
Debug Bar Query Tracer Security & Risk Analysis
wordpress.org/plugins/debug-bar-query-tracerA Debug Bar plugin that lets you trace what plugins are causing database queries.
Is Debug Bar Query Tracer Safe to Use in 2026?
Generally Safe
Score 100/100Debug Bar Query Tracer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The security posture of the debug-bar-query-tracer plugin v0.1 appears to be quite good based on the provided static analysis. There are no identified attack vectors such as AJAX handlers, REST API routes, or shortcodes exposed to potential attackers. The absence of dangerous functions, file operations, and external HTTP requests further strengthens its security. Importantly, all SQL queries are utilizing prepared statements, mitigating the risk of SQL injection vulnerabilities.
However, a significant concern arises from the output escaping. With 100% of the identified outputs not being properly escaped, this presents a clear risk of Cross-Site Scripting (XSS) vulnerabilities. Any data displayed by the plugin that originates from user input or external sources could potentially be exploited. The plugin also has no recorded vulnerability history, which is positive, but this could also indicate a lack of rigorous security testing or a very small user base.
In conclusion, while the plugin exhibits strong security practices in its input handling and data access layers, the lack of output escaping is a critical flaw that needs immediate attention. The absence of vulnerabilities in its history is a good sign, but it shouldn't overshadow the identified XSS risk. Addressing the output escaping is paramount to improving the plugin's overall security.
Key Concerns
- Unescaped output detected
Debug Bar Query Tracer Security Vulnerabilities
Debug Bar Query Tracer Code Analysis
Output Escaping
Debug Bar Query Tracer Attack Surface
WordPress Hooks 2
Maintenance & Trust
Debug Bar Query Tracer Maintenance & Trust
Maintenance Signals
Community Trust
Debug Bar Query Tracer Alternatives
Query Monitor – The developer tools panel for WordPress
query-monitor
Query Monitor is the developer tools panel for WordPress and WooCommerce.
Script Report
script-report
Debug and audit JavaScript and CSS loading in WordPress. Analyze dependencies, detect issues, and improve performance on any page.
LiteSpeed Cache
litespeed-cache
All-in-one unbeatable acceleration & PageSpeed improvement: caching, image/CSS/JS optimization...
Jetpack – WP Security, Backup, Speed, & Growth
jetpack
Improve your WP security with powerful one-click tools like backup, WAF, and malware scan. Includes free tools like stats, CDN and social sharing.
Image Optimizer – Optimize Images and Convert to WebP or AVIF
image-optimization
Automatically resize, optimize, and convert images to WebP and AVIF. Compress images in bulk or on upload to boost your WordPress site performance.
Debug Bar Query Tracer Developer Profile
2 plugins · 60 total installs
How We Detect Debug Bar Query Tracer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/debug-bar-query-tracer/Tracer.php/wp-content/plugins/debug-bar-query-tracer/Panel.php