
Pandora FMS WP – Monitoring WordPress from Pandora FMS Security & Risk Analysis
wordpress.org/plugins/pandora-fms-wpPlugin for monitoring Wordpress with Pandora FMS. Collect data from your wordpress and make it accessible from outside using the REST API.
Is Pandora FMS WP – Monitoring WordPress from Pandora FMS Safe to Use in 2026?
Generally Safe
Score 85/100Pandora FMS WP – Monitoring WordPress from Pandora FMS has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "pandora-fms-wp" v2.0 plugin presents a significant security risk due to its extensive, unprotected attack surface. All identified entry points, including AJAX handlers and REST API routes, lack essential authentication and permission checks. This means any unauthenticated user could potentially interact with and manipulate these endpoints, leading to unintended behavior or exploitation. While the plugin demonstrates good practices in other areas, such as a high percentage of properly escaped output and the absence of dangerous functions or file operations, the lack of access control on its entry points overshadows these strengths.
The static analysis did not reveal any direct vulnerabilities like dangerous functions or critical taint flows. Furthermore, the plugin has no recorded vulnerability history, which is a positive sign suggesting diligent maintenance. However, this lack of history does not negate the immediate risks posed by the unprotected attack surface. The absence of nonce checks on AJAX handlers and capability checks on REST API routes is a critical oversight that requires immediate attention to prevent potential cross-site scripting (XSS) or other injection attacks.
In conclusion, while the plugin shows promise in its handling of output and its clean vulnerability record, the unauthenticated nature of its AJAX and REST API endpoints creates a substantial and immediate security concern. The development team must prioritize implementing robust authentication and authorization mechanisms for all entry points to mitigate these risks. Without these fundamental security controls, the plugin remains highly susceptible to exploitation by malicious actors.
Key Concerns
- AJAX handlers without auth checks
- REST API routes without permission callbacks
- No nonce checks
- No capability checks
- SQL queries with prepared statements only 52%
- Outputs not properly escaped (8%)
Pandora FMS WP – Monitoring WordPress from Pandora FMS Security Vulnerabilities
Pandora FMS WP – Monitoring WordPress from Pandora FMS Release Timeline
Pandora FMS WP – Monitoring WordPress from Pandora FMS Code Analysis
SQL Query Safety
Output Escaping
Pandora FMS WP – Monitoring WordPress from Pandora FMS Attack Surface
AJAX Handlers 2
REST API Routes 17
WordPress Hooks 12
Scheduled Events 1
Maintenance & Trust
Pandora FMS WP – Monitoring WordPress from Pandora FMS Maintenance & Trust
Maintenance Signals
Community Trust
Pandora FMS WP – Monitoring WordPress from Pandora FMS Alternatives
FBS Activity Tracker
fbs-activity-tracker
A modern, granular user activity and audit log WordPress plugin with a custom-designed dashboard interface for comprehensive site monitoring.
Liaison Site Prober
liaison-site-prober
Liaison Site Prober helps you log and track key changes and user actions on your WordPress website — giving you better visibility and security.
MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites
mainwp-child
MainWP Child establishes a secure link between your WordPress sites and your self-hosted MainWP Dashboard, simplifying site management.
Activity Log – Monitor & Record User Changes
aryo-activity-log
This top rated Activity Log plugin helps you monitor & log all changes and actions on your WordPress site, so you can remain secure and organized.
BBQ Firewall – Fast & Powerful Firewall Security
block-bad-queries
The fastest firewall plugin for WordPress. Protect against a wide range of threats with minimal performance impact.
Pandora FMS WP – Monitoring WordPress from Pandora FMS Developer Profile
1 plugin · 10 total installs
How We Detect Pandora FMS WP – Monitoring WordPress from Pandora FMS
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pandora-fms-wp/js/pfms-admin.js/wp-content/plugins/pandora-fms-wp/css/pfms-admin.css/wp-content/plugins/pandora-fms-wp/css/pfms-plugin.css/wp-content/plugins/pandora-fms-wp/js/pfms-admin.jspandora-fms-wp/js/pfms-admin.js?ver=pandora-fms-wp/css/pfms-admin.css?ver=pandora-fms-wp/css/pfms-plugin.css?ver=HTML / DOM Fingerprints
<!-- PFMS_AdminPages init --><!-- PFMS_Widget_Dashboard init --><!-- PFMS_Hooks init --><!-- PFMS_ApiRest init -->+11 morepfms_adminpfms_wp_var/wp-json/pandora-fms-wp/v1/get_data/wp-json/pandora-fms-wp/v1/save_data