
EZ SQL Reports Shortcode Widget and DB Backup Security & Risk Analysis
wordpress.org/plugins/elisqlreportsCreate and save SQL Reports in your WP Admin and place them on pages and posts with a shortcode. Keep your database safe with automatic backups.
Is EZ SQL Reports Shortcode Widget and DB Backup Safe to Use in 2026?
Generally Safe
Score 94/100EZ SQL Reports Shortcode Widget and DB Backup has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin elisqlreports v5.25.25 exhibits a mixed security posture. While it demonstrates strengths in using prepared statements for all SQL queries and performing nonce checks on entry points, there are significant concerns. The static analysis reveals a considerable number of dangerous functions, specifically `passthru`, which can lead to arbitrary code execution if not handled with extreme care and strict input validation. Furthermore, the output escaping is only 43% properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities where user-supplied data might be rendered directly in the browser without proper sanitization. The historical vulnerability data reveals a concerning pattern of past security issues, including one high and four medium severity vulnerabilities, primarily related to CSRF and XSS. Although there are no currently unpatched CVEs, the recurring nature of these vulnerability types suggests potential ongoing weaknesses in input sanitization and output encoding practices. The plugin has a total of 5 known CVEs, which is a notable number for a single plugin, indicating a history of security flaws. The last vulnerability was also very recent, suggesting that new issues may still be discovered or introduced.
Key Concerns
- Presence of dangerous function `passthru`
- Low output escaping rate (43%)
- High historical vulnerability count (5 CVEs)
- Past high severity vulnerability (1)
- Past medium severity vulnerabilities (4)
- Recent vulnerability discovery (2025-06-28)
EZ SQL Reports Shortcode Widget and DB Backup Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
EZ SQL Reports Shortcode Widget and DB Backup <= 5.25.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via SQLREPORT Shortcode
EZ SQL Reports Shortcode Widget and DB Backup <= 5.25.08 - Cross-Site Request Forgery to Stored Cross-Site Scripting
EZ SQL Reports Shortcode Widget and DB Backup <= 5.25.08 - Cross-Site Request Forgery
EZ SQL Reports Shortcode Widget and DB Backup 4.11.13 - 5.25.08 - Cross-Site Request Forgery to Remote Code Execution
EZ SQL Reports Shortcode Widget and DB Backup <= 5.21.35 - Authenticated (Contributor+) Stored Cross-Site Scripting
EZ SQL Reports Shortcode Widget and DB Backup Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
EZ SQL Reports Shortcode Widget and DB Backup Attack Surface
Shortcodes 3
WordPress Hooks 9
Scheduled Events 4
Maintenance & Trust
EZ SQL Reports Shortcode Widget and DB Backup Maintenance & Trust
Maintenance Signals
Community Trust
EZ SQL Reports Shortcode Widget and DB Backup Alternatives
Database Backup for WordPress
wp-db-backup
Database Backup for WordPress is your one-stop database backup solution for WordPress.
DBC Backup 2
dbc-backup-2
DBC Backup 2 is a safe & simple way to schedule regular WordPress database backups using the wp-cron batch jobs.
WP-Database-Optimizer-Tools
wp-database-optimizer-tools
WP-Database-Optimizer helps you to optimize your database by performing some actions for example optimizing tables, deleting revisions and data that c …
inx All Backup
inx-all-backup
WordPressサイト全体のバックアップと復元が簡単に行えるプラグイン
Pitta Migration
pitta-migration
Migrate WordPress databases using WP_HOME and WP_SITEURL constants.
EZ SQL Reports Shortcode Widget and DB Backup Developer Profile
9 plugins · 101K total installs
How We Detect EZ SQL Reports Shortcode Widget and DB Backup
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/elisqlreports/images/btn_donateCC_WIDE.gifelisqlreports/index.php?ver=elisqlreports/js/elisqlreports.js?ver=HTML / DOM Fingerprints
metabox-holderstuffboxhndleinsidebutton-primary Silence is golden.id="top_title"id="admin-page-container"id="ELISQLREPORTS-right-sidebar"id="ELISQLREPORTS-main-section"id="ELISQLREPORTS-metabox-container"id="SQLFormDel"+7 morewindow.ELISQLREPORTSvar func[ELISQLREPORTS]