
PHP Compatibility Checker Security & Risk Analysis
wordpress.org/plugins/php-compatibility-checkerMake sure your plugins and themes are compatible with newer PHP versions.
Is PHP Compatibility Checker Safe to Use in 2026?
Generally Safe
Score 85/100PHP Compatibility Checker has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The php-compatibility-checker plugin v1.6.3 exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, external HTTP requests, file operations, and the consistent use of prepared statements for SQL queries are commendable. Furthermore, the 100% proper output escaping and the lack of any identified taint flows with unsanitized paths indicate diligent coding practices to prevent common web vulnerabilities. The plugin also has no exposed entry points like AJAX handlers, REST API routes, or shortcodes that could be exploited without authentication.
However, the plugin's vulnerability history reveals a past issue, specifically a medium-severity Cross-Site Request Forgery (CSRF) vulnerability, although it is now patched. The presence of this historical vulnerability, even if resolved, warrants a degree of caution. While the current static analysis shows no immediate threats, relying solely on this snapshot might overlook potential complexities or interactions with the WordPress environment that a past CSRF issue could hint at. The lack of capability checks and nonce checks is not directly problematic given the zero identified entry points, but it's a practice to be mindful of if the plugin were to evolve and introduce such features.
In conclusion, the plugin is generally well-secured with robust static analysis results. The primary area of concern stems from its past vulnerability, specifically a CSRF. While this has been addressed, it suggests that the plugin is not entirely immune to security flaws and past issues can serve as indicators of areas that might require ongoing scrutiny. The absence of current identified risks is a positive sign, but a proactive approach to monitoring for future vulnerabilities remains advisable.
Key Concerns
- Past medium severity vulnerability found
PHP Compatibility Checker Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
PHP Compatibility Checker <= 1.5.2 - Cross-Site Request Forgery
PHP Compatibility Checker Release Timeline
PHP Compatibility Checker Code Analysis
PHP Compatibility Checker Attack Surface
WordPress Hooks 2
Maintenance & Trust
PHP Compatibility Checker Maintenance & Trust
Maintenance Signals
Community Trust
PHP Compatibility Checker Alternatives
Plugin Compatibility Checker
plugin-compatibility-checker
Scan and check your plugins for PHP and WordPress compatibility. Requires a $1/month Portal subscription to obtain a license key.
Server IP & Memory Usage Display
server-ip-memory-usage
Show the memory limit, current memory usage and IP address in the admin footer.
Version Info – Server Health Monitor, PHP & MySQL Version Display, Environment Indicators
version-info
The #1 technical dashboard for WordPress professionals. Display PHP, MySQL, WP & server versions anywhere in admin. Monitor CPU, RAM, DB size & …
Better Plugin Compatibility Control
better-plugin-compatibility-control
Adds version compatibility info to the plugins page to inform the admin at a glance if a plugin is compatible with the current WP and PHP version.
PHP Version
php-version
You can able to see the current PHP version in WordPress admin dashboard widget.
PHP Compatibility Checker Developer Profile
16 plugins · 3.5M total installs
How We Detect PHP Compatibility Checker
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/php-compatibility-checker/build/index.js/wp-content/plugins/php-compatibility-checker/build/runtime.js/wp-content/plugins/php-compatibility-checker/build/react-dom.js/wp-content/plugins/php-compatibility-checker/build/react.js/wp-content/plugins/php-compatibility-checker/build/moment.js/wp-content/plugins/php-compatibility-checker/build/lodash.js+6 morephp-compatibility-checker/build/index.js?ver=php-compatibility-checker/build/runtime.js?ver=php-compatibility-checker/build/react-dom.js?ver=php-compatibility-checker/build/react.js?ver=php-compatibility-checker/build/moment.js?ver=php-compatibility-checker/build/lodash.js?ver=php-compatibility-checker/build/vendors-node_modules_wp_element_build_index_js.js?ver=php-compatibility-checker/build/vendors-node_modules_wp_components_build_index_js.js?ver=php-compatibility-checker/build/vendors-node_modules_wp_i18n_build_index_js.js?ver=php-compatibility-checker/build/vendors-node_modules_wp_data_build_index_js.js?ver=php-compatibility-checker/build/vendors-node_modules_wp_edit_post_build_index_js.js?ver=php-compatibility-checker/build/vendors-node_modules_react_jsx_runtime_js.js?ver=HTML / DOM Fingerprints
components-noticecomponents-spinnercomponents-panelcomponents-buttoncomponents-modalcomponents-tab-panelcomponents-form-togglecomponents-text-control+96 moredata-is-wpengine-plugindata-plugin-slug='php-compatibility-checker'data-plugin-version='1.6.3'window.wp.elementwindow.wp.componentswindow.wp.i18nwindow.wp.datawindow.wp.editPostwindow.React+3 more/wp-json/wpe-php-compat/v1/scan/wp-json/wpe-php-compat/v1/settings/wp-json/wpe-php-compat/v1/scan-results