
ElasticPress Debugging Add-On Security & Risk Analysis
wordpress.org/plugins/debug-bar-elasticpressExtends the Query Monitor and Debug Bar plugins for ElasticPress queries.
Is ElasticPress Debugging Add-On Safe to Use in 2026?
Generally Safe
Score 91/100ElasticPress Debugging Add-On has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin "debug-bar-elasticpress" v3.1.1 demonstrates a generally strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with an attack surface is a significant positive. Furthermore, the code shows excellent practices regarding SQL queries, exclusively using prepared statements, and a very high percentage of output escaping. The presence of nonce checks and capability checks, while not exhaustive, also suggests an awareness of security best practices.
However, the plugin's vulnerability history is a notable concern. While there are no currently unpatched vulnerabilities, the presence of a past high severity CVE related to Cross-site Scripting indicates that vulnerabilities have existed. The fact that the last known vulnerability was in August 2022, and that there's a history of such issues, suggests a potential for them to reappear if not rigorously addressed in future development. The taint analysis showing zero flows is excellent, but this is balanced by the historical vulnerability data.
In conclusion, "debug-bar-elasticpress" v3.1.1 exhibits strong defensive coding in its current static analysis, with minimal attack surface and good practices for SQL and output handling. The primary weakness lies in its past vulnerability history, specifically XSS, which warrants continued vigilance and thorough security reviews for future versions.
Key Concerns
- Past high severity CVE exists
- Past vulnerability (2022)
ElasticPress Debugging Add-On Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Debug Bar ElasticPress <= 2.1.0 - Cross-Site Scripting
ElasticPress Debugging Add-On Code Analysis
Output Escaping
ElasticPress Debugging Add-On Attack Surface
WordPress Hooks 24
Maintenance & Trust
ElasticPress Debugging Add-On Maintenance & Trust
Maintenance Signals
Community Trust
ElasticPress Debugging Add-On Alternatives
Query Monitor – The developer tools panel for WordPress
query-monitor
Query Monitor is the developer tools panel for WordPress and WooCommerce.
Debug Bar Rewrite Rules
debug-bar-rewrite-rules
Debug Bar Rewrite Rules adds a new panel to Debug Bar that displays information about WordPress Rewrites Rules (if used).
Black Bar
blackbar
Black Bar is an unobtrusive Debug Bar for WordPress developers that attaches itself to the bottom of the browser window.
Debug Bar Actions and Filters Addon
debug-bar-actions-and-filters-addon
Displays all the hooks( Actions and Filters ) for the current request in Debug Bar panel.
Debug Bar Cron
debug-bar-cron
Debug Bar Cron adds a new panel to Debug Bar that displays information about WP scheduled events.
ElasticPress Debugging Add-On Developer Profile
23 plugins · 1.4M total installs
How We Detect ElasticPress Debugging Add-On
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/debug-bar-elasticpress/assets/js/main.js/wp-content/plugins/debug-bar-elasticpress/assets/css/main.css/wp-content/plugins/debug-bar-elasticpress/assets/js/main.jsdebug-bar-elasticpress/assets/js/main.js?ver=debug-bar-elasticpress/assets/css/main.css?ver=HTML / DOM Fingerprints
ep-debug-bar-warning