Incident Agent Security & Risk Analysis

wordpress.org/plugins/incident-agent

Complete WordPress monitoring with real-time alerts, error tracking, and uptime monitoring. Know about issues before your users do.

0 active installs v1.0.3 PHP 7.4+ WP 5.0+ Updated Mar 19, 2026
alertserror-trackingmonitoringsecurityuptime
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Incident Agent Safe to Use in 2026?

Generally Safe

Score 100/100

Incident Agent has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The incident-agent plugin v1.0.3 demonstrates a strong security posture based on the provided static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or direct SQL queries without prepared statements, along with a high percentage of properly escaped output, indicates adherence to secure coding practices. The plugin also shows diligence in implementing nonce checks and handling file operations and external HTTP requests with apparent safety measures.

However, a notable concern arises from the complete lack of capability checks. This means that any functionality exposed, even if not directly through common attack vectors like AJAX or REST, might be accessible to any logged-in user, regardless of their role or permissions. While taint analysis found no issues, this absence of authorization checks represents a significant potential weakness that could be exploited if any sensitive actions are performed by the plugin.

Furthermore, the plugin's vulnerability history is entirely clean, with no recorded CVEs. This is a positive sign, suggesting a history of stable and secure development. However, this historical data does not mitigate the current identified weakness of missing capability checks. In conclusion, the plugin exhibits good technical security measures in its code, but the lack of proper authorization checks presents a clear and present risk that needs to be addressed.

Key Concerns

  • No capability checks for entry points
Vulnerabilities
None known

Incident Agent Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Incident Agent Release Timeline

v1.0.3Current
Code Analysis
Analyzed Apr 16, 2026

Incident Agent Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
8 prepared
Unescaped Output
3
85 escaped
Nonce Checks
5
Capability Checks
0
File Operations
1
External Requests
5
Bundled Libraries
0

SQL Query Safety

100% prepared8 total queries

Output Escaping

97% escaped88 total outputs
Attack Surface

Incident Agent Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 86
actionadmin_menuincident-agent.php:54
actionadmin_enqueue_scriptsincident-agent.php:116
filtercron_schedulesincident-agent.php:809
actionincidentwp_transmit_eventsincident-agent.php:817
actionwp_loginincident-agent.php:918
actionwp_logoutincident-agent.php:925
actionwp_login_failedincident-agent.php:931
actionactivated_pluginincident-agent.php:938
actiondeactivated_pluginincident-agent.php:945
actiondeleted_pluginincident-agent.php:952
actionedited_pluginincident-agent.php:962
actionswitch_themeincident-agent.php:969
actiondeleted_themeincident-agent.php:976
actionedited_themeincident-agent.php:986
actionsave_postincident-agent.php:993
actionbefore_delete_postincident-agent.php:1008
actiontransition_post_statusincident-agent.php:1020
actionwp_insert_commentincident-agent.php:1035
actiondelete_commentincident-agent.php:1045
actionadd_attachmentincident-agent.php:1056
actiondelete_attachmentincident-agent.php:1066
actionuser_registerincident-agent.php:1077
actiondelete_userincident-agent.php:1087
actionprofile_updateincident-agent.php:1098
actionset_user_roleincident-agent.php:1107
actionupdate_optionincident-agent.php:1118
actionupgrader_process_completeincident-agent.php:1131
actionwp_update_nav_menuincident-agent.php:1180
actiondeleted_optionincident-agent.php:1187
actioncustomize_save_afterincident-agent.php:1199
actionwp_insert_siteincident-agent.php:1205
actionwp_delete_siteincident-agent.php:1215
actionadmin_noticesincident-agent.php:1225
actioncreated_termincludes/class-event-tracker.php:135
actionedited_termincludes/class-event-tracker.php:136
actiondelete_termincludes/class-event-tracker.php:137
actionsave_postincludes/class-event-tracker.php:188
actionbefore_delete_postincludes/class-event-tracker.php:189
actiontransition_post_statusincludes/class-event-tracker.php:190
actioncomment_postincludes/class-event-tracker.php:257
actionedit_commentincludes/class-event-tracker.php:258
actiondelete_commentincludes/class-event-tracker.php:259
actionspam_commentincludes/class-event-tracker.php:260
actiontrash_commentincludes/class-event-tracker.php:261
actionwp_set_comment_statusincludes/class-event-tracker.php:262
actionuser_registerincludes/class-event-tracker.php:327
actionprofile_updateincludes/class-event-tracker.php:328
actiondelete_userincludes/class-event-tracker.php:329
actionset_user_roleincludes/class-event-tracker.php:330
actionwp_loginincludes/class-event-tracker.php:331
actionwp_logoutincludes/class-event-tracker.php:332
actionadd_attachmentincludes/class-event-tracker.php:405
actionedit_attachmentincludes/class-event-tracker.php:406
actiondelete_attachmentincludes/class-event-tracker.php:407
actionwp_create_nav_menuincludes/class-event-tracker.php:449
actionwp_update_nav_menuincludes/class-event-tracker.php:450
actionwp_delete_nav_menuincludes/class-event-tracker.php:451
actionupdate_option_sidebars_widgetsincludes/class-event-tracker.php:485
actionupdate_option_blognameincludes/class-event-tracker.php:500
actionupdate_option_blogdescriptionincludes/class-event-tracker.php:501
actionupdate_option_admin_emailincludes/class-event-tracker.php:502
actionupdate_option_users_can_registerincludes/class-event-tracker.php:503
actionupdate_option_default_roleincludes/class-event-tracker.php:504
actionupdate_option_permalink_structureincludes/class-event-tracker.php:505
actioncustomize_save_afterincludes/class-event-tracker.php:508
actionupdate_optionincludes/class-event-tracker.php:511
actionactivated_pluginincludes/class-event-tracker.php:623
actiondeactivated_pluginincludes/class-event-tracker.php:624
actionupgrader_process_completeincludes/class-event-tracker.php:625
actiondeleted_pluginincludes/class-event-tracker.php:626
actionswitch_themeincludes/class-event-tracker.php:682
actionupgrader_process_completeincludes/class-event-tracker.php:683
actiondeleted_themeincludes/class-event-tracker.php:684
actionwoocommerce_settings_savedincludes/class-event-tracker.php:726
actionwoocommerce_new_productincludes/class-event-tracker.php:729
actionwoocommerce_update_productincludes/class-event-tracker.php:730
actionwoocommerce_new_orderincludes/class-event-tracker.php:733
actionwoocommerce_order_status_changedincludes/class-event-tracker.php:734
actionwoocommerce_coupon_options_saveincludes/class-event-tracker.php:737
actionwp_login_failedincludes/class-event-tracker.php:842
actionwp_authenticate_userincludes/class-event-tracker.php:843
filterauthenticateincludes/class-event-tracker.php:844
actionwp_die_handlerincludes/class-event-tracker.php:907
actiontemplate_redirectincludes/class-event-tracker.php:910
filterwp_die_handlerincludes/class-event-tracker.php:913
actionplugins_loadedincludes/class-event-tracker.php:1010

Scheduled Events 1

incidentwp_transmit_events
Maintenance & Trust

Incident Agent Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 19, 2026
PHP min version7.4
Downloads166

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Incident Agent Developer Profile

Craig Gomes

2 plugins · 400 total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Incident Agent

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/incident-agent/assets/admin-modern.css/wp-content/plugins/incident-agent/assets/js/admin-tabs.js
Script Paths
/wp-content/plugins/incident-agent/assets/js/admin-tabs.js
Version Parameters
incident-agent/assets/admin-modern.css?ver=incident-agent/assets/js/admin-tabs.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-tabdata-target
JS Globals
incidentwp_admin_tabs_params
FAQ

Frequently Asked Questions about Incident Agent