
Display Server Info Security & Risk Analysis
wordpress.org/plugins/display-server-infoDisplays server, PHP, and database info in the dashboard, admin bar, and footer, with shortcode and multilingual support.
Is Display Server Info Safe to Use in 2026?
Generally Safe
Score 100/100Display Server Info has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'display-server-info' plugin version 2.2.0 exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, a complete reliance on prepared statements for SQL queries, and an extremely high percentage of properly escaped output are significant strengths. Furthermore, the plugin demonstrates good security practices by implementing capability checks and nonce checks on its entry points, indicating a deliberate effort to prevent unauthorized actions and cross-site request forgery. The lack of any known historical vulnerabilities further reinforces this positive assessment.
However, a few minor areas warrant attention. The presence of two external HTTP requests, while not inherently malicious, could potentially introduce risks if the target servers are compromised or if the plugin doesn't handle responses securely. While the taint analysis shows no unsanitized flows, a more thorough review of how data from these external requests is handled would be prudent. The limited number of entry points (4) and the fact that all are protected is a major positive, minimizing the plugin's attack surface. Overall, this plugin appears to be well-secured, with a focus on fundamental security principles, though the external requests are a minor point of caution.
Key Concerns
- External HTTP requests present
Display Server Info Security Vulnerabilities
Display Server Info Code Analysis
SQL Query Safety
Output Escaping
Display Server Info Attack Surface
AJAX Handlers 3
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
Display Server Info Maintenance & Trust
Maintenance Signals
Community Trust
Display Server Info Alternatives
Server Info for Debugging
server-info-for-debugging
Displays server stats and WordPress system information for debugging purposes.
atec System Info
atec-system-info
atec System Info (Operating system, server, memory, PHP and database details)
PHP Server Info
php-server-info
A very simple plugin for displaying full PHP Info from within the WordPress Admin menu.
Web Server Information
wpheka-web-server-information
Web Server Information plugin will give you detailed information about your hosting server's configuration and installed modules.
Admin Bar Server Info
admin-bar-server-info
Lightweight plugin that displays essential server and environment information in a dropdown menu on the WordPress admin bar.
Display Server Info Developer Profile
3 plugins · 30 total installs
How We Detect Display Server Info
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/display-server-info/assets/css/disi-common-style.min.css/wp-content/plugins/display-server-info/assets/css/disi-dashboard-style.min.css/wp-content/plugins/display-server-info/assets/css/disi-more-style.min.css/wp-content/plugins/display-server-info/assets/css/bootstrap.min.css/wp-content/plugins/display-server-info/assets/js/disi-common.min.js/wp-content/plugins/display-server-info/assets/js/disi-ajax-handle.min.js/wp-content/plugins/display-server-info/assets/js/bootstrap.min.js/wp-content/plugins/display-server-info/assets/js/disi-ajax-handle.min.jsdisplay-server-info/assets/css/disi-common-style.min.css?ver=display-server-info/assets/css/disi-dashboard-style.min.css?ver=display-server-info/assets/css/disi-more-style.min.css?ver=display-server-info/assets/css/bootstrap.min.css?ver=3.3.5display-server-info/assets/js/disi-common.min.js?ver=display-server-info/assets/js/disi-ajax-handle.min.js?ver=display-server-info/assets/js/bootstrap.min.js?ver=3.3.5HTML / DOM Fingerprints
disi-display-boarddisi-line-gray-bgdisi-server-infodisi-admin-footer-infodisiAjaxObject[disi_server_info]