wordpress.org/plugins/debug-bar-actions-and-filters-addonDisplays all the hooks( Actions and Filters ) for the current request in Debug Bar panel.
Is Debug Bar Actions and Filters Addon Safe to Use in 2026?
Generally Safe
Score 85/100Debug Bar Actions and Filters Addon has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'debug-bar-actions-and-filters-addon' v1.5.5 exhibits a strong security posture in several key areas. The absence of any recorded CVEs and a clean vulnerability history suggest a history of responsible development and timely patching. The static analysis reveals a commendable lack of attack surface, with no AJAX handlers, REST API routes, shortcodes, or cron events exposed without proper authentication or permission checks. Furthermore, all identified SQL queries utilize prepared statements, and the majority of output is properly escaped, mitigating common injection risks. The plugin also demonstrates good practice by avoiding file operations and external HTTP requests.
However, the presence of the `create_function` function, which is deprecated and can lead to code execution vulnerabilities if not handled with extreme care, represents a significant concern. While the taint analysis shows no unsanitized paths, the potential for `create_function` to be misused remains. The lack of nonce checks on any potential entry points, though currently not exposed, could become a weakness if future development introduces new handlers without this security measure. The single capability check is positive, but the overall lack of other security checks (like nonces) on what could be considered an extended attack surface (even if currently protected) warrants attention.
In conclusion, while the plugin has a solid foundation with a clean history and well-protected entry points, the inclusion of `create_function` is a notable security risk that needs to be addressed. The absence of nonce checks on potentially interactive elements, even if currently unexploited, is also a minor weakness. Addressing these specific points would further enhance the plugin's security.
Key Concerns
- Presence of deprecated and potentially dangerous create_function
- Zero nonce checks on potential entry points
Debug Bar Actions and Filters Addon Security Vulnerabilities
Debug Bar Actions and Filters Addon Code Analysis
Dangerous Functions Found
Output Escaping
Debug Bar Actions and Filters Addon Attack Surface
WordPress Hooks 5
Maintenance & Trust
Debug Bar Actions and Filters Addon Maintenance & Trust
Maintenance Signals
Community Trust
Debug Bar Actions and Filters Addon Alternatives
FacetWP Manipulator
facetwp-manipulator
FacetWP Manipulator allows you to add code to specific FacetWP filters and Actions to manipulate functionality without hard coding it to the theme.
Captain Hooks
captain-hooks
Captain Hooks is a WordPress plugin that provides developers with a comprehensive view of all actions, filters, and shortcodes of their environment.
Prioritize Hooks
prioritize-hooks
Prioritize Hooks allows the overriding of the priority of various filters and actions hooked by plugins and themes.
rtPanel Hooks Editor
rtpanel-hooks-editor
This plugin is add-on for [rtPanel Theme Framework](https://wordpress.org/themes/rtpanel "rtPanel Theme Framework") and should be used along …
Sectors – Conditional Templates & Hooks
sectors
What if you could add templates, actions, and filters depending on the context?
Debug Bar Actions and Filters Addon Developer Profile
2 plugins · 510 total installs
How We Detect Debug Bar Actions and Filters Addon
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/debug-bar-actions-and-filters-addon/debug-bar-action-and-filters-addon.phpHTML / DOM Fingerprints
debug-bar-tabledebug-bar-actions-filters