
DreamCore Monitor Security & Risk Analysis
wordpress.org/plugins/dreamcore-monitorWordPress monitoring solution that tracks login attempts, core status, plugin updates, theme status, and file integrity.
Is DreamCore Monitor Safe to Use in 2026?
Generally Safe
Score 100/100DreamCore Monitor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "dreamcore-monitor" v1.1.0 plugin exhibits a generally strong security posture, with a well-defined attack surface that appears to be protected by authorization checks. The absence of known CVEs and a clean vulnerability history are positive indicators. The code also demonstrates good practices with a high percentage of SQL queries using prepared statements and a reasonable rate of output escaping.
However, the static analysis reveals two concerning taint flows with unsanitized paths. While rated as high severity, their specific impact isn't detailed, but they represent potential vectors for malicious input to be processed without proper sanitization, which could lead to vulnerabilities if exploited. Additionally, the presence of external HTTP requests, while not inherently a vulnerability, could be a point of concern if they are not implemented securely and can be influenced by user input or external factors.
Overall, "dreamcore-monitor" v1.1.0 is a reasonably secure plugin, especially given its lack of past vulnerabilities. The primary area for improvement lies in thoroughly investigating and sanitizing the identified unsanitized taint flows. Addressing these potential weaknesses will further strengthen its security.
Key Concerns
- High severity unsanitized taint flows
- External HTTP requests present
DreamCore Monitor Security Vulnerabilities
DreamCore Monitor Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
DreamCore Monitor Attack Surface
REST API Routes 12
WordPress Hooks 24
Scheduled Events 1
Maintenance & Trust
DreamCore Monitor Maintenance & Trust
Maintenance Signals
Community Trust
DreamCore Monitor Alternatives
SiteSignal
sitesignal
SiteSignal WordPress connector for AI visibility, website health, performance monitoring, and technical audits.
Loginizer
loginizer
Loginizer is a WordPress security plugin which helps you fight against bruteforce attacks.
WP Ghost (Hide My WP Ghost) – Security & Firewall
hide-my-wp
Hide and Secure WP paths, wp-login, wp-admin, and more. Hack Prevention, Security, Brute Force protection, 8G Firewall, 2FA Passkey Login, and more.
Unauthorised Login Redirect
unauthorised-login-redirect
This plugin allows you to effectively hide your wp-login.php and wp-admin by requiring that you access it via a custom URL.
Protector – Login Security & Hide Admin URL
wp-admin-protect
Protect your WP Admin access. Easily change your wp-login URL by adding a secret term to hide your login page from bots and unwanted visitors.
DreamCore Monitor Developer Profile
1 plugin · 10 total installs
How We Detect DreamCore Monitor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/dreamcore-monitor/assets/css/dreamcore-monitor-public.css/wp-content/plugins/dreamcore-monitor/assets/js/dreamcore-monitor-public.js/wp-content/plugins/dreamcore-monitor/admin/css/dreamcore-monitor-admin.cssdreamcore-monitor/assets/css/dreamcore-monitor-public.css?ver=dreamcore-monitor/assets/js/dreamcore-monitor-public.js?ver=dreamcore-monitor/admin/css/dreamcore-monitor-admin.css?ver=HTML / DOM Fingerprints
integrity-statsstat-itemstat-item.not-modifiedstat-item.modifiedstat-item.missingstat-numberstat-labeldreamcore-monitor-notice+8 morePlugin Name: DreamCore MonitorDescription: A comprehensive WordPress monitoring solution that tracks login attempts, core status, plugin updates, theme status, file integrity, and WooCommerce orders with REST API support.Copyright (c) 2023 IF Solutions. All rights reserved.UPGRADE NOTICE:+7 moredata-dcm-action="export_logins"DreamcoreMonitorAdmindcm_monitor_ajax_object/wp-json/dreamcore-monitor/v1/settings/wp-json/dreamcore-monitor/v1/logs/wp-json/dreamcore-monitor/v1/security-scan/wp-json/dreamcore-monitor/v1/file-integrity[dreamcore_monitor_dashboard][dreamcore_monitor_security_alert][dreamcore_monitor_file_integrity_report]