
Find Slow Functions & Actions & Filters & Hooks (Debug Bar) Security & Risk Analysis
wordpress.org/plugins/debug-functions-time[ โ ๐๐๐๐๐๐ ๐๐๐๐๐๐๐ b๐ ๐ซ๐๐๐๐] THE ONLY PLUGIN which finds & measures slow functions, actions, filters ...
Is Find Slow Functions & Actions & Filters & Hooks (Debug Bar) Safe to Use in 2026?
Generally Safe
Score 100/100Find Slow Functions & Actions & Filters & Hooks (Debug Bar) has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin 'debug-functions-time' v1.44 presents a mixed security posture. On the positive side, the static analysis reveals a very limited attack surface, with no exposed AJAX handlers, REST API routes, shortcodes, or cron events that are not protected by authentication. This significantly reduces the immediate vectors for exploitation. However, there are several concerning signals within the code itself. The presence of the `unserialize` function is a critical risk if not handled with extreme caution, as it can lead to Remote Code Execution if the serialized data is controlled by an attacker. While a majority of SQL queries use prepared statements, 23% do not, which could be a source of SQL injection vulnerabilities. Furthermore, only half of the output escaping is done properly, increasing the risk of Cross-Site Scripting (XSS) vulnerabilities, a pattern that aligns with its historical vulnerability type.
The plugin's vulnerability history shows one medium-severity CVE related to XSS, last patched in August 2022. The fact that there are no currently unpatched vulnerabilities is a good sign, indicating that the developers have addressed past issues. However, the recurring XSS theme and the presence of potential vulnerabilities like `unserialize` and unescaped output suggest a need for more robust security practices. The high percentage of flows with unsanitized paths (70%) and the identified high-severity taint flow are significant concerns that point to potential weaknesses in how data is processed and validated, even with a seemingly small attack surface. The plugin demonstrates strengths in limiting its exposure points but weaknesses in internal code hygiene and data handling.
Key Concerns
- Dangerous function 'unserialize' found
- 17% of SQL queries not using prepared statements
- 52% of outputs are not properly escaped
- 1 high severity taint flow found
- 70% of analyzed flows have unsanitized paths
- 1 medium severity CVE in history
Find Slow Functions & Actions & Filters & Hooks (Debug Bar) Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Find Slow Functions & Actions & Filters & Hooks <= 1.40 - Reflected Cross-Site Scripting
Find Slow Functions & Actions & Filters & Hooks (Debug Bar) Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Find Slow Functions & Actions & Filters & Hooks (Debug Bar) Attack Surface
WordPress Hooks 37
Maintenance & Trust
Find Slow Functions & Actions & Filters & Hooks (Debug Bar) Maintenance & Trust
Maintenance Signals
Community Trust
Find Slow Functions & Actions & Filters & Hooks (Debug Bar) Alternatives
Admin Bar Queries
admin-bar-queries
MySQL queries and load details added to your admin bar.
Query Monitor โ The developer tools panel for WordPress
query-monitor
Query Monitor is the developer tools panel for WordPress and WooCommerce.
Read Meter โ Reading Time & Progress Bar
read-meter
The Read Meter plugin displays the estimated reading time for blog posts along with a progress bar.
My WP Customize Admin/Frontend
my-wp
Simply and easy-to-use the customize for Admin and Frontend. A lot of custom filters and actions, and included the developer tools.
HashBar โ Announcement, Notification Bar & Popup Campaign
hashbar-wp-notification-bar
Create Announcement Bars, Notification Bars & Popup Campaigns with countdown timers, A/B testing, smart targeting & analytics.
Find Slow Functions & Actions & Filters & Hooks (Debug Bar) Developer Profile
16 plugins ยท 51K total installs
How We Detect Find Slow Functions & Actions & Filters & Hooks (Debug Bar)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/debug-functions-time/style.css/wp-content/plugins/debug-functions-time/debug.jsdebug-functions-time/style.css?ver=debug-functions-time/debug.js?ver=HTML / DOM Fingerprints
trace_debuginactiveactivetitle1headRownoticfirst_rowhead_tr+11 more<!-- trace_debug --><!-- standard way --><!-- my tryout to sort them with PHP, failed... pastebin(dot)com/raw/qcmw6pbc -->id="trace_debug"class="inactive"style="background:red; padding:10px;"class="title1"href="javascript:show_fully();"data-action-name+3 morewindow.DFTwp_ARRAYvar DFTwp_countervar DFTwp_implemented_11var DFTwp_END_TIME