
Plugin Compatibility Info Security & Risk Analysis
wordpress.org/plugins/plugin-compatibility-infoShows the version of WordPress that your plugins have been tested up to ( according to the plugin author ).
Is Plugin Compatibility Info Safe to Use in 2026?
Generally Safe
Score 85/100Plugin Compatibility Info has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "plugin-compatibility-info" v1.0.0 exhibits a generally good security posture based on the provided static analysis. The plugin has a limited attack surface with only one AJAX handler, which importantly has an associated capability check. Its adherence to using prepared statements for all SQL queries and a high percentage of properly escaped output are strong indicators of secure coding practices. The absence of known vulnerabilities in its history further supports a low-risk profile.
However, the static analysis does reveal potential areas for improvement. The presence of two "flows with unsanitized paths" is a concern, even though they are not classified as critical or high severity in the taint analysis. This suggests that while direct exploitation might not be immediately apparent, there's a risk of unintended behavior or path traversal if specific user inputs are not handled with extreme care. The absence of nonce checks on the AJAX handler, while it has a capability check, is another point of consideration, as nonces are a crucial layer of defense against CSRF attacks.
Overall, the plugin is well-implemented with secure database practices and good output sanitization. The lack of historical vulnerabilities is a significant positive. The primary weaknesses lie in the two unsanitized path flows and the missing nonce check on the AJAX endpoint, which, while not currently leading to critical issues, represent minor security gaps that could be exploited in conjunction with other factors or future code changes. Addressing these would elevate the plugin's security even further.
Key Concerns
- Unsanitized path flows found (2)
- Missing nonce check on AJAX handler
Plugin Compatibility Info Security Vulnerabilities
Plugin Compatibility Info Code Analysis
Output Escaping
Data Flow Analysis
Plugin Compatibility Info Attack Surface
AJAX Handlers 1
WordPress Hooks 4
Maintenance & Trust
Plugin Compatibility Info Maintenance & Trust
Maintenance Signals
Community Trust
Plugin Compatibility Info Alternatives
Better Plugin Compatibility Control
better-plugin-compatibility-control
Adds version compatibility info to the plugins page to inform the admin at a glance if a plugin is compatible with the current WP and PHP version.
Display PHP Version
display-php-version
Displays the currently installed PHP/MySQL version in the "At a Glance" admin dashboard widget.
Audit Trail
audit-trail
Audit Trail is a plugin to keep track of what is going on inside your blog by monitoring administration functions.
Plugin Compatibility Checker
plugin-compatibility-checker
Scan and check your plugins for PHP and WordPress compatibility. Requires a $1/month Portal subscription to obtain a license key.
PHP Version
php-version
You can able to see the current PHP version in WordPress admin dashboard widget.
Plugin Compatibility Info Developer Profile
2 plugins · 100 total installs
How We Detect Plugin Compatibility Info
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/plugin-compatibility-info/js/plugin-compatibility-info-admin.js/wp-content/plugins/plugin-compatibility-info/css/plugin-compatibility-info-admin.css/wp-content/plugins/plugin-compatibility-info/js/plugin-compatibility-info-admin.jsplugin-compatibility-info/js/plugin-compatibility-info-admin.js?ver=plugin-compatibility-info/css/plugin-compatibility-info-admin.css?ver=HTML / DOM Fingerprints
plugin-compatibility-info-level-plugin-compatibility-info-level-1plugin-compatibility-info-level-2plugin-compatibility-info-level-3plugin-compatibility-info-level-4data-plugin-compatibility-info-slug