
Environment Info Security & Risk Analysis
wordpress.org/plugins/environment-infoShow environmental info on your admin bar.
Is Environment Info Safe to Use in 2026?
Generally Safe
Score 85/100Environment Info has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'environment-info' plugin v1.1.1 presents a generally positive security posture based on the static analysis, with no identified dangerous functions, SQL queries executed via prepared statements, file operations, or external HTTP requests. The absence of known vulnerabilities in its history further reinforces this. However, a significant concern arises from the 100% unescaped output across all six identified output points. This indicates a high likelihood of Cross-Site Scripting (XSS) vulnerabilities, where malicious code could be injected and executed within the user's browser. The lack of any capability checks or nonce checks on any of the identified entry points, although the attack surface is currently zero, means that if any entry points were to be introduced in future versions, they would be unprotected.
Key Concerns
- All outputs are unescaped
- No capability checks on entry points
- No nonce checks on entry points
Environment Info Security Vulnerabilities
Environment Info Code Analysis
Output Escaping
Environment Info Attack Surface
WordPress Hooks 2
Maintenance & Trust
Environment Info Maintenance & Trust
Maintenance Signals
Community Trust
Environment Info Alternatives
Hide Admin Bar from Non-Admins
hide-admin-bar-from-non-admins
Hides the WordPress toolbar (admin bar) for all non-admin users. Simple plugin with no settings to configure.
Admin Bar & Dashboard Access Control
admin-bar-dashboard-control
Disable admin bar and control users access to WordPress dashboard.
AffiliateWP – Order Details For Affiliates
affiliatewp-order-details-for-affiliates
Allow affiliates to see order details on referrals they generated
Role Based Redirect
role-based-redirect
Redirect users after login/logout by role. Optionally hide admin bar and block dashboard access for selected roles.
WP Hide Dashboard
wp-hide-dashboard
Hide the Dashboard menu, Personal Options section and Help link on the Profile page from your subscribers when they are logged in.
Environment Info Developer Profile
22 plugins · 2K total installs
How We Detect Environment Info
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
environmentsenvis-activeenv-titleenv-info