Pandora FMS WP – Monitoring WordPress from Pandora FMS Security & Risk Analysis

wordpress.org/plugins/pandora-fms-wp

Plugin for monitoring Wordpress with Pandora FMS. Collect data from your wordpress and make it accessible from outside using the REST API.

10 active installs v2.0 PHP + WP 4.7+ Updated Feb 9, 2022
auditmonitoringsecuresecurity
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Pandora FMS WP – Monitoring WordPress from Pandora FMS Safe to Use in 2026?

Generally Safe

Score 85/100

Pandora FMS WP – Monitoring WordPress from Pandora FMS has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The "pandora-fms-wp" v2.0 plugin presents a significant security risk due to its extensive, unprotected attack surface. All identified entry points, including AJAX handlers and REST API routes, lack essential authentication and permission checks. This means any unauthenticated user could potentially interact with and manipulate these endpoints, leading to unintended behavior or exploitation. While the plugin demonstrates good practices in other areas, such as a high percentage of properly escaped output and the absence of dangerous functions or file operations, the lack of access control on its entry points overshadows these strengths.

The static analysis did not reveal any direct vulnerabilities like dangerous functions or critical taint flows. Furthermore, the plugin has no recorded vulnerability history, which is a positive sign suggesting diligent maintenance. However, this lack of history does not negate the immediate risks posed by the unprotected attack surface. The absence of nonce checks on AJAX handlers and capability checks on REST API routes is a critical oversight that requires immediate attention to prevent potential cross-site scripting (XSS) or other injection attacks.

In conclusion, while the plugin shows promise in its handling of output and its clean vulnerability record, the unauthenticated nature of its AJAX and REST API endpoints creates a substantial and immediate security concern. The development team must prioritize implementing robust authentication and authorization mechanisms for all entry points to mitigate these risks. Without these fundamental security controls, the plugin remains highly susceptible to exploitation by malicious actors.

Key Concerns

  • AJAX handlers without auth checks
  • REST API routes without permission callbacks
  • No nonce checks
  • No capability checks
  • SQL queries with prepared statements only 52%
  • Outputs not properly escaped (8%)
Vulnerabilities
None known

Pandora FMS WP – Monitoring WordPress from Pandora FMS Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Pandora FMS WP – Monitoring WordPress from Pandora FMS Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

Pandora FMS WP – Monitoring WordPress from Pandora FMS Code Analysis

Dangerous Functions
0
Raw SQL Queries
12
13 prepared
Unescaped Output
15
179 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

52% prepared25 total queries

Output Escaping

92% escaped194 total outputs
Attack Surface
19 unprotected

Pandora FMS WP – Monitoring WordPress from Pandora FMS Attack Surface

Entry Points19
Unprotected19

AJAX Handlers 2

authwp_ajax_check_admin_user_enabledpandorafms-wp.php:44
authwp_ajax_check_plugins_pending_updatepandorafms-wp.php:45

REST API Routes 17

GET/wp-json/pandorafms_wp/onlineincludes/PandoraFMS_WP.class.php:270
GET/wp-json/pandorafms_wp/site_nameincludes/PandoraFMS_WP.class.php:277
GET/wp-json/pandorafms_wp/versionincludes/PandoraFMS_WP.class.php:284
GET/wp-json/pandorafms_wp/wp_versionincludes/PandoraFMS_WP.class.php:291
GET/wp-json/pandorafms_wp/adminincludes/PandoraFMS_WP.class.php:298
GET/wp-json/pandorafms_wp/new_accountincludes/PandoraFMS_WP.class.php:306
GET/wp-json/pandorafms_wp/theme_registeredincludes/PandoraFMS_WP.class.php:313
GET/wp-json/pandorafms_wp/plugin_registeredincludes/PandoraFMS_WP.class.php:320
GET/wp-json/pandorafms_wp/new_postsincludes/PandoraFMS_WP.class.php:327
GET/wp-json/pandorafms_wp/new_commentsincludes/PandoraFMS_WP.class.php:334
GET/wp-json/pandorafms_wp/plugin_updateincludes/PandoraFMS_WP.class.php:341
GET/wp-json/pandorafms_wp/core_updateincludes/PandoraFMS_WP.class.php:348
GET/wp-json/pandorafms_wp/user_loginincludes/PandoraFMS_WP.class.php:355
GET/wp-json/pandorafms_wp/failed_loginincludes/PandoraFMS_WP.class.php:362
GET/wp-json/pandorafms_wp/custom_sql_1includes/PandoraFMS_WP.class.php:369
GET/wp-json/pandorafms_wp/custom_sql_2includes/PandoraFMS_WP.class.php:376
GET/wp-json/pandorafms_wp/bruteforceincludes/PandoraFMS_WP.class.php:383
WordPress Hooks 12
actionuser_registerincludes/PandoraFMS_WP.class.php:421
actionwp_loginincludes/PandoraFMS_WP.class.php:422
actionwp_login_failedincludes/PandoraFMS_WP.class.php:423
actionwp_dashboard_setupincludes/PandoraFMS_WP.class.php:528
actionwp_print_scriptspandorafms-wp.php:41
actionadmin_footerpandorafms-wp.php:43
actioncron_clean_logspandorafms-wp.php:53
actionrest_api_initpandorafms-wp.php:58
actionadmin_noticespandorafms-wp.php:73
actioninitpandorafms-wp.php:74
actionadmin_initpandorafms-wp.php:75
actionadmin_menupandorafms-wp.php:76

Scheduled Events 1

cron_clean_logs
Maintenance & Trust

Pandora FMS WP – Monitoring WordPress from Pandora FMS Maintenance & Trust

Maintenance Signals

WordPress version tested5.9.13
Last updatedFeb 9, 2022
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Pandora FMS WP – Monitoring WordPress from Pandora FMS Developer Profile

Ártica PFMS

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Pandora FMS WP – Monitoring WordPress from Pandora FMS

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/pandora-fms-wp/js/pfms-admin.js/wp-content/plugins/pandora-fms-wp/css/pfms-admin.css/wp-content/plugins/pandora-fms-wp/css/pfms-plugin.css
Script Paths
/wp-content/plugins/pandora-fms-wp/js/pfms-admin.js
Version Parameters
pandora-fms-wp/js/pfms-admin.js?ver=pandora-fms-wp/css/pfms-admin.css?ver=pandora-fms-wp/css/pfms-plugin.css?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- PFMS_AdminPages init --><!-- PFMS_Widget_Dashboard init --><!-- PFMS_Hooks init --><!-- PFMS_ApiRest init -->+11 more
JS Globals
pfms_adminpfms_wp_var
REST Endpoints
/wp-json/pandora-fms-wp/v1/get_data/wp-json/pandora-fms-wp/v1/save_data
FAQ

Frequently Asked Questions about Pandora FMS WP – Monitoring WordPress from Pandora FMS