Debug Bar for Sophi Security & Risk Analysis

wordpress.org/plugins/debug-bar-for-sophi

Extends the Debug Bar plugin for the Sophi.io Site Automation service.

0 active installs v0.3.0 PHP 7.4+ WP 5.6+ Updated Jul 7, 2022
debug-barsophi
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Debug Bar for Sophi Safe to Use in 2026?

Generally Safe

Score 85/100

Debug Bar for Sophi has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The 'debug-bar-for-sophi' plugin version 0.3.0 exhibits a generally strong security posture based on the provided static analysis. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events with unprotected entry points is a significant strength, drastically limiting the potential attack surface. The code also shows good practices regarding SQL queries, with 100% using prepared statements, and a high percentage of output being properly escaped. The presence of a nonce check and the absence of critical or high-severity taint flows further contribute to this positive assessment.

However, there are a few areas that warrant attention. The plugin performs file operations, and while the static analysis doesn't highlight specific vulnerabilities in these operations, any such activity can be a potential risk if not handled with extreme care. More importantly, the plugin has zero capability checks. This means that even if entry points were to exist or be introduced in future versions, there are no built-in WordPress role-based access controls to restrict who can interact with the plugin's functionalities. The vulnerability history being completely clean is encouraging, suggesting a history of responsible development, but the lack of capability checks remains a notable oversight that could expose features to unauthorized users if they were ever accessible.

In conclusion, 'debug-bar-for-sophi' v0.3.0 appears to be developed with security in mind, particularly in its limited attack surface and data handling. The lack of past vulnerabilities is a positive indicator. The primary weakness lies in the complete absence of capability checks, which is a fundamental security practice for plugins that might expose any form of functionality. The file operations, while not flagged as problematic, should always be reviewed with caution in any security audit.

Key Concerns

  • No capability checks found
Vulnerabilities
None known

Debug Bar for Sophi Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Debug Bar for Sophi Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
35 escaped
Nonce Checks
1
Capability Checks
0
File Operations
4
External Requests
0
Bundled Libraries
0

Output Escaping

92% escaped38 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
logs_page (includes\classes\Settings.php:93)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Debug Bar for Sophi Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 21
filtersophi_request_argsincludes\class-sophi-debug-bar-panel.php:50
filtersophi_request_resultincludes\class-sophi-debug-bar-panel.php:51
filtersophi_cms_tracking_request_dataincludes\class-sophi-debug-bar-panel.php:53
actionsophi_cms_tracking_resultincludes\class-sophi-debug-bar-panel.php:54
filtersophi_tracker_emitter_debugincludes\class-sophi-debug-bar-panel.php:56
actionadmin_initincludes\classes\Settings.php:25
actionadmin_menuincludes\classes\Settings.php:29
actionadmin_noticesincludes\core.php:27
actionadmin_noticesincludes\core.php:31
actionadmin_noticesincludes\core.php:36
filtersophi_bypass_get_cacheincludes\core.php:50
filtersophi_bypass_curated_posts_cacheincludes\core.php:53
actionwp_enqueue_scriptsincludes\core.php:56
actionwp_enqueue_scriptsincludes\core.php:57
actionadmin_enqueue_scriptsincludes\core.php:58
actionadmin_enqueue_scriptsincludes\core.php:59
filtermce_cssincludes\core.php:62
filterscript_loader_tagincludes\core.php:64
filterdebug_bar_panelsincludes\core.php:66
filterdebug_bar_enablesophi-debug-bar.php:47
actioninitsophi-debug-bar.php:50
Maintenance & Trust

Debug Bar for Sophi Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedJul 7, 2022
PHP min version7.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Debug Bar for Sophi Developer Profile

Jeffrey Paul

2 plugins · 20 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Debug Bar for Sophi

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/debug-bar-for-sophi/dist/js/shared.js/wp-content/plugins/debug-bar-for-sophi/dist/css/shared.css/wp-content/plugins/debug-bar-for-sophi/assets/css/frontend/editor-style.css/wp-content/plugins/debug-bar-for-sophi/dist/css/editor-style.min.css
Script Paths
/wp-content/plugins/debug-bar-for-sophi/dist/js/shared.js
Version Parameters
/wp-content/plugins/debug-bar-for-sophi/dist/js/shared.js?ver=/wp-content/plugins/debug-bar-for-sophi/dist/css/shared.css?ver=/wp-content/plugins/debug-bar-for-sophi/assets/css/frontend/editor-style.css?ver=/wp-content/plugins/debug-bar-for-sophi/dist/css/editor-style.min.css?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Debug Bar for Sophi