SensorPress Security & Risk Analysis

wordpress.org/plugins/sensorpress-uptime-monitoring

The Internet is always on. Is your website?

30 active installs v1.0 PHP + WP 3.6+ Updated Dec 6, 2013
monitoringup-time
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is SensorPress Safe to Use in 2026?

Generally Safe

Score 85/100

SensorPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The "sensorpress-uptime-monitoring" v1.0 plugin exhibits a seemingly good security posture based on the provided static analysis. The absence of identified vulnerabilities in its history and the limited attack surface with no unprotected entry points are positive indicators. However, the static analysis reveals significant concerns, particularly the 100% unescaped output, which presents a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. The lack of any nonce or capability checks on its entry points, despite having external HTTP requests, suggests potential authorization bypass or unauthorized action risks. While the SQL queries are prepared, the other identified weaknesses create an uneven security profile, leaning towards concerning due to the high likelihood of exploitable output vulnerabilities. The plugin's history of no recorded vulnerabilities might be due to its limited version or potential lack of extensive security auditing.

Key Concerns

  • Significant portion of output is unescaped
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

SensorPress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

SensorPress Release Timeline

v1.0Current
Code Analysis
Analyzed Apr 16, 2026

SensorPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
4
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

33% escaped6 total outputs
Attack Surface

SensorPress Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionadmin_enqueue_scriptsadmin/class-sensorpress-admin.php:73
actionadmin_enqueue_scriptsadmin/class-sensorpress-admin.php:74
actionadmin_menuadmin/class-sensorpress-admin.php:77
actionadmin_initadmin/class-sensorpress-admin.php:78
actioninitpublic/class-sensorpress.php:69
actionwpmu_new_blogpublic/class-sensorpress.php:72
actionwp_enqueue_scriptspublic/class-sensorpress.php:75
actionwp_enqueue_scriptspublic/class-sensorpress.php:76
actionwp_headpublic/class-sensorpress.php:77
actionplugins_loadedsensorpress-uptime-monitoring.php:54
actionplugins_loadedsensorpress-uptime-monitoring.php:79
Maintenance & Trust

SensorPress Maintenance & Trust

Maintenance Signals

WordPress version tested3.7.41
Last updatedDec 6, 2013
PHP min version
Downloads3K

Community Trust

Rating66/100
Number of ratings3
Active installs30
Developer Profile

SensorPress Developer Profile

brewlabs

5 plugins · 2K total installs

60
trust score
Avg Security Score
73/100
Avg Patch Time
1682 days
View full developer profile
Detection Fingerprints

How We Detect SensorPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sensorpress-uptime-monitoring/assets/css/admin.css/wp-content/plugins/sensorpress-uptime-monitoring/assets/js/admin.js
Script Paths
assets/js/admin.js
Version Parameters
sensorpress-uptime-monitoring/assets/css/admin.css?ver=sensorpress-uptime-monitoring/assets/js/admin.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- SensorPress:<!-- If this file is called directly, abort. --><!-- SensorPress:<!-- Plugin class. This class should ideally be used to work with the -->+41 more
FAQ

Frequently Asked Questions about SensorPress