Digages Website Monitor Security & Risk Analysis

wordpress.org/plugins/digages-website-monitor

Digages Website Monitor tracks visitor activity, login attempts, and theme/plugin installs and updates to keep your WordPress site secure.

0 active installs v1.0.0 PHP 7.0+ WP 5.0+ Updated Feb 9, 2026
activity-loglogin-attemptsmonitoringsecuritywebsite-analytics
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Digages Website Monitor Safe to Use in 2026?

Generally Safe

Score 100/100

Digages Website Monitor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "digages-website-monitor" plugin v1.0.0 exhibits a generally strong security posture, largely due to its diligent implementation of security best practices. The absence of any recorded vulnerabilities or CVEs, coupled with a high percentage of prepared SQL statements and properly escaped output, indicates a proactive approach to secure coding. Furthermore, the presence of nonce and capability checks on its AJAX handlers, along with a contained attack surface with all entry points protected by authorization checks, significantly reduces the likelihood of common web vulnerabilities.

However, a closer look at the static analysis reveals a couple of areas that warrant attention. The taint analysis identified two flows with unsanitized paths. While no critical or high severity issues were flagged from these flows, unsanitized paths can sometimes be precursors to path traversal or arbitrary file read/write vulnerabilities, especially if they interact with file operations or external HTTP requests. The plugin also performs two file operations and two external HTTP requests, which, while not inherently insecure, could become points of compromise if not handled with extreme care and robust input validation and sanitization on any user-supplied data that influences these operations.

In conclusion, "digages-website-monitor" v1.0.0 is a well-developed plugin from a security perspective, with a commendable track record and adherence to many security best practices. The primary area for improvement lies in thoroughly auditing and sanitizing the identified unsanitized path flows. Addressing these minor concerns would further solidify its security and mitigate potential, albeit currently low, risks.

Key Concerns

  • Flows with unsanitized paths
Vulnerabilities
None known

Digages Website Monitor Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Digages Website Monitor Code Analysis

Dangerous Functions
0
Raw SQL Queries
11
25 prepared
Unescaped Output
1
186 escaped
Nonce Checks
8
Capability Checks
2
File Operations
2
External Requests
2
Bundled Libraries
0

SQL Query Safety

69% prepared36 total queries

Output Escaping

99% escaped187 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

4 flows2 with unsanitized paths
digages_wpusermon_ajax_track_page_time (includes\activity-tracker.php:383)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Digages Website Monitor Attack Surface

Entry Points4
Unprotected0

AJAX Handlers 4

authwp_ajax_digages_track_page_timeincludes\activity-tracker.php:32
noprivwp_ajax_digages_track_page_timeincludes\activity-tracker.php:33
authwp_ajax_digages_delete_logincludes\ajax-handlers.php:10
authwp_ajax_digages_clear_all_logsincludes\ajax-handlers.php:11
WordPress Hooks 20
actionplugins_loadeddigages-website-monitor.php:44
actionadmin_enqueue_scriptsdigages-website-monitor.php:80
actionwp_loginincludes\activity-tracker.php:11
actionwp_logoutincludes\activity-tracker.php:14
actionpublish_postincludes\activity-tracker.php:17
actionpost_updatedincludes\activity-tracker.php:18
actionbefore_delete_postincludes\activity-tracker.php:19
actioninitincludes\activity-tracker.php:22
actionadmin_initincludes\activity-tracker.php:25
actionwp_footerincludes\activity-tracker.php:30
actionadmin_footerincludes\activity-tracker.php:31
actionactivated_pluginincludes\admin-alerts.php:11
actionupgrader_process_completeincludes\admin-alerts.php:12
actionswitch_themeincludes\admin-alerts.php:15
actionadmin_initincludes\admin-menu.php:90
actionadmin_menuincludes\admin-menu.php:96
actiondigages_wpusermon_cleanup_logsincludes\install.php:160
filterauthenticateincludes\login-monitor.php:10
actionwp_login_failedincludes\login-monitor.php:11
actionwp_loginincludes\login-monitor.php:12

Scheduled Events 1

digages_wpusermon_cleanup_logs
Maintenance & Trust

Digages Website Monitor Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 9, 2026
PHP min version7.0
Downloads134

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Digages Website Monitor Developer Profile

Digages

5 plugins · 850 total installs

88
trust score
Avg Security Score
91/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Digages Website Monitor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/digages-website-monitor/assets/css/admin.css/wp-content/plugins/digages-website-monitor/assets/css/about.css/wp-content/plugins/digages-website-monitor/assets/js/admin.js/wp-content/plugins/digages-website-monitor/assets/js/install-plugin.js
Script Paths
/wp-content/plugins/digages-website-monitor/assets/js/admin.js/wp-content/plugins/digages-website-monitor/assets/js/install-plugin.js
Version Parameters
digages-website-monitor/assets/css/admin.css?ver=digages-website-monitor/assets/css/about.css?ver=digages-website-monitor/assets/js/admin.js?ver=digages-website-monitor/assets/js/install-plugin.js?ver=

HTML / DOM Fingerprints

Data Attributes
digages-wp-website-monitor-settings
JS Globals
digagesUserMon
FAQ

Frequently Asked Questions about Digages Website Monitor