
Error Log Viewer By WP Guru Security & Risk Analysis
wordpress.org/plugins/error-log-viewer-wpError Log Viewer by WP Guru simplifies viewing and analyzing PHP error logs, making it easier to monitor and resolve errors quickly.
Is Error Log Viewer By WP Guru Safe to Use in 2026?
Use With Caution
Score 66/100Error Log Viewer By WP Guru has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The 'error-log-viewer-wp' plugin version 1.0.5 exhibits a mixed security posture. While it demonstrates some good practices like a high percentage of prepared SQL statements and properly escaped output, significant concerns are present. The presence of two unprotected AJAX handlers drastically expands the attack surface, creating potential entry points for malicious actors. Furthermore, the taint analysis reveals one flow with unsanitized paths, indicating a potential for path traversal vulnerabilities, even if not classified as critical in this analysis.
The vulnerability history is a major red flag. With two known CVEs, including a currently unpatched high-severity vulnerability related to SQL Injection and Path Traversal, the plugin has a documented history of exploitable flaws. The recentness of the last vulnerability (2025-04-09) suggests ongoing security issues. The use of the `unserialize` function, a known dangerous function, coupled with unsanitized path flows and a history of path traversal, raises concerns about potential remote code execution or sensitive file access.
In conclusion, while the plugin has some positive security implementations, the combination of an exposed attack surface via unprotected AJAX handlers, a critical taint flow indicating potential path traversal, the dangerous `unserialize` function, and a history of serious unpatched vulnerabilities makes this plugin a considerable security risk. Users should exercise extreme caution and prioritize patching or deactivating it.
Key Concerns
- Unpatched high-severity CVE
- Unprotected AJAX handlers
- High severity taint flow (unsanitized paths)
- Dangerous function: unserialize
- Medium severity CVE (now patched, but historical risk)
Error Log Viewer By WP Guru Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Error Log Viewer <= 1.0.5 - Authenticated (Subscriber+) SQL Injection
Error Log Viewer By WP Guru <= 1.0.1.3 - Missing Authorization to Unauthenticated Arbitrary File Read
Error Log Viewer By WP Guru Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Error Log Viewer By WP Guru Attack Surface
AJAX Handlers 7
WordPress Hooks 16
Scheduled Events 1
Maintenance & Trust
Error Log Viewer By WP Guru Maintenance & Trust
Maintenance Signals
Community Trust
Error Log Viewer By WP Guru Alternatives
Error Log Monitor
error-log-monitor
Adds a Dashboard widget that displays the latest messages from your PHP error log. It can also send logged errors to email.
Error Log Viewer by BestWebSoft
error-log-viewer
Get latest error log messages to diagnose website problems. Define and fix issues faster.
Debug
debug
Debug can help you to find errors in your wordpress website via editing wp-config.php file and email notification.
Quick debug.log Viewer
quick-debug-log-viewer
Easily view and manage your WordPress debug.log file directly from the admin area — no FTP access required.
LH Javascript Error log
lh-javascript-error-log
Log Javascript errors from your browser to your wordpress error log.
Error Log Viewer By WP Guru Developer Profile
1 plugin · 90 total installs
How We Detect Error Log Viewer By WP Guru
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/error-log-viewer-wp/assets/css/elvwp-style.css/wp-content/plugins/error-log-viewer-wp/assets/js/elvwp-script.js/wp-content/plugins/error-log-viewer-wp/assets/js/elvwp-script.jserror-log-viewer-wp/assets/css/elvwp-style.css?ver=error-log-viewer-wp/assets/js/elvwp-script.js?ver=HTML / DOM Fingerprints
elvwp-error-log-viewer-wp-wrap<!-- The Error Log Viewer By WP Guru --><!-- END Error Log Viewer By WP Guru --><!-- START Error Log Viewer By WP Guru -->data-elvwp-nonceelvwp_data