Database Manager – WP Adminer Security & Risk Analysis

wordpress.org/plugins/pexlechris-adminer

Manage the database from your WordPress Dashboard using Adminer.

20K active installs v4.3.4.1 PHP 7.0+ WP 4.7.0+ Updated Mar 30, 2026
adminerdatabasemariadbmysqlsql
100
A · Safe
CVEs total1
Unpatched0
Last CVEAug 16, 2022
Download
Safety Verdict

Is Database Manager – WP Adminer Safe to Use in 2026?

Generally Safe

Score 100/100

Database Manager – WP Adminer has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Aug 16, 2022Updated 1mo ago
Risk Assessment

The "pexlechris-adminer" plugin v4.3.3 exhibits a mixed security posture. On the positive side, there are no identified AJAX handlers, REST API routes, shortcodes, or cron events that constitute an attack surface, and the plugin exclusively uses prepared statements for its SQL queries. Furthermore, the code signals indicate a good adherence to output escaping for the majority of outputs and a capability check is present, suggesting some level of authorization is considered.

However, concerns arise from the taint analysis, which reveals two flows with unsanitized paths. While these did not reach critical or high severity in the static analysis, unsanitized paths represent a potential vector for attackers to manipulate file operations or other sensitive functions. The vulnerability history also indicates a past "Exposure of Sensitive Information to an Unauthorized Actor" vulnerability, even though it is currently patched. This historical pattern, coupled with the identified unsanitized paths, suggests a potential for sensitive data to be mishandled if not thoroughly addressed.

Overall, the plugin has strengths in its limited attack surface and SQL practices. However, the presence of unsanitized paths and a history of information exposure vulnerabilities warrant careful consideration and further investigation to ensure these areas are fully mitigated against potential risks.

Key Concerns

  • Taint analysis: 2 flows with unsanitized paths
  • Vulnerability history: Past exposure of sensitive information
  • Output escaping: 26% of outputs not properly escaped
  • File operations present: 3
Vulnerabilities
1 published

Database Manager – WP Adminer Security Vulnerabilities

CVEs by Year

1 CVE in 2022
2022
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

WF-7047d53e-c9e4-46f9-8b5f-3489a1fb7e97-pexlechris-adminermedium · 6.8Exposure of Sensitive Information to an Unauthorized Actor

Database Management tool – Adminer <= 1.1.5 - Information Exposure

Aug 16, 2022 Patched in 1.1.6 (525d)
Version History

Database Manager – WP Adminer Release Timeline

v4.3.4.1Current
v4.3.2
v4.3.0
v4.2.0
v4.1.3
v4.1.2
v4.1.1
v4.1.0
v4.0.4
v4.0.3
v4.0.2
v4.0.1
v4.0.0
v3.1.2
v3.1.1
v3.0.3.1
v3.0.2
v3.0.1
v3.0.0
v2.2.2
Code Analysis
Analyzed Mar 16, 2026

Database Manager – WP Adminer Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
14 escaped
Nonce Checks
0
Capability Checks
1
File Operations
3
External Requests
0
Bundled Libraries
0

Output Escaping

74% escaped19 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
pexlechris_adminer_before_adminer_loads (pexlechris-adminer.php:243)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Database Manager – WP Adminer Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
filterplugin_action_links_pexlechris-adminer/pexlechris-adminer.phppexlechris-adminer.php:42
actionadmin_initpexlechris-adminer.php:59
actionplugins_loadedpexlechris-adminer.php:112
actionplugins_loadedpexlechris-adminer.php:124
actionplugins_loadedpexlechris-adminer.php:154
actionadmin_bar_menupexlechris-adminer.php:160
actionadmin_menupexlechris-adminer.php:201
actionpexlechris_adminer_before_adminer_loadspexlechris-adminer.php:242
actionpexlechris_adminer_before_adminer_loadspexlechris-adminer.php:261
filterdoing_it_wrong_trigger_errorpexlechris-adminer.php:274
Maintenance & Trust

Database Manager – WP Adminer Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 30, 2026
PHP min version7.0
Downloads317K

Community Trust

Rating100/100
Number of ratings28
Active installs20K
Developer Profile

Database Manager – WP Adminer Developer Profile

Pexle Chris

2 plugins · 20K total installs

78
trust score
Avg Security Score
98/100
Avg Patch Time
265 days
View full developer profile
Detection Fingerprints

How We Detect Database Manager – WP Adminer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/pexlechris-adminer/pexlechris-adminer.php
Version Parameters
pexlechris-adminer/pexlechris-adminer.php?ver=

HTML / DOM Fingerprints

CSS Classes
pexlechris-adminer-tools-page-button
Data Attributes
data-pexlechris-adminer-url
FAQ

Frequently Asked Questions about Database Manager – WP Adminer