
Apache Status & Info Security & Risk Analysis
wordpress.org/plugins/htaccess-server-info-server-statusApache server-info and server-status monitoring right in your WordPress admin.
Is Apache Status & Info Safe to Use in 2026?
Generally Safe
Score 100/100Apache Status & Info has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'htaccess-server-info-server-status' plugin v3.3.0 exhibits a mixed security posture. On the positive side, it has no recorded historical vulnerabilities and its code analysis shows no critical findings like dangerous functions or unsanitized taint flows. The majority of SQL queries use prepared statements, and there are a reasonable number of nonce and capability checks in place. However, there are notable areas of concern. The plugin exposes two AJAX handlers without authentication checks, which presents a significant attack vector. While the static analysis doesn't reveal specific exploitable flaws in these handlers, their unprotected nature is a considerable risk. Furthermore, less than 60% of output is properly escaped, indicating a potential for cross-site scripting (XSS) vulnerabilities if user-supplied data is not sufficiently sanitized before display. The plugin also performs several file operations and external HTTP requests, which, while not inherently insecure, can become vulnerabilities if not handled with extreme care regarding input validation and error handling. In conclusion, while the plugin benefits from a clean vulnerability history, the presence of unprotected AJAX endpoints and inadequate output escaping are significant weaknesses that require attention.
Key Concerns
- Unprotected AJAX handlers
- Insufficient output escaping
Apache Status & Info Security Vulnerabilities
Apache Status & Info Code Analysis
SQL Query Safety
Output Escaping
Apache Status & Info Attack Surface
AJAX Handlers 3
Shortcodes 4
WordPress Hooks 28
Maintenance & Trust
Apache Status & Info Maintenance & Trust
Maintenance Signals
Community Trust
Apache Status & Info Alternatives
phpinfo() WP
phpinfo-wp
A simple plugin to look up server info and manage server configuration of wordpress site
Redirection
redirection
Manage 301 redirects, track 404 errors, and improve your site. No knowledge of Apache or Nginx required.
Spider Blocker
spiderblocker
SpiderBlocker will block most common bots that consume bandwidth and slow down your blog.
Custom PHP Settings
custom-php-settings
This plugin makes it possible to override php settings.
Server Info
server-info
This plugin will show you very useful information about your hosting server such as PHP version, Server OS, Server IP etc.
Apache Status & Info Developer Profile
12 plugins · 15K total installs
How We Detect Apache Status & Info
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/htaccess-server-info-server-status/assets/css/switchery.min.css/wp-content/plugins/htaccess-server-info-server-status/assets/css/tooltip.min.css/wp-content/plugins/htaccess-server-info-server-status/assets/css/style.css/wp-content/plugins/htaccess-server-info-server-status/assets/js/switchery.min.js/wp-content/plugins/htaccess-server-info-server-status/assets/js/livesstatus.js/wp-content/plugins/htaccess-server-info-server-status/assets/js/main.js/wp-content/plugins/htaccess-server-info-server-status/assets/js/livesstatus.js?ver=1000/wp-content/plugins/htaccess-server-info-server-status/assets/js/main.js?ver=1000/wp-content/plugins/htaccess-server-info-server-status/assets/js/switchery.min.js/wp-content/plugins/htaccess-server-info-server-status/assets/js/livesstatus.js/wp-content/plugins/htaccess-server-info-server-status/assets/js/main.js?ver=1000HTML / DOM Fingerprints
hsiss-dashboardhsiss-rowhsiss-boxhsiss-box-40-60-linehsiss-about-logodata-hsiss-noncelivestatus[hsiss-libraries][hsiss-changelog]