
Lyon Site Activity Security & Risk Analysis
wordpress.org/plugins/lyon-site-activityA simple, lightweight plugin that gives site administrators an at-a-glance view of recent content edits.
Is Lyon Site Activity Safe to Use in 2026?
Generally Safe
Score 85/100Lyon Site Activity has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'lyon-site-activity' plugin v2.0.2 exhibits a strong security posture in several key areas based on the static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points significantly limits the potential attack surface. Furthermore, the plugin demonstrates good practice by exclusively using prepared statements for its SQL queries, mitigating risks of SQL injection. The lack of file operations and external HTTP requests also reduces potential vulnerabilities.
However, the static analysis reveals a significant concern regarding output escaping. With only 3% of 36 outputs properly escaped, there is a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. Any user-supplied data that is displayed on the frontend without proper sanitization could be exploited to inject malicious scripts. The complete absence of nonce checks and capability checks on potential entry points, although the entry points themselves are currently zero, indicates a potential weakness if the plugin's functionality were to expand or be integrated with other components that introduce new entry points. The vulnerability history showing no recorded CVEs suggests a history of responsible development, but it cannot compensate for identified code weaknesses.
In conclusion, while the plugin benefits from a minimal attack surface and secure SQL practices, the pervasive issue with output escaping presents a critical security concern that requires immediate attention. The lack of any security checks (nonces, capabilities) is also a point of concern for future-proofing. Addressing the output escaping vulnerabilities is paramount to securing this plugin.
Key Concerns
- Low output escaping rate
- Missing nonce checks
- Missing capability checks
Lyon Site Activity Security Vulnerabilities
Lyon Site Activity Code Analysis
SQL Query Safety
Output Escaping
Lyon Site Activity Attack Surface
WordPress Hooks 5
Maintenance & Trust
Lyon Site Activity Maintenance & Trust
Maintenance Signals
Community Trust
Lyon Site Activity Alternatives
Log Deprecated Notices
log-deprecated-notices
Logs the usage of deprecated files, functions, and function arguments, and identifies where the deprecated functionality is being used.
Quick debug.log Viewer
quick-debug-log-viewer
Easily view and manage your WordPress debug.log file directly from the admin area — no FTP access required.
Log Deprecated Notices Extender
log-deprecated-notices-extender
This developer-oriented WordPress plugin extends Andrew Nacin's Log Deprecated Notices to show a link in the WP 3.3+ Toolbar.
Pagelog
pagelog
This plugin registers and displays statistics of the usage of selected wp posts/pages.
LogAction – Activity Logs for Admin
logaction
Track and log WordPress activities to monitor and improve your site's security and administrative tasks.
Lyon Site Activity Developer Profile
1 plugin · 10 total installs
How We Detect Lyon Site Activity
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lyon-site-activity/assets/styles.css/wp-content/plugins/lyon-site-activity/assets/scripts.js/wp-content/plugins/lyon-site-activity/assets/scripts.jslyon-site-activity/assets/styles.css?ver=lyon-site-activity/assets/scripts.js?ver=HTML / DOM Fingerprints
site-activity-settingslsa_cpt_listname="lsa_plugin_options[lsa_post_tax_types