
DockTHOR Security & Risk Analysis
wordpress.org/plugins/dockthorDockTHOR is a lightweight WordPress integration for sending PHP errors and exceptions to the THOR monitoring platform.
Is DockTHOR Safe to Use in 2026?
Generally Safe
Score 100/100DockTHOR has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "dockthor" v1.0.0 demonstrates a strong security posture based on the provided static analysis. There are no identified entry points such as AJAX handlers, REST API routes, shortcodes, or cron events that lack authentication or permission checks. The code also shows excellent practices in preventing common vulnerabilities: no dangerous functions were detected, all SQL queries use prepared statements, and all output is properly escaped. Furthermore, there are no file operations, external HTTP requests, or non-existent nonce/capability checks, which significantly reduces the potential attack surface.
The taint analysis also reveals no identified flows with unsanitized paths, indicating that data is likely handled safely. The plugin's vulnerability history is clean, with zero known CVEs, suggesting a track record of secure development or a lack of past scrutiny. The bundling of Guzzle v1.1 is a minor concern as older versions might contain vulnerabilities, but without specific details on Guzzle's versioning and its security record, it's difficult to assign a high risk.
In conclusion, "dockthor" v1.0.0 appears to be a very secure plugin. Its strengths lie in its minimal attack surface and adherence to secure coding practices like prepared statements and output escaping. The lack of any detected vulnerabilities or concerning taint flows is highly positive. The only potential area for improvement is ensuring bundled libraries are kept up-to-date, though this is not a critical issue based on the current data.
Key Concerns
- Bundled library Guzzle v1.1 potentially outdated
DockTHOR Security Vulnerabilities
DockTHOR Release Timeline
DockTHOR Code Analysis
Bundled Libraries
Output Escaping
DockTHOR Attack Surface
WordPress Hooks 7
Maintenance & Trust
DockTHOR Maintenance & Trust
Maintenance Signals
Community Trust
DockTHOR Alternatives
Error Notifier for Slack
error-notifier
Get real-time Slack notifications for WordPress critical errors to fix site issues instantly!
Sentry for WordPress
wp-sentry-integration
A (unofficial) WordPress plugin to report PHP errors and Browser (JavaScript) errors to Sentry.
BugSnag Error Monitoring plugin
bugsnag
Automatically detects errors & crashes on your WordPress site using BugSnag to notify you by email, chat or issues system.
DecaLog
decalog
Capture and log events, metrics and traces on your site. Make WordPress observable - finally!
Developer Loggers for Simple History
developer-loggers-for-simple-history
Useful loggers for SimpleHistory for developers during development of a site or to maintain a live site.
DockTHOR Developer Profile
2 plugins · 200 total installs
How We Detect DockTHOR
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.