Hosting Stability Meter Security & Risk Analysis

wordpress.org/plugins/hosting-stability-meter

Benchmarks stability measuring in time. Detailed interactive graph for hosting performance peaks and dips let you know hosting is good or bad.

10 active installs v1.0.1 PHP 5.2.0+ WP 4.6+ Updated Sep 1, 2020
benchmarkcpuhardwarehostingspeed
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Hosting Stability Meter Safe to Use in 2026?

Generally Safe

Score 85/100

Hosting Stability Meter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "hosting-stability-meter" plugin version 1.0.1 exhibits a mixed security posture. On the positive side, the static analysis reveals a very small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events exposed without authentication or permission checks. Furthermore, there are no known CVEs associated with this plugin, suggesting a history of responsible development or a lack of prior targeted exploitation.

However, several concerning code signals warrant attention. A significant portion of the SQL queries (100%) are not using prepared statements, posing a risk of SQL injection vulnerabilities, especially if any of the input influencing these queries is not strictly validated. The taint analysis indicates two flows with unsanitized paths, although these did not reach critical or high severity in this analysis, they represent potential avenues for exploitation if combined with other weaknesses. The relatively low percentage of properly escaped output (52%) also raises concerns about cross-site scripting (XSS) vulnerabilities.

In conclusion, while the plugin has a minimal attack surface and no known historical vulnerabilities, the lack of prepared statements for all SQL queries and the presence of unsanitized paths in taint analysis are notable weaknesses. The output escaping also needs improvement. These are areas that, if exploited, could lead to significant security breaches.

Key Concerns

  • All SQL queries are not prepared
  • Unsanitized paths found in taint analysis
  • Only 52% of output is properly escaped
Vulnerabilities
None known

Hosting Stability Meter Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Hosting Stability Meter Code Analysis

Dangerous Functions
0
Raw SQL Queries
5
0 prepared
Unescaped Output
10
11 escaped
Nonce Checks
0
Capability Checks
1
File Operations
5
External Requests
1
Bundled Libraries
0

SQL Query Safety

0% prepared5 total queries

Output Escaping

52% escaped21 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
get_host_hash (class.hosting-stability-meter.php:393)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Hosting Stability Meter Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_initclass.hosting-stability-meter-admin.php:76
actionadmin_menuclass.hosting-stability-meter-admin.php:77
filtercron_schedulesclass.hosting-stability-meter.php:81
actioninithosting-stability-meter.php:22
actioninithosting-stability-meter.php:26
Maintenance & Trust

Hosting Stability Meter Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedSep 1, 2020
PHP min version5.2.0
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Hosting Stability Meter Developer Profile

Aleksei Znaev

2 plugins · 110 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Hosting Stability Meter

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/hosting-stability-meter/class.hosting-stability-meter-admin.php/wp-content/plugins/hosting-stability-meter/class.hosting-stability-meter-benchmarks.php/wp-content/plugins/hosting-stability-meter/class.hosting-stability-meter.php/wp-content/plugins/hosting-stability-meter/hosting-stability-meter.php
Script Paths
https://www.gstatic.com/charts/loader.js

HTML / DOM Fingerprints

Data Attributes
id="hostingstabilitymeter_th_cpu"id="hostingstabilitymeter_th_disk"id="hostingstabilitymeter_th_db"
FAQ

Frequently Asked Questions about Hosting Stability Meter