
Hosting Monitor Security & Risk Analysis
wordpress.org/plugins/hosting-monitorTrack how much disk and database space WordPress is using.
Is Hosting Monitor Safe to Use in 2026?
Generally Safe
Score 85/100Hosting Monitor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'hosting-monitor' plugin version 0.7.5 exhibits a mixed security posture. On one hand, the plugin demonstrates strong adherence to modern WordPress security practices, with zero known CVEs, no unpatched vulnerabilities, and SQL queries exclusively using prepared statements. The presence of nonce and capability checks, alongside the absence of external HTTP requests and file operations, are positive indicators. However, the static analysis reveals significant concerns within the code itself. The use of dangerous functions like 'shell_exec' and 'create_function' is a major red flag, potentially opening the door to remote code execution if not handled with extreme caution and robust sanitization. Furthermore, a significant portion of output is not properly escaped, posing a cross-site scripting (XSS) risk. The single identified unsanitized path in the taint analysis, while not classified as critical or high, warrants attention as it represents a potential avenue for malicious input to be processed without adequate validation. The plugin's vulnerability history being entirely clean is positive, but it does not negate the risks present in the current code analysis. A balanced view suggests the plugin has avoided past exploitable issues but carries inherent risks due to its implementation of dangerous functions and insufficient output sanitization.
Key Concerns
- Dangerous functions used (shell_exec, create_function)
- Low percentage of properly escaped output
- Unsanitized path identified in taint analysis
Hosting Monitor Security Vulnerabilities
Hosting Monitor Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Hosting Monitor Attack Surface
WordPress Hooks 5
Maintenance & Trust
Hosting Monitor Maintenance & Trust
Maintenance Signals
Community Trust
Hosting Monitor Alternatives
Disk Space Pie Chart
disk-space-pie-chart
Shows your server space (free and used) as a funky Pie Chart in your backend. It also shows a percentage bar in your WordPress dahsboard.
Disk Usage Sunburst
disk-usage-sunburst
Visualize and drill down the disk usage of your whole WordPress installation. Find and identify big files immediately!
My Simple Space
my-simple-space
Disk Space, Database and Memory Usage in the dashboard.
Server Monitor
server-monitor
Adds three simple widgets to your WordPress Dashboard displaying fundamental info about your server and installation.
ServerMonitor
servermonitor
A simple plugin to view server resource usage (ram, cpu, disk), check your PHP error log, and more.
Hosting Monitor Developer Profile
3 plugins · 940 total installs
How We Detect Hosting Monitor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
TODO msb 10-24-2011: Put this & hosting_monitor() in class, de-duplicate theseMixed code, new & from Disk Space Pie Chart (DSPC)Entire method from Disk Space Pie Chart (DSPC)Send Low-on-Space Alerts:name="guru_space"name="hm_db_space"name="guru_unit"name="hm_db_unit"value="TB"selected+4 more