NodeInfo(2) Security & Risk Analysis

wordpress.org/plugins/nodeinfo

NodeInfo and NodeInfo2 for WordPress!

1K active installs v3.1.0 PHP 7.2+ WP 6.6+ Updated Dec 30, 2025
activitypubdiasporafediversenodeinfoostatus
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is NodeInfo(2) Safe to Use in 2026?

Generally Safe

Score 100/100

NodeInfo(2) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The static analysis of the 'nodeinfo' plugin v3.1.0 reveals a strong security posture with no identified critical vulnerabilities or security weaknesses in its code. The plugin demonstrates excellent adherence to secure coding practices, as evidenced by the absence of dangerous functions, file operations, external HTTP requests, and the exclusive use of prepared statements for SQL queries. Furthermore, all output appears to be properly escaped, and no taint flows with unsanitized paths were detected. The plugin also benefits from a complete lack of known CVEs, indicating a history of secure development and maintenance.

The plugin's attack surface is effectively zero, with no AJAX handlers, REST API routes, shortcodes, or cron events exposed. This is a significant strength, as it minimizes the potential entry points for attackers. The absence of any detected issues in the static analysis, combined with a clean vulnerability history, strongly suggests that this plugin is currently very secure. There are no immediate or apparent risks based on the provided data.

Vulnerabilities
None known

NodeInfo(2) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

NodeInfo(2) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

NodeInfo(2) Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionplugins_loadednodeinfo.php:43
Maintenance & Trust

NodeInfo(2) Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 30, 2025
PHP min version7.2
Downloads18K

Community Trust

Rating80/100
Number of ratings1
Active installs1K
Developer Profile

NodeInfo(2) Developer Profile

Matthias Pfefferle

8 plugins · 3K total installs

78
trust score
Avg Security Score
98/100
Avg Patch Time
321 days
View full developer profile
Detection Fingerprints

How We Detect NodeInfo(2)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/nodeinfo/assets/css/nodeinfo.css
Script Paths
/wp-content/plugins/nodeinfo/assets/js/nodeinfo.js
Version Parameters
nodeinfo/assets/css/nodeinfo.css?ver=nodeinfo/assets/js/nodeinfo.js?ver=

HTML / DOM Fingerprints

REST Endpoints
/wp-json/nodeinfo/wp-json/nodeinfo2
FAQ

Frequently Asked Questions about NodeInfo(2)