
MySQL Profiler Security & Risk Analysis
wordpress.org/plugins/mysql-profilerDisplays a list of each page's SQL queries and the functions calling them that can be searched and sorted by time, type, etc.
Is MySQL Profiler Safe to Use in 2026?
Generally Safe
Score 85/100MySQL Profiler has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "mysql-profiler" plugin v1.0 exhibits a generally strong security posture based on the provided static analysis. The absence of any identified dangerous functions, file operations, external HTTP requests, or SQL queries not using prepared statements is highly commendable. Furthermore, all identified outputs are properly escaped. The attack surface appears to be zero, with no AJAX handlers, REST API routes, shortcodes, or cron events found. This indicates a deliberate effort to minimize potential entry points for malicious actors.
However, a significant concern arises from the complete lack of nonce and capability checks. While the attack surface is reported as zero, this means that any future additions or unforeseen interactions could potentially be exploited if proper authentication and authorization mechanisms are not implemented. The presence of the outdated DataTables v1.9.0 library also poses a potential risk, as older versions of libraries can contain known vulnerabilities that may not have been discovered or disclosed as CVEs in the plugin's history. The plugin's vulnerability history being completely clean is a positive sign, but it's crucial to remember that a lack of discovered vulnerabilities does not guarantee future safety, especially when outdated dependencies are present.
In conclusion, "mysql-profiler" v1.0 has excellent foundational security practices in place, particularly regarding direct code execution and data handling. The primary weaknesses lie in the absence of essential security checks (nonces and capabilities) and the use of an outdated bundled library. Addressing these two areas would significantly bolster the plugin's security, moving it from a strong candidate to a robustly secured plugin.
Key Concerns
- Missing nonce checks
- Missing capability checks
- Bundled outdated library: DataTables v1.9.0
MySQL Profiler Security Vulnerabilities
MySQL Profiler Code Analysis
Bundled Libraries
MySQL Profiler Attack Surface
Maintenance & Trust
MySQL Profiler Maintenance & Trust
Maintenance Signals
Community Trust
MySQL Profiler Alternatives
Admin Bar Queries
admin-bar-queries
MySQL queries and load details added to your admin bar.
Speedix
speedix
Pinpoint exactly which plugins and hooks slow your site. Real-time PHP profiling with visual dashboard, health scores, and zero guesswork.
WP XHProf Profiler
wp-xhprof-profiler
Adds PHP profiling support to your Wordpress using Facebook's XHProf Profiler.
Freesoul Deactivate Plugins – Disable plugins on individual WordPress pages
freesoul-deactivate-plugins
Load plugins only where you need them. No bloat, no conflicts, more speed. Deactivate plugins where they don't add anything useful.
Code Profiler – WordPress Performance Profiling and Debugging Made Easy
code-profiler
A profiler to measure the performance of your WordPress plugins and themes.
MySQL Profiler Developer Profile
5 plugins · 70 total installs
How We Detect MySQL Profiler
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mysql-profiler/css/style.css/wp-content/plugins/mysql-profiler/js/mysql-profiler.js/wp-content/plugins/mysql-profiler/js/mysql-profiler.jsmysql-profiler/css/style.css?ver=mysql-profiler/js/mysql-profiler.js?ver=HTML / DOM Fingerprints
MysqlProfilermysqlProfiler