Semonto – Uptime monitoring, Broken Links, SSL and Lighthouse Security & Risk Analysis

wordpress.org/plugins/semonto-website-monitor

Semonto watches the health of your website and server. Get notified when something is wrong, so you can fix the issue before anyone notices.

0 active installs v1.1.6 PHP 7.4+ WP 5.0+ Updated May 15, 2025
broken-linkssemontoserver-healthssluptime
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Semonto – Uptime monitoring, Broken Links, SSL and Lighthouse Safe to Use in 2026?

Generally Safe

Score 92/100

Semonto – Uptime monitoring, Broken Links, SSL and Lighthouse has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The semonto-website-monitor plugin v1.1.6 exhibits a generally strong security posture with no known vulnerabilities or CVEs. The static analysis reveals a commendably small attack surface, with no AJAX handlers, REST API routes, shortcodes, or cron events exposed without authentication. The code also demonstrates good practices regarding SQL queries, exclusively using prepared statements, and a very high percentage of properly escaped output. The absence of file operations and external HTTP requests further reduces potential attack vectors. However, the presence of dangerous functions like 'exec' and 'shell_exec' is a significant concern. While the taint analysis shows no identified unsanitized flows, the mere existence of these powerful functions, especially without any apparent authorization or capability checks guarding their use, creates a latent risk. If an attacker could somehow trigger these functions, it could lead to arbitrary code execution on the server. The lack of nonce checks and capability checks on any potential entry points (though none are explicitly identified in the attack surface) is also a weakness that could be exploited if new entry points are introduced or if existing ones are not properly secured by default.

Key Concerns

  • Dangerous functions (exec, shell_exec) present
  • No nonce checks on potential entry points
  • No capability checks on potential entry points
Vulnerabilities
None known

Semonto – Uptime monitoring, Broken Links, SSL and Lighthouse Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Semonto – Uptime monitoring, Broken Links, SSL and Lighthouse Release Timeline

v1.1.6Current
v1.1.4
v1.1.3
v1.1.2
v1.1.1
v1.1.0
v1.0.1
Code Analysis
Analyzed Mar 17, 2026

Semonto – Uptime monitoring, Broken Links, SSL and Lighthouse Code Analysis

Dangerous Functions
3
Raw SQL Queries
0
5 prepared
Unescaped Output
1
97 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

exec$df_command = exec('which df');functions.php:418
exec$vmstat_command = exec('which df');functions.php:427
shell_exec$output = shell_exec('df -h');functions.php:446

SQL Query Safety

100% prepared5 total queries

Output Escaping

99% escaped98 total outputs
Attack Surface

Semonto – Uptime monitoring, Broken Links, SSL and Lighthouse Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
filterquery_varsfunctions.php:330
actionparse_requestfunctions.php:331
actioninitfunctions.php:332
actionadmin_enqueue_scriptssemonto-health-monitor.php:19
actionadmin_enqueue_scriptssemonto-health-monitor.php:20
actionadmin_menusemonto-health-monitor.php:86
actionadmin_initsemonto-health-monitor.php:95
actionadmin_noticessemonto-health-monitor.php:96
actionadmin_initsemonto-health-monitor.php:97
Maintenance & Trust

Semonto – Uptime monitoring, Broken Links, SSL and Lighthouse Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.6
Last updatedMay 15, 2025
PHP min version7.4
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Semonto – Uptime monitoring, Broken Links, SSL and Lighthouse Developer Profile

CodingMammoth

1 plugin · 0 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Semonto – Uptime monitoring, Broken Links, SSL and Lighthouse

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/semonto-website-monitor/semonto-health-monitor.css/wp-content/plugins/semonto-website-monitor/semonto-health-monitor.js
Script Paths
/wp-content/plugins/semonto-website-monitor/semonto-health-monitor.js

HTML / DOM Fingerprints

CSS Classes
semonto-health-monitorsemonto-health-monitor__install-messagesemonto-health-monitor__titlesemonto-health-monitor__tabssemonto-health-monitor__tabsemonto-health-monitor__body
JS Globals
SemontoHealthMonitor
FAQ

Frequently Asked Questions about Semonto – Uptime monitoring, Broken Links, SSL and Lighthouse