
Health Monitor Security & Risk Analysis
wordpress.org/plugins/health-monitorHealth Monitor is designed to help you keep your website running smoothly. It continuously checks your site’s performance, security, and overall healt …
Is Health Monitor Safe to Use in 2026?
Generally Safe
Score 100/100Health Monitor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The health-monitor plugin v1.4.3 exhibits a mixed security posture. On the positive side, there are no known critical vulnerabilities (CVEs) or taint analysis issues, and the plugin generally follows good practices regarding SQL prepared statements and output escaping. The lack of bundled libraries and external HTTP requests is also a positive indicator. However, a significant concern arises from the substantial attack surface, with 8 out of 12 AJAX handlers lacking authentication checks. This could potentially expose sensitive functionality to unauthorized users, depending on the actions performed by these handlers. The presence of nonce checks and capability checks on some AJAX handlers is a good start, but the majority remain unprotected.
While the vulnerability history is clean, which is a strong positive, it does not negate the immediate risks identified in the static analysis. The plugin's overall security is hindered by the unprotected entry points. Future analysis should focus on understanding the exact functionality of these unprotected AJAX handlers and ensuring appropriate access controls are implemented. Without this, the risk, while not exploited in the past, remains present.
Key Concerns
- Unprotected AJAX handlers
- Majority of AJAX handlers lack auth checks
- SQL queries with prepared statements at 72%
- Output escaping at 91%
Health Monitor Security Vulnerabilities
Health Monitor Release Timeline
Health Monitor Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Health Monitor Attack Surface
AJAX Handlers 12
WordPress Hooks 12
Scheduled Events 3
Maintenance & Trust
Health Monitor Maintenance & Trust
Maintenance Signals
Community Trust
Health Monitor Alternatives
Performance Lab
performance-lab
Performance plugin from the WordPress Performance Team, which is a collection of standalone performance features.
DiveWP – Boost Site Performance with Clear, Actionable Steps
divewp-boost-site-performance
Learn WP Best Practices Through Your Own Site! Get clear insights about Performance, Security, and Best Practices – explained in plain English.
BoltAudit – Plugin & Performance Analyzer
boltaudit
BoltAudit helps you identify bloated, unused, abandoned, and performance-heavy plugins—plus database bloat, autoloaded options, and runtime impact.
Watchman Tower
watchman-tower
Centralized WordPress monitoring for agencies. Track uptime, performance, SSL, and site health across multiple client sites.
HealthSweep Site Monitor – Advanced Site Health & Performance Tools
healthsweep-site-monitor
Advanced WordPress Site Health, performance, security, cleanup, snapshots, alerts, and local speed benchmarking for admins.
Health Monitor Developer Profile
1 plugin · 20 total installs
How We Detect Health Monitor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/health-monitor/assets/css/admin-style.css/wp-content/plugins/health-monitor/assets/css/reports.css/wp-content/plugins/health-monitor/assets/js/admin-scripts.js/wp-content/plugins/health-monitor/assets/js/charts.js/wp-content/plugins/health-monitor/assets/js/health-monitor-lighthouse-report.js/wp-content/plugins/health-monitor/assets/images/health-monitor.svg/wp-content/plugins/health-monitor/assets/js/admin-scripts.js/wp-content/plugins/health-monitor/assets/js/charts.js/wp-content/plugins/health-monitor/assets/js/health-monitor-lighthouse-report.jshealth-monitor/assets/css/admin-style.css?ver=health-monitor/assets/css/reports.css?ver=health-monitor/assets/js/admin-scripts.js?ver=health-monitor/assets/js/charts.js?ver=health-monitor/assets/js/health-monitor-lighthouse-report.js?ver=HTML / DOM Fingerprints
health-monitor-headerhealth-monitor-title-wprhealth-monitor-titlehealth-monitor-iconhealth-monitor-authorhealth-monitor-ctacta-wprcta-text+2 moreid="health-monitor"health_monitor_lighthouse_args