
Oh Dear – Monitor Uptime, Performance and Broken Links Security & Risk Analysis
wordpress.org/plugins/ohdearThis plugin brings Oh Dear uptime, performance and broken links monitoring into your WordPress dashboard.
Is Oh Dear – Monitor Uptime, Performance and Broken Links Safe to Use in 2026?
Generally Safe
Score 85/100Oh Dear – Monitor Uptime, Performance and Broken Links has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "ohdear" plugin v1.0.2 exhibits a mixed security posture. While it demonstrates good practices by avoiding dangerous functions, all SQL queries are prepared, and there are no recorded historical vulnerabilities, several critical security concerns are present. The plugin exposes three AJAX handlers, all of which lack proper authentication checks. This significantly increases the attack surface, as any unauthenticated user could potentially interact with these handlers, leading to unintended actions or information disclosure if these handlers perform sensitive operations.
Furthermore, the static analysis indicates a notable weakness in output escaping, with only 34% of outputs being properly escaped. This could open the door to cross-site scripting (XSS) vulnerabilities if user-supplied data is reflected in the output without adequate sanitization. The absence of nonce checks on AJAX handlers exacerbates this risk, making it easier for attackers to craft malicious requests. The taint analysis showing zero flows is positive, but it does not negate the risks identified by the static analysis of unauthenticated entry points and poor output escaping.
In conclusion, the plugin's clean vulnerability history and good SQL handling are strengths. However, the unprotected AJAX handlers and insufficient output escaping represent significant security weaknesses that warrant immediate attention. The lack of capability checks further compounds these issues. The plugin would benefit greatly from implementing robust authentication and authorization mechanisms for all AJAX handlers and ensuring all output is properly escaped.
Key Concerns
- Unprotected AJAX handlers
- Insufficient output escaping
- Missing nonce checks on AJAX
- Missing capability checks
Oh Dear – Monitor Uptime, Performance and Broken Links Security Vulnerabilities
Oh Dear – Monitor Uptime, Performance and Broken Links Release Timeline
Oh Dear – Monitor Uptime, Performance and Broken Links Code Analysis
SQL Query Safety
Output Escaping
Oh Dear – Monitor Uptime, Performance and Broken Links Attack Surface
AJAX Handlers 3
WordPress Hooks 9
Maintenance & Trust
Oh Dear – Monitor Uptime, Performance and Broken Links Maintenance & Trust
Maintenance Signals
Community Trust
Oh Dear – Monitor Uptime, Performance and Broken Links Alternatives
Facilitated Routines
facilitated-routines
Automate technical SEO, image optimization and webp creation, security, unused media cleanup, sitemaps, find broken links, and more.
Site Suggest
site-suggest
Site Suggest is a comprehensive WordPress plugin designed to assist site administrators in reviewing and optimizing their site's SEO analytics.
Watchman Tower
watchman-tower
Centralized WordPress monitoring for agencies. Track uptime, performance, SSL, and site health across multiple client sites.
WP-Stack
wp-stack-connect
Wp-stack makes your lives easy by automating the most boring tasks you do on your websites and saves you hours of work and hundreds of dollars every m …
LinkRivers Site Monitor
linkrivers-site-monitor
Professional website monitoring for local businesses. Track uptime, SSL, page speed, SEO health, and Real User Monitoring.
Oh Dear – Monitor Uptime, Performance and Broken Links Developer Profile
3 plugins · 1K total installs
How We Detect Oh Dear – Monitor Uptime, Performance and Broken Links
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ohdear/assets/css/admin.css/wp-content/plugins/ohdear/assets/js/admin-dashboard.js/wp-content/plugins/ohdear/assets/js/admin.js/wp-content/plugins/ohdear/assets/js/vue.js/wp-content/plugins/ohdear/assets/js/v-tooltip.js/wp-content/plugins/ohdear/assets/js/v-chart.jsassets/js/admin-dashboard.jsassets/js/admin.jsassets/js/vue.jsassets/js/v-tooltip.jsassets/js/v-chart.jsohdear/assets/css/admin.css?ver=ohdear/assets/js/admin-dashboard.js?ver=ohdear/assets/js/admin.js?ver=ohdear/assets/js/vue.js?ver=ohdear/assets/js/v-tooltip.js?ver=ohdear/assets/js/v-chart.js?ver=HTML / DOM Fingerprints
ohdear-wrapohdear-cardohdear-card-headerohdear-card-bodyohdear-alertohdear-alert-infoohdear-alert-warningohdear-alert-danger<!-- This is the main wrapper for the Oh Dear plugin --><!-- Oh Dear Widget --><!-- END Oh Dear Widget --><!-- Oh Dear Widget -->+9 moredata-themedata-placementdata-boundarydata-offsetdata-templatedata-titleOhDearAPIOhDearSiteOhDearCheck/wp-json/ohdear/v1/sites/wp-json/ohdear/v1/checks/wp-json/ohdear/v1/checks/sites<div class="ohdear-widget-status">