
phpinfo() WP – Site Health, PHP Compatibility & Server Audit Security & Risk Analysis
wordpress.org/plugins/phpinfo-wpStop silent site breakages. The ultimate in-admin server audit & per-user troubleshooting tool built for agencies and professional developers.
Is phpinfo() WP – Site Health, PHP Compatibility & Server Audit Safe to Use in 2026?
Generally Safe
Score 99/100phpinfo() WP – Site Health, PHP Compatibility & Server Audit has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The phpinfo-wp plugin v6.1 exhibits a mixed security posture. On one hand, the static analysis indicates a very small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events that are unprotected. Furthermore, all SQL queries are properly prepared, and there are no identified taint flows of critical or high severity. This suggests that the core functionality of the plugin, as analyzed, does not expose direct input validation or direct database manipulation vulnerabilities through common entry points.
However, significant concerns arise from the output escaping and vulnerability history. A concerning 0% of output is properly escaped, meaning sensitive information or unexpected data could be rendered directly in the browser, potentially leading to XSS vulnerabilities. The plugin has a history of 2 medium severity CVEs, specifically related to Exposure of Sensitive Information and Cross-Site Request Forgery, with the most recent one being June 19, 2024, which is unpatched. This history, coupled with the lack of output escaping, strongly suggests a pattern of insecure handling of data and a persistent risk of sensitive information disclosure and potentially client-side attacks.
In conclusion, while the plugin has a low direct attack surface and secure database practices, the prevalent lack of output escaping and the recent, unpatched medium-severity vulnerabilities significantly undermine its security. The identified historical vulnerability types indicate a consistent weakness in how the plugin manages and presents data. Users should be extremely cautious, and the lack of output escaping should be addressed immediately.
Key Concerns
- Unpatched medium severity CVEs
- 100% of output not properly escaped
- 0 capability checks on entry points
phpinfo() WP – Site Health, PHP Compatibility & Server Audit Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
phpinfo() WP <= 5.0 - Unauthenticated Information Exposure
phpinfo() WP <= 4.0 - Cross-Site Request Forgery
phpinfo() WP – Site Health, PHP Compatibility & Server Audit Release Timeline
phpinfo() WP – Site Health, PHP Compatibility & Server Audit Code Analysis
Output Escaping
phpinfo() WP – Site Health, PHP Compatibility & Server Audit Attack Surface
WordPress Hooks 6
Maintenance & Trust
phpinfo() WP – Site Health, PHP Compatibility & Server Audit Maintenance & Trust
Maintenance Signals
Community Trust
phpinfo() WP – Site Health, PHP Compatibility & Server Audit Alternatives
Site Health Tools
site-health-tools
Introduces additional common tools to the Site Health interface.
Troubleshooting
troubleshooting
Provides a Troubleshooting Mode to help with support and debugging.
Phpinfo
phpinfo
Prints out your webservers php settings as well as other information about your WordPress installation.
Plugin Health Check
plugin-health-check
Adds checks to the Site Health screen to test installed plugins and themes.
Health Radar
health-radar
Detect plugin conflicts, performance issues, PHP compatibility risks, and debug log errors from your WordPress dashboard.
phpinfo() WP – Site Health, PHP Compatibility & Server Audit Developer Profile
1 plugin · 3K total installs
How We Detect phpinfo() WP – Site Health, PHP Compatibility & Server Audit
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/phpinfo-wp/css/style.css/wp-content/plugins/phpinfo-wp/js/scripts.jsjs/scripts.js#async