
Hack-Info Security & Risk Analysis
wordpress.org/plugins/hack-infoExt Security. Monitoring about evil hacking attempts. Our reports - Simply, Briefly and in Detail.
Is Hack-Info Safe to Use in 2026?
Generally Safe
Score 99/100Hack-Info has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "hack-info" plugin v4.25 demonstrates a generally good security posture, with no critical or high-severity vulnerabilities identified in static and taint analysis. The plugin utilizes prepared statements for all SQL queries and properly escapes all output, indicating sound development practices in these common areas of concern. Furthermore, the absence of dangerous functions, file operations, and a limited attack surface with 100% protected entry points are strong indicators of a secure codebase.
However, the plugin is not without its risks. The presence of one known medium-severity vulnerability in its history, last patched in December 2024, suggests a pattern of past security weaknesses. While this specific vulnerability is now patched, it raises a flag about the historical security of the plugin and the diligence required by users to keep it updated. The single external HTTP request, while not inherently malicious, represents a potential point of compromise if the external service is compromised or if the request is not handled securely. The single cron event also warrants attention; if this event performs sensitive operations without proper authentication or sanitization, it could become an attack vector.
In conclusion, "hack-info" v4.25 is a relatively secure plugin, particularly in its handling of database queries and output. Its strengths lie in its well-protected entry points and adherence to secure coding practices for common web vulnerabilities. The primary concern stems from its vulnerability history, highlighting the importance of ongoing updates and vigilance for users. The external HTTP request and cron event, while not immediately concerning based on the provided data, represent areas that users should monitor for any changes or unexpected behavior.
Key Concerns
- Known past medium vulnerability
- Single external HTTP request
- Single cron event present
Hack-Info Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Hack-Info <= 3.17 - Cross-Site Request Forgery to Stored Cross-Site Scripting
Hack-Info Release Timeline
Hack-Info Code Analysis
SQL Query Safety
Output Escaping
Hack-Info Attack Surface
WordPress Hooks 9
Scheduled Events 1
Maintenance & Trust
Hack-Info Maintenance & Trust
Maintenance Signals
Community Trust
Hack-Info Alternatives
N0WPScan
n0wpscan
Secure your Wordpress of WPScan Prevent hackers using WPScan to find vulnerabilities in your site, disable this plugin when you are security testing o …
Hostinger Tools
hostinger
Simplified WordPress management. Manage site info, maintenance, security, & redirects.
All-In-One Security (AIOS) – Security and Firewall
all-in-one-wp-security-and-firewall
Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plugin designed especially for WordPress.
MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites
mainwp-child
MainWP Child establishes a secure link between your WordPress sites and your self-hosted MainWP Dashboard, simplifying site management.
Modular DS: Monitor, update, and backup multiple websites
modular-connector
Manage all your WordPress sites from one place. Automate updates, backups, uptime monitoring, security, maintenance reports, and more.
Hack-Info Developer Profile
18 plugins · 2K total installs
How We Detect Hack-Info
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/hack-info/includes/admin/css/admin-style.csshack-info/includes/admin/css/admin-style.css?ver=HTML / DOM Fingerprints
/*
* WPGear.
* Hack-Info
* admin.php
*/