
InfoMon – System Info & Server Monitor Security & Risk Analysis
wordpress.org/plugins/infomonInfoMon shows WordPress, PHP, database and server details in a clean admin page and a compact dashboard widget, with handy JSON export.
Is InfoMon – System Info & Server Monitor Safe to Use in 2026?
Generally Safe
Score 100/100InfoMon – System Info & Server Monitor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "infomon" v1.3.5 exhibits a generally strong security posture based on the provided static analysis. The absence of any known vulnerabilities (CVEs) and a clean taint analysis are positive indicators. Furthermore, the plugin demonstrates good development practices by using prepared statements for all SQL queries and properly escaping a high percentage of its outputs. The limited attack surface, with no unprotected entry points, is also a significant strength.
However, there are a few areas that warrant attention. The complete absence of nonce checks across all entry points is a concern, particularly as it doesn't appear to be mitigated by a robust capability check system (only 3 capability checks were found across the entire plugin). While the attack surface is currently small and protected, relying solely on capability checks without nonces for AJAX or REST API endpoints could leave it vulnerable to CSRF-style attacks if new endpoints are added without proper security considerations. The lack of taint analysis results (0 flows analyzed) is also a limitation, as it means there's no guarantee that complex or subtle vulnerabilities haven't been missed.
In conclusion, "infomon" v1.3.5 is a relatively secure plugin with a history of no known vulnerabilities and good practices in SQL and output handling. The primary weakness lies in the complete lack of nonce checks, which, while not an immediate exploit given the current protected entry points, represents a potential oversight in defense against certain types of attacks. Continued vigilance and the implementation of nonce checks in future updates would further solidify its security.
Key Concerns
- Missing nonce checks on entry points
InfoMon – System Info & Server Monitor Security Vulnerabilities
InfoMon – System Info & Server Monitor Code Analysis
Output Escaping
InfoMon – System Info & Server Monitor Attack Surface
REST API Routes 1
WordPress Hooks 4
Maintenance & Trust
InfoMon – System Info & Server Monitor Maintenance & Trust
Maintenance Signals
Community Trust
InfoMon – System Info & Server Monitor Alternatives
Display PHP Version
display-php-version
Displays the currently installed PHP/MySQL version in the "At a Glance" admin dashboard widget.
PHP Version
php-version
You can able to see the current PHP version in WordPress admin dashboard widget.
Server Info
server-info
This plugin will show you very useful information about your hosting server such as PHP version, Server OS, Server IP etc.
WP PHP Version Display
wp-php-version-display
Displays the current running PHP/MySQL version inside "At a Glance" admin dashboard widget.
Server Monitor
server-monitor
Adds three simple widgets to your WordPress Dashboard displaying fundamental info about your server and installation.
InfoMon – System Info & Server Monitor Developer Profile
1 plugin · 50 total installs
How We Detect InfoMon – System Info & Server Monitor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/infomon/assets/css/admin.css/wp-content/plugins/infomon/assets/js/admin.js/wp-content/plugins/infomon/assets/js/admin.jsinfomon-admin?ver=infomon-admin-js?ver=HTML / DOM Fingerprints
infomon-toolbarinfomon-copy-tableinfomon-copy-jsoninfomon-download-jsoninfomon-kpisinfomon-kpiinfomon-kpi-valueinfomon-kpi-label+8 moreid="infomon-copy-table"id="infomon-copy-json"id="infomon-download-json"id="infomon-table"class="infomon-kpi infomon-kpi--class="infomon-card"+4 more/infomon/v1/status<div class="infomon-toolbar"><div class="infomon-kpis"><div class="infomon-kpi"><div class="infomon-cards">