
Digages Website Monitor Security & Risk Analysis
wordpress.org/plugins/digages-website-monitorDigages Website Monitor tracks visitor activity, login attempts, and theme/plugin installs and updates to keep your WordPress site secure.
Is Digages Website Monitor Safe to Use in 2026?
Generally Safe
Score 100/100Digages Website Monitor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "digages-website-monitor" plugin v1.0.0 exhibits a generally strong security posture, largely due to its diligent implementation of security best practices. The absence of any recorded vulnerabilities or CVEs, coupled with a high percentage of prepared SQL statements and properly escaped output, indicates a proactive approach to secure coding. Furthermore, the presence of nonce and capability checks on its AJAX handlers, along with a contained attack surface with all entry points protected by authorization checks, significantly reduces the likelihood of common web vulnerabilities.
However, a closer look at the static analysis reveals a couple of areas that warrant attention. The taint analysis identified two flows with unsanitized paths. While no critical or high severity issues were flagged from these flows, unsanitized paths can sometimes be precursors to path traversal or arbitrary file read/write vulnerabilities, especially if they interact with file operations or external HTTP requests. The plugin also performs two file operations and two external HTTP requests, which, while not inherently insecure, could become points of compromise if not handled with extreme care and robust input validation and sanitization on any user-supplied data that influences these operations.
In conclusion, "digages-website-monitor" v1.0.0 is a well-developed plugin from a security perspective, with a commendable track record and adherence to many security best practices. The primary area for improvement lies in thoroughly auditing and sanitizing the identified unsanitized path flows. Addressing these minor concerns would further solidify its security and mitigate potential, albeit currently low, risks.
Key Concerns
- Flows with unsanitized paths
Digages Website Monitor Security Vulnerabilities
Digages Website Monitor Release Timeline
Digages Website Monitor Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Digages Website Monitor Attack Surface
AJAX Handlers 4
WordPress Hooks 20
Scheduled Events 1
Maintenance & Trust
Digages Website Monitor Maintenance & Trust
Maintenance Signals
Community Trust
Digages Website Monitor Alternatives
Unstoppable Activity Tracker
unstoppable-activity-tracker
Standalone activity tracker. Records site events to a local database table and exposes them via a secure, API-key-protected REST endpoint.
Deviser Shield – Instant Activity & File Change Alert
deviser-shield
Monitor WordPress plugin activity and receive instant email alerts for activations, deactivations, deletions, and file changes.
Kovalenko Admin Change Audit
kovalenko-admin-change-audit
Records important WordPress activity and provides an owner-only log viewer for monitoring client changes.
ActivityPilot
activitypilot
Track, visualize, and analyze admin and user activity in a timeline UI with break detection, workflows, REST API, and exportable audit logs.
Bat Activity Log
bat-activity-log
Track important WordPress activity with detailed audit logs, filters, alerts, reports, and integrity checks.
Digages Website Monitor Developer Profile
7 plugins · 940 total installs
How We Detect Digages Website Monitor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/digages-website-monitor/assets/css/admin.css/wp-content/plugins/digages-website-monitor/assets/css/about.css/wp-content/plugins/digages-website-monitor/assets/js/admin.js/wp-content/plugins/digages-website-monitor/assets/js/install-plugin.js/wp-content/plugins/digages-website-monitor/assets/js/admin.js/wp-content/plugins/digages-website-monitor/assets/js/install-plugin.jsdigages-website-monitor/assets/css/admin.css?ver=digages-website-monitor/assets/css/about.css?ver=digages-website-monitor/assets/js/admin.js?ver=digages-website-monitor/assets/js/install-plugin.js?ver=HTML / DOM Fingerprints
digages-wp-website-monitor-settingsdigagesUserMon