
PHP Info Security & Risk Analysis
wordpress.org/plugins/php-info-wpPlugin for troubleshooting purpose to view your phpinfo().
Is PHP Info Safe to Use in 2026?
Generally Safe
Score 85/100PHP Info has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The php-info-wp plugin, v1.0.3, presents a mixed security profile. Statistically, it appears to have a very small attack surface with zero identified entry points, including AJAX handlers, REST API routes, shortcodes, and cron events. Furthermore, there are no reported vulnerabilities (CVEs) in its history, suggesting a relatively clean track record. However, the static code analysis reveals significant concerns. A notable weakness is that 100% of its output (4 total outputs) is not properly escaped, which could lead to Cross-Site Scripting (XSS) vulnerabilities if any dynamic data is ever displayed without sanitization. The presence of file operations without more context also warrants caution, though the absence of direct SQL injection risks via prepared statements and no dangerous function calls are positive indicators. The lack of capability checks and nonce checks on any potential entry points (even though none are currently exposed) is a significant architectural concern that could become a liability if functionality is ever added without proper security considerations. The plugin's reliance on potentially unescaped output is its most immediate and actionable risk.
Key Concerns
- All outputs are unescaped
- No capability checks on entry points
- No nonce checks on entry points
PHP Info Security Vulnerabilities
PHP Info Release Timeline
PHP Info Code Analysis
Output Escaping
PHP Info Attack Surface
WordPress Hooks 3
Maintenance & Trust
PHP Info Maintenance & Trust
Maintenance Signals
Community Trust
PHP Info Alternatives
WP-ServerInfo
wp-serverinfo
Display your host's PHP, MYSQL & memcached (if installed) information on your WordPress dashboard.
phpinfo() WP
phpinfo-wp
A simple plugin to look up server info and manage server configuration of wordpress site
PHP Server Info
php-server-info
A very simple plugin for displaying full PHP Info from within the WordPress Admin menu.
Phpinfo
phpinfo
Prints out your webservers php settings as well as other information about your WordPress installation.
Simple PHP Info
simple-php-info
Displays the phpinfo() table in the WordPress dashboard and creates a shortcode for use in posts and pages.
PHP Info Developer Profile
13 plugins · 840 total installs
How We Detect PHP Info
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/php-info-wp/phpinfo.cssphp-info-wp/phpinfo.css?ver=