Find Slow Functions & Actions & Filters & Hooks (Debug Bar) Security & Risk Analysis

wordpress.org/plugins/debug-functions-time

[ โœ… ๐’๐„๐‚๐”๐‘๐„ ๐๐‹๐”๐†๐ˆ๐๐’ b๐“Ž ๐’ซ๐“Š๐“‹๐‘œ๐“] THE ONLY PLUGIN which finds & measures slow functions, actions, filters ...

0 active installs v1.44 PHP + WP 6.0+ Updated Unknown
bardebugfunctionslowtime
100
A ยท Safe
CVEs total1
Unpatched0
Last CVEAug 1, 2022
Safety Verdict

Is Find Slow Functions & Actions & Filters & Hooks (Debug Bar) Safe to Use in 2026?

Generally Safe

Score 100/100

Find Slow Functions & Actions & Filters & Hooks (Debug Bar) has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Aug 1, 2022
Risk Assessment

The plugin 'debug-functions-time' v1.44 presents a mixed security posture. On the positive side, the static analysis reveals a very limited attack surface, with no exposed AJAX handlers, REST API routes, shortcodes, or cron events that are not protected by authentication. This significantly reduces the immediate vectors for exploitation. However, there are several concerning signals within the code itself. The presence of the `unserialize` function is a critical risk if not handled with extreme caution, as it can lead to Remote Code Execution if the serialized data is controlled by an attacker. While a majority of SQL queries use prepared statements, 23% do not, which could be a source of SQL injection vulnerabilities. Furthermore, only half of the output escaping is done properly, increasing the risk of Cross-Site Scripting (XSS) vulnerabilities, a pattern that aligns with its historical vulnerability type.

The plugin's vulnerability history shows one medium-severity CVE related to XSS, last patched in August 2022. The fact that there are no currently unpatched vulnerabilities is a good sign, indicating that the developers have addressed past issues. However, the recurring XSS theme and the presence of potential vulnerabilities like `unserialize` and unescaped output suggest a need for more robust security practices. The high percentage of flows with unsanitized paths (70%) and the identified high-severity taint flow are significant concerns that point to potential weaknesses in how data is processed and validated, even with a seemingly small attack surface. The plugin demonstrates strengths in limiting its exposure points but weaknesses in internal code hygiene and data handling.

Key Concerns

  • Dangerous function 'unserialize' found
  • 17% of SQL queries not using prepared statements
  • 52% of outputs are not properly escaped
  • 1 high severity taint flow found
  • 70% of analyzed flows have unsanitized paths
  • 1 medium severity CVE in history
Vulnerabilities
1

Find Slow Functions & Actions & Filters & Hooks (Debug Bar) Security Vulnerabilities

CVEs by Year

1 CVE in 2022
2022
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

WF-cce4a7cc-d93c-4d0e-ba63-b73bee0ea181-debug-functions-timemedium ยท 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Find Slow Functions & Actions & Filters & Hooks <= 1.40 - Reflected Cross-Site Scripting

Aug 1, 2022 Patched in 1.41 (540d)
Code Analysis
Analyzed Mar 17, 2026

Find Slow Functions & Actions & Filters & Hooks (Debug Bar) Code Analysis

Dangerous Functions
1
Raw SQL Queries
14
46 prepared
Unescaped Output
73
80 escaped
Nonce Checks
5
Capability Checks
3
File Operations
26
External Requests
4
Bundled Libraries
0

Dangerous Functions Found

unserializeif ( @unserialize($serialized_string) !== false ) return $serialized_string;library.php:3813

SQL Query Safety

77% prepared60 total queries

Output Escaping

52% escaped153 total outputs
Data Flows
7 unsanitized

Data Flow Analysis

10 flows7 with unsanitized paths
enable_display_set (index.php:441)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Find Slow Functions & Actions & Filters & Hooks (Debug Bar) Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 37
actioninitindex.php:40
actionallindex.php:44
actionwp_headindex.php:50
actionadmin_headindex.php:51
actionwp_headlibrary.php:4768
actionadmin_headlibrary.php:4769
actionwp_enqueue_scriptslibrary_wp.php:73
actionadmin_enqueue_scriptslibrary_wp.php:74
actionadmin_footerlibrary_wp.php:148
actioninitlibrary_wp.php:163
actionadmin_initlibrary_wp.php:210
filtermce_external_pluginslibrary_wp.php:212
filtermce_buttons_2library_wp.php:213
filtertiny_mce_versionlibrary_wp.php:215
actionwplibrary_wp.php:231
actionplugins_loadedlibrary_wp.php:540
actionwplibrary_wp.php:550
actionwp_footerlibrary_wp.php:700
actioninitlibrary_wp.php:711
actionwp_loadedlibrary_wp.php:854
actionshutdownlibrary_wp.php:859
actioninitlibrary_wp.php:1732
actionadmin_headlibrary_wp.php:1743
actioncurrent_screenlibrary_wp.php:1744
actionwplibrary_wp.php:1753
filterupload_mimeslibrary_wp.php:1759
filterwp_handle_uploadlibrary_wp.php:1760
actioninitlibrary_wp.php:1822
actionnetwork_admin_menulibrary_wp.php:1912
actionadmin_menulibrary_wp.php:1914
actionactivated_pluginlibrary_wp.php:1916
actionnetwork_admin_noticeslibrary_wp.php:2103
actionadmin_noticeslibrary_wp.php:2104
filterwp_php_error_messagelibrary_wp.php:2187
actionwp_footerlibrary_wp.php:2375
filterwidget_textlibrary_wp.php:2399
filtersite_transient_update_pluginslibrary_wp.php:3266
Maintenance & Trust

Find Slow Functions & Actions & Filters & Hooks (Debug Bar) Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedUnknown
PHP min version
Downloads4K

Community Trust

Rating76/100
Number of ratings8
Active installs0
Developer Profile

Find Slow Functions & Actions & Filters & Hooks (Debug Bar) Developer Profile

Puvox Software

16 plugins ยท 51K total installs

75
trust score
Avg Security Score
94/100
Avg Patch Time
540 days
View full developer profile
Detection Fingerprints

How We Detect Find Slow Functions & Actions & Filters & Hooks (Debug Bar)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/debug-functions-time/style.css
Script Paths
/wp-content/plugins/debug-functions-time/debug.js
Version Parameters
debug-functions-time/style.css?ver=debug-functions-time/debug.js?ver=

HTML / DOM Fingerprints

CSS Classes
trace_debuginactiveactivetitle1headRownoticfirst_rowhead_tr+11 more
HTML Comments
<!-- trace_debug --><!-- standard way --><!-- my tryout to sort them with PHP, failed... pastebin(dot)com/raw/qcmw6pbc -->
Data Attributes
id="trace_debug"class="inactive"style="background:red; padding:10px;"class="title1"href="javascript:show_fully();"data-action-name+3 more
JS Globals
window.DFTwp_ARRAYvar DFTwp_countervar DFTwp_implemented_11var DFTwp_END_TIME
FAQ

Frequently Asked Questions about Find Slow Functions & Actions & Filters & Hooks (Debug Bar)