
GLOBUS Debug Control Security & Risk Analysis
wordpress.org/plugins/globus-debug-controlWordPress debug toolkit: filter errors, toggle WP_DEBUG, view error logs, monitor cron, transients, HTTP requests, and more.
Is GLOBUS Debug Control Safe to Use in 2026?
Generally Safe
Score 100/100GLOBUS Debug Control has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "globus-debug-control" plugin v2.2.5 exhibits a generally strong security posture, with robust use of security best practices. All identified AJAX handlers include authentication checks, and no shortcodes, cron events, or REST API routes were found, significantly limiting the plugin's attack surface. The code also demonstrates excellent SQL sanitation through the exclusive use of prepared statements and a very high percentage (98%) of properly escaped output. Furthermore, the presence of nonce and capability checks on all entry points and file operations indicates a deliberate effort to secure these areas. The plugin has no recorded vulnerability history, which is a very positive indicator.
However, a few areas warrant attention. The presence of five instances of the `ini_set` function, while not inherently a vulnerability, can be a risk if misused to alter sensitive PHP configurations in a way that could be exploited. Additionally, the taint analysis revealed one flow with an unsanitized path. While no critical or high severity issues were flagged in the taint analysis, an unsanitized path represents a potential entry point for path traversal or file inclusion vulnerabilities. The absence of external HTTP requests is a positive aspect, reducing the risk of server-side request forgery (SSRF) or compromised external services.
In conclusion, the "globus-debug-control" plugin v2.2.5 is largely well-secured, with strong adherence to common WordPress security practices. The lack of historical vulnerabilities and the secure handling of SQL and output are significant strengths. The primary concerns are the potential risks associated with the use of `ini_set` and the single identified unsanitized path flow, which, though not rated as critical, should be addressed to further strengthen the plugin's security.
Key Concerns
- Unsanitized path flow found
- Use of dangerous function (ini_set)
GLOBUS Debug Control Security Vulnerabilities
GLOBUS Debug Control Release Timeline
GLOBUS Debug Control Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
GLOBUS Debug Control Attack Surface
AJAX Handlers 10
WordPress Hooks 15
Maintenance & Trust
GLOBUS Debug Control Maintenance & Trust
Maintenance Signals
Community Trust
GLOBUS Debug Control Alternatives
0 Day Analytics
0-day-analytics
0 Day Analytics is a comprehensive WordPress debugging and operational
All-in-One Debug Lab
all-in-one-debug-lab
The "All-in-One Debug Lab" plugin, makes it easy to search and locate errors in wordpress.
Developer Debug Mode
developer-debug-mode
Toggle WordPress debug mode instantly. No wp-config.php editing needed. Features auto-save, admin bar quick toggle, and debug log viewer.
WP Crontrol
wp-crontrol
WP Crontrol enables you to take control of the cron events on your WordPress website.
WP Debugging
wp-debugging
A support/troubleshooting plugin for WordPress.
GLOBUS Debug Control Developer Profile
2 plugins · 2K total installs
How We Detect GLOBUS Debug Control
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/globus-debug-control/assets/css/admin-error-log-viewer.css/wp-content/plugins/globus-debug-control/assets/css/admin-settings.css/wp-content/plugins/globus-debug-control/assets/css/frontend-php-error-display.css/wp-content/plugins/globus-debug-control/assets/css/gdc-admin-page.css/wp-content/plugins/globus-debug-control/assets/js/admin-cron-viewer.js/wp-content/plugins/globus-debug-control/assets/js/admin-error-log-viewer.js/wp-content/plugins/globus-debug-control/assets/js/admin-http-log.js/wp-content/plugins/globus-debug-control/assets/js/admin-settings.js+4 more/wp-content/plugins/globus-debug-control/assets/js/admin-cron-viewer.js/wp-content/plugins/globus-debug-control/assets/js/admin-error-log-viewer.js/wp-content/plugins/globus-debug-control/assets/js/admin-http-log.js/wp-content/plugins/globus-debug-control/assets/js/admin-settings.js/wp-content/plugins/globus-debug-control/assets/js/admin-transient-viewer.js/wp-content/plugins/globus-debug-control/assets/js/constants-viewer.js+2 moreglobus-debug-control/assets/css/admin-error-log-viewer.css?ver=globus-debug-control/assets/css/admin-settings.css?ver=globus-debug-control/assets/css/frontend-php-error-display.css?ver=globus-debug-control/assets/css/gdc-admin-page.css?ver=globus-debug-control/assets/js/admin-cron-viewer.js?ver=globus-debug-control/assets/js/admin-error-log-viewer.js?ver=globus-debug-control/assets/js/admin-http-log.js?ver=globus-debug-control/assets/js/admin-settings.js?ver=globus-debug-control/assets/js/admin-transient-viewer.js?ver=globus-debug-control/assets/js/constants-viewer.js?ver=globus-debug-control/assets/js/gdc-admin-page.js?ver=globus-debug-control/assets/js/frontend-php-error-display.js?ver=HTML / DOM Fingerprints
gdc-debug-badgegdc-debug-ongdc-debug-offgdc-tab-contentdata-gdc-tab