
Package Installator Security & Risk Analysis
wordpress.org/plugins/package-installatorA plugin to manage system packages (e.g., php-xml) with a modern React-based UI via SSH.
Is Package Installator Safe to Use in 2026?
Generally Safe
Score 100/100Package Installator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "package-installator" v1.2.1 plugin exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The plugin demonstrates good practices by implementing nonce checks and capability checks on its entry points, and it has a clean history with no recorded CVEs. The code analysis shows a high percentage of properly escaped output, which is a positive indicator for preventing cross-site scripting vulnerabilities.
However, a notable concern lies in the handling of SQL queries. The analysis reveals one SQL query that is not using prepared statements. This represents a significant risk, as it makes the plugin vulnerable to SQL injection attacks, particularly if any user-supplied data is incorporated into this query without proper sanitization. While the taint analysis did not reveal any unsanitized paths or critical/high severity flows, the raw SQL query is a direct and present danger.
In conclusion, the plugin's lack of historical vulnerabilities and its diligent use of authentication checks and output escaping are strengths. Nevertheless, the un-prepared SQL query is a critical weakness that must be addressed to mitigate the risk of SQL injection. The plugin's overall security could be significantly improved by refactoring the SQL query to utilize prepared statements.
Key Concerns
- Raw SQL query without prepared statements
Package Installator Security Vulnerabilities
Package Installator Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Package Installator Attack Surface
AJAX Handlers 6
WordPress Hooks 5
Maintenance & Trust
Package Installator Maintenance & Trust
Maintenance Signals
Community Trust
Package Installator Alternatives
SSH SFTP Updater Support
ssh-sftp-updater-support
"SSH SFTP Updater Support" is the easiest way to keep your WordPress installation up-to-date with SFTP.
Simple Syntax Highlighting
simple-syntax-highlighting
Simple, clean and lightweight syntax highlighting WordPress plugin.
debianfix
debianfix
Fixes for Debian php stuff
Display SSH Keys
display-ssh
A simple plugin to show public keys of the authors.
Interactive Posts
interactive-posts-ippm
Interactive Posts allows you to upload and attach assets to posts from packages enhancing the experience of any post.
Package Installator Developer Profile
9 plugins · 120 total installs
How We Detect Package Installator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/package-installator/assets/js/vendor/react.min.js/wp-content/plugins/package-installator/assets/js/vendor/react-dom.min.js/wp-content/plugins/package-installator/assets/js/vendor/axios.min.js/wp-content/plugins/package-installator/assets/js/vendor/react-select.min.js/wp-content/plugins/package-installator/assets/js/package-manager.js/wp-content/plugins/package-installator/assets/css/tailwind.min.css/wp-content/plugins/package-installator/assets/css/styles.css/wp-content/plugins/package-installator/assets/js/package-manager.jspackage-installator/assets/css/styles.css?ver=package-installator/assets/js/package-manager.js?ver=HTML / DOM Fingerprints
wpkginst-package-managerwpkginst_ssh_private_key_rowwpkginst_ssh_password_rowwpkginst-settingswpkginst-terminalwpkginst-logwpkginst_ssh_auth_typewpkginst_ssh_hostwpkginst_ssh_usernamewpkginst_ssh_portwpkginst_ssh_private_keywpkginst_ssh_password+1 morewpkginstAjaxReactReactDOMaxiosSelect