
Relay Security & Risk Analysis
wordpress.org/plugins/relayA bridge between your WordPress site’s internals and your monitoring tools.
Is Relay Safe to Use in 2026?
Generally Safe
Score 100/100Relay has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "relay" plugin v1.5.1 exhibits a strong security posture based on the provided static analysis. The absence of any identified attack surface, dangerous functions, raw SQL queries, unescaped output, file operations, or external HTTP requests is commendable. The presence of a nonce check further indicates a commitment to basic security practices. Taint analysis revealing zero flows with unsanitized paths further reinforces the impression of secure coding. The plugin's vulnerability history also shows zero recorded CVEs, suggesting a stable and well-maintained codebase. However, the complete lack of capability checks on any entry points, even though there are no entry points detected in this analysis, could be a potential area for concern if functionality were to be added in the future without proper authorization controls. Overall, the plugin appears to be very secure with a focus on preventing common web vulnerabilities. The limited scope of the static analysis (e.g., zero flows analyzed) means that the absence of vulnerabilities might be due to the plugin's simplicity rather than an exhaustive audit. While the current state is excellent, future development should prioritize implementing capability checks for any added functionality.
Relay Security Vulnerabilities
Relay Release Timeline
Relay Code Analysis
Output Escaping
Relay Attack Surface
WordPress Hooks 3
Maintenance & Trust
Relay Maintenance & Trust
Maintenance Signals
Community Trust
Relay Alternatives
Synapse – Data Bridge for Automation
synapse
The data bridge for WordPress. A powerful REST API to monitor sites and automate workflows with n8n, Zapier, Make, and your own scripts.
Real User Monitoring by RapidSpike
rapidspike-real-user-monitoring
Live performance data via Real User Monitoring. Track real user experience - traffic volume and page load speed - by country, browser and device.
UpdaWa — Update Watchdog
updawa
Monitors WordPress core, plugin, theme, and SSL certificate status via a clean admin dashboard and a Bearer-token-secured REST API.
Vigilant Healthchecks
vigilant-healthchecks
A WordPress plugin that provides healthchecks to your WordPress site that integrate seamlessly with Vigilant (https://govigilant.io).
MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites
mainwp-child
MainWP Child establishes a secure link between your WordPress sites and your self-hosted MainWP Dashboard, simplifying site management.
Relay Developer Profile
4 plugins · 530 total installs
How We Detect Relay
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
relay_api_key/relay/v1/core