
Plugin Report Security & Risk Analysis
wordpress.org/plugins/plugin-reportA WordPress plugin that provides detailed information about currently installed plugins.
Is Plugin Report Safe to Use in 2026?
Generally Safe
Score 100/100Plugin Report has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "plugin-report" v2.2.2 presents a generally good security posture with several positive indicators. Notably, it has a small attack surface, with all identified entry points having authentication checks. The code demonstrates strong practices by exclusively using prepared statements for its SQL queries and includes nonce and capability checks, suggesting an awareness of common WordPress security vulnerabilities. The absence of known CVEs and past vulnerabilities further contributes to a positive outlook.
However, there are areas for improvement that introduce some risk. The taint analysis reveals a flow with an unsanitized path, which is a significant concern, even though it was not classified as critical or high severity. This could potentially lead to unexpected behavior or vulnerabilities if an attacker can control the input to this flow. Additionally, a concerning 35% of output escaping is noted as not properly escaped. This indicates a potential for Cross-Site Scripting (XSS) vulnerabilities, especially if sensitive data is being outputted without adequate sanitization.
In conclusion, while "plugin-report" v2.2.2 exhibits strengths in its handling of SQL, authentication, and its clean vulnerability history, the presence of an unsanitized path in taint analysis and the significant percentage of unescaped output warrant caution. Addressing these specific issues will further strengthen the plugin's security.
Key Concerns
- Flow with unsanitized path
- Low percentage of properly escaped output
Plugin Report Security Vulnerabilities
Plugin Report Code Analysis
Output Escaping
Data Flow Analysis
Plugin Report Attack Surface
AJAX Handlers 1
WordPress Hooks 4
Maintenance & Trust
Plugin Report Maintenance & Trust
Maintenance Signals
Community Trust
Plugin Report Alternatives
Proper Network Activation
proper-network-activation
Avoid errors when using WordPress MultiSite network activation
Multisite Administration Tools
multisite-administration-tools
Adds information to the network admin sites, plugins and themes page. Allows you to easily see what theme and plugins are enabled on a site.
WPCore Plugin Manager
wpcore
Create plugin collections and install them in one click on any WordPress site.
Root Relative URLs
root-relative-urls
Converts all URLs to root-relative URLs for hosting the same site on multiple IPs, easier production migration and better mobile device testing.
Hide Plugins
hide-plugins
Hide installed plugins from clients and other admin users.
Plugin Report Developer Profile
4 plugins · 2K total installs
How We Detect Plugin Report
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/plugin-report/css/plugin-report.css/wp-content/plugins/plugin-report/js/tablesort.min.js/wp-content/plugins/plugin-report/js/tablesort.number.min.js/wp-content/plugins/plugin-report/js/tablesort.dotsep.min.js/wp-content/plugins/plugin-report/js/plugin-report.jsplugin-report/style.css?ver=plugin-report/js/tablesort.min.js?ver=plugin-report/js/tablesort.number.min.js?ver=plugin-report/js/tablesort.dotsep.min.js?ver=plugin-report/js/plugin-report.js?ver=HTML / DOM Fingerprints
pr-risk-lowpr-risk-mediumpr-risk-highplugin-report-row-temp-no-sortdata-sort-defaultdata-sort-methoddata-plugin-slugplugin_report_vars