
Inspect HTTP Requests Security & Risk Analysis
wordpress.org/plugins/inspect-http-requestsLog, view, and Block WP HTTP requests
Is Inspect HTTP Requests Safe to Use in 2026?
Generally Safe
Score 100/100Inspect HTTP Requests has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "inspect-http-requests" plugin v1.0.10 presents a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for its SQL queries and includes a reasonable number of nonce and capability checks relative to its entry points. The absence of any recorded vulnerabilities in its history suggests a relatively stable and well-maintained codebase.
However, significant concerns arise from the static analysis. A substantial portion of its attack surface, specifically all four AJAX handlers, lacks authentication checks. This is further exacerbated by the taint analysis, which reveals two flows with unsanitized paths classified as high severity. The low percentage of properly escaped output (29%) also indicates a risk of cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled carefully before being displayed.
In conclusion, while the plugin has strengths in its SQL handling and historical lack of vulnerabilities, the unprotected AJAX endpoints and high-severity unsanitized paths represent critical security weaknesses that could be exploited. The poor output escaping practices also add to the potential risk landscape.
Key Concerns
- AJAX handlers without authentication
- High severity taint flows with unsanitized paths
- Low percentage of properly escaped output
Inspect HTTP Requests Security Vulnerabilities
Inspect HTTP Requests Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Inspect HTTP Requests Attack Surface
AJAX Handlers 4
WordPress Hooks 8
Maintenance & Trust
Inspect HTTP Requests Maintenance & Trust
Maintenance Signals
Community Trust
Inspect HTTP Requests Alternatives
Log HTTP Requests
log-http-requests
Log and view all WP HTTP requests
Meta for WooCommerce
facebook-for-woocommerce
Get the Official Meta for WooCommerce plugin for powerful ways to help grow your business.
Site Mailer – SMTP Replacement, Email API Deliverability & Email Log
site-mailer
Effortlessly manage transactional emails with Site Mailer. High deliverability, logs and statistics, and no SMTP plugins needed.
Simple JWT Login – Allows you to use JWT on REST endpoints.
simple-jwt-login
Enhance the WordPress REST API with JWT authentication for secure access by mobile apps, external sites, and third-party services.
HTTP Requests Manager
http-requests-manager
Limit, Debug, Optimize WP_HTTP requests. Limit by request count, page load time, reduce timeout for each request. Speed up login and admin pages.
Inspect HTTP Requests Developer Profile
14 plugins · 2K total installs
How We Detect Inspect HTTP Requests
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/inspect-http-requests/admin/css/inspect-http-requests-admin.css/wp-content/plugins/inspect-http-requests/admin/js/inspect-http-requests-admin.js/wp-content/plugins/inspect-http-requests/admin/js/inspect-http-requests-admin.jsinspect-http-requests/admin/css/inspect-http-requests-admin.css?ver=inspect-http-requests/admin/js/inspect-http-requests-admin.js?ver=HTML / DOM Fingerprints
etsInspectHttpRequestsParams