
Query monitor Twig profile Security & Risk Analysis
wordpress.org/plugins/query-monitor-twig-profileDisplays Twig profiler output in Query Monitor.
Is Query monitor Twig profile Safe to Use in 2026?
Generally Safe
Score 85/100Query monitor Twig profile has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The query-monitor-twig-profile plugin, version 1.3.6, exhibits a strong security posture based on the provided static analysis. The absence of identified AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the attack surface. Furthermore, the complete reliance on prepared statements for all SQL queries and the lack of dangerous function calls are excellent security practices.
However, a concern arises from the output escaping. With only 43% of outputs properly escaped, there's a moderate risk of Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is directly outputted without sanitization. The lack of identified vulnerabilities in the history is positive, suggesting good development practices or a lack of exploitation attempts. Nevertheless, the output escaping issue warrants attention for a more robust security profile.
In conclusion, the plugin demonstrates strengths in preventing common injection vulnerabilities and limiting its attack surface. The primary weakness lies in output escaping, which could be improved. The vulnerability history is reassuring, but the presence of unescaped output means that immediate risks, while not historically present, are not entirely absent.
Key Concerns
- Low percentage of properly escaped output
Query monitor Twig profile Security Vulnerabilities
Query monitor Twig profile Release Timeline
Query monitor Twig profile Code Analysis
Output Escaping
Query monitor Twig profile Attack Surface
WordPress Hooks 6
Maintenance & Trust
Query monitor Twig profile Maintenance & Trust
Maintenance Signals
Community Trust
Query monitor Twig profile Alternatives
Query Monitor
query-monitor
Query Monitor is the developer tools panel for WordPress and WooCommerce.
Code Profiler – WordPress Performance Profiling and Debugging Made Easy
code-profiler
A profiler to measure the performance of your WordPress plugins and themes.
Timber Debug Bar
debug-bar-timber
Adds a Panel to the Debug Bar for Timber information
Clear cache for Timber
clear-cache-for-timber
Small Wordpress plugin for flushing cache of Timber (Twig Template Plugin for Wordpress)
ACF Timber Integration
acf-timber-integration
Automatically enables in the Timber twig context variable all user-defined advanced custom fields.
Query monitor Twig profile Developer Profile
1 plugin · 80 total installs
How We Detect Query monitor Twig profile
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/query-monitor-twig-profile/assets/save.js/wp-content/plugins/query-monitor-twig-profile/assets/twig-profile/dist/twig-profile.js/wp-content/plugins/query-monitor-twig-profile/assets/save.js/wp-content/plugins/query-monitor-twig-profile/assets/twig-profile/dist/twig-profile.jsquery-monitor-twig-profile/assets/save.js?ver=query-monitor-twig-profile/assets/twig-profile/dist/twig-profile.js?ver=HTML / DOM Fingerprints
qm_twig_profile_l10n