
Debug Log Viewer Security & Risk Analysis
wordpress.org/plugins/debug-log-viewerEffortlessly view, search, filter and manage your WordPress debug.log in the admin dashboard. Real-time monitoring and email alerts
Is Debug Log Viewer Safe to Use in 2026?
Generally Safe
Score 99/100Debug Log Viewer has a strong security track record. Known vulnerabilities have been patched promptly.
The debug-log-viewer plugin exhibits a concerning security posture due to a significant number of unprotected AJAX handlers. While the code signals indicate good practices regarding SQL queries and output escaping, the 19 AJAX handlers operating without authentication checks represent a substantial attack surface. This means that any unauthenticated user could potentially trigger these functions, leading to unintended consequences or further exploitation if any vulnerabilities exist within them.
The taint analysis shows a worrying trend of 5 flows with unsanitized paths, though thankfully these did not reach critical or high severity. This suggests that while there may be opportunities for path manipulation, they are not currently leading to severe compromises. The plugin's vulnerability history, with one medium CVE previously, and a common pattern of missing authorization, reinforces the concern around unprotected entry points. The last reported vulnerability was in 2025, suggesting it's been patched, but the historical pattern is a red flag.
In conclusion, the plugin demonstrates strengths in secure coding practices for SQL and output handling. However, the overwhelming number of unprotected AJAX entry points is a critical weakness that overshadows these strengths. The historical trend of missing authorization vulnerabilities further emphasizes the need for robust access control on all dynamic functionalities.
Key Concerns
- 19 unprotected AJAX handlers
- 5 flows with unsanitized paths
- 1 medium CVE in history
- Common vulnerability type: Missing Authorization
- Bundled library: Freemius v1.0
Debug Log Viewer Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Debug Log Viewer <= 2.0.3 - Missing Authorization
Debug Log Viewer Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Debug Log Viewer Attack Surface
AJAX Handlers 19
WordPress Hooks 7
Maintenance & Trust
Debug Log Viewer Maintenance & Trust
Maintenance Signals
Community Trust
Debug Log Viewer Alternatives
LogIQ
log-iq
A powerful and user-friendly debug log viewer for WordPress with editor integration.
Daisy Debug – Easy WP Debugging, Enable WP Debug, View Error Logs, Download Debug Log
daisy-debug
A beautiful debugging tool that lets you manage debug settings without editing wp-config.php file.
Debug Suite
debug-suite
A powerful, enterprise-grade debugging toolkit for WordPress developers with advanced log management, error tracking, and development tools.
Easy Error Log
easy-error-log
Effortlessly track and manage WordPress debug.log on your WordPress site. Streamline the debugging process with Easy Error Log.
ErrorLyze – Error Logger & AI Debugger
errorlyze
Detect and fix WordPress PHP errors with AI-powered analysis. Automatic error logging, monitoring, and step-by-step fix recommendations for developers …
Debug Log Viewer Developer Profile
2 plugins · 1K total installs
How We Detect Debug Log Viewer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/debug-log-viewer/admin/assets/css/style.css/wp-content/plugins/debug-log-viewer/front/assets/vendor/css/font-awesome.min.css/wp-content/plugins/debug-log-viewer/front/dist/bundle.js/wp-content/plugins/debug-log-viewer/front/assets/vendor/js/font-awesome.jsdebug-log-viewer/admin/assets/css/style.css?ver=debug-log-viewer/front/dist/bundle.js?ver=debug-log-viewer/front/assets/vendor/js/font-awesome.js?ver=HTML / DOM Fingerprints
dbg_lv_plugin_wrapper<!-- Debug Log Viewer -->data-view-modedata-log-emptydata-log-filterdbg_lv_backend_datadbg_lv_freemius_data/wp-json/debug-log-viewer/v1/settings