
Debug Bar Screen Info Security & Risk Analysis
wordpress.org/plugins/debug-bar-screen-infoShow screen info of the current admin page in a new tab within the debug bar
Is Debug Bar Screen Info Safe to Use in 2026?
Generally Safe
Score 100/100Debug Bar Screen Info has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "debug-bar-screen-info" plugin, version 1.1.5, exhibits a generally strong security posture based on the provided static analysis. It lacks any identified attack vectors such as AJAX handlers, REST API routes, or shortcodes, which significantly reduces its potential for external exploitation. Furthermore, its SQL queries are exclusively using prepared statements, and it demonstrates a good level of output escaping (78%), mitigating common injection vulnerabilities. The absence of known CVEs and a clean vulnerability history is also a positive indicator of its security.
However, there are notable concerns. The presence of the `create_function` dangerous function is a significant red flag. While not directly tied to an attack surface in this analysis, `create_function` is deprecated and can lead to serious security vulnerabilities if not handled with extreme care, particularly if its output is ever user-controlled. Additionally, the complete lack of nonce checks, even with a capability check present, is a weakness. While the attack surface appears limited, any future addition of user-facing features without proper nonce validation could introduce cross-site request forgery (XRF) risks.
Overall, while the plugin has strong defenses against common web vulnerabilities and a clean historical record, the use of `create_function` and the absence of nonce checks represent areas where future improvements are warranted to maintain a robust security profile.
Key Concerns
- Dangerous function found (create_function)
- Missing nonce checks
Debug Bar Screen Info Security Vulnerabilities
Debug Bar Screen Info Code Analysis
Dangerous Functions Found
Output Escaping
Debug Bar Screen Info Attack Surface
WordPress Hooks 6
Maintenance & Trust
Debug Bar Screen Info Maintenance & Trust
Maintenance Signals
Community Trust
Debug Bar Screen Info Alternatives
Query Monitor – The developer tools panel for WordPress
query-monitor
Query Monitor is the developer tools panel for WordPress and WooCommerce.
ElasticPress Debugging Add-On
debug-bar-elasticpress
Extends the Query Monitor and Debug Bar plugins for ElasticPress queries.
Debug Bar Rewrite Rules
debug-bar-rewrite-rules
Debug Bar Rewrite Rules adds a new panel to Debug Bar that displays information about WordPress Rewrites Rules (if used).
Black Bar
blackbar
Black Bar is an unobtrusive Debug Bar for WordPress developers that attaches itself to the bottom of the browser window.
Debug Bar Actions and Filters Addon
debug-bar-actions-and-filters-addon
Displays all the hooks( Actions and Filters ) for the current request in Debug Bar panel.
Debug Bar Screen Info Developer Profile
6 plugins · 7K total installs
How We Detect Debug Bar Screen Info
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/debug-bar-screen-info/css/debug-bar-screen-info.cssdebug-bar-screen-info/css/debug-bar-screen-info.css?ver=HTML / DOM Fingerprints
href="http://codex.wordpress.org/Class_Reference/WP_Screen" target="_blank" title="