
Server Info – System Health & Diagnostics Suite Security & Risk Analysis
wordpress.org/plugins/server-infoThe ultimate free Server Info plugin for WordPress. View Memory Limits, PHP/MySQL versions, Datacenter Location, and an Always-On Admin HUD.
Is Server Info – System Health & Diagnostics Suite Safe to Use in 2026?
Generally Safe
Score 100/100Server Info – System Health & Diagnostics Suite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The server-info plugin v0.0.1 exhibits a concerning security posture due to a significant lack of protective measures, despite a clean vulnerability history. While the static analysis shows no direct vulnerabilities like unsanitized taint flows or raw SQL queries, the absence of nonces and capability checks on all entry points is a major red flag. The presence of the `exec` function is also a serious concern, as it can be leveraged for remote code execution if proper sanitization and access controls are not rigorously applied, which appears to be the case here given the lack of checks.
The plugin's attack surface is currently zero according to the static analysis, which is an unusual finding given the presence of the `exec` function. This suggests either a very limited scope for the plugin or a potential misinterpretation of the analysis. The clean vulnerability history is a positive sign, but it does not negate the inherent risks introduced by the identified code signals. A plugin with the `exec` function and no authentication or authorization checks on any potential entry points is inherently risky, regardless of past exploits.
In conclusion, while the plugin has no recorded vulnerabilities, its static analysis reveals critical weaknesses. The `exec` function, combined with the complete lack of nonces and capability checks, creates a high-risk scenario for potential privilege escalation or arbitrary code execution. This plugin should not be deployed in a production environment without significant security enhancements.
Key Concerns
- Dangerous function 'exec' found
- No nonce checks on entry points
- No capability checks on entry points
- Output escaping is not fully implemented (78%)
Server Info – System Health & Diagnostics Suite Security Vulnerabilities
Server Info – System Health & Diagnostics Suite Release Timeline
Server Info – System Health & Diagnostics Suite Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Server Info – System Health & Diagnostics Suite Attack Surface
WordPress Hooks 4
Maintenance & Trust
Server Info – System Health & Diagnostics Suite Maintenance & Trust
Maintenance Signals
Community Trust
Server Info – System Health & Diagnostics Suite Alternatives
atec System Info
atec-system-info
atec System Info (Operating system, server, memory, PHP and database details)
PHP Server Info
php-server-info
A very simple plugin for displaying full PHP Info from within the WordPress Admin menu.
Server Info for Debugging
server-info-for-debugging
Displays server stats and WordPress system information for debugging purposes.
Display Server Info
display-server-info
Displays server, PHP, and database info in the dashboard, admin bar, and footer, with shortcode and multilingual support.
Apache Status & Info
htaccess-server-info-server-status
Apache server-info and server-status monitoring right in your WordPress admin.
Server Info – System Health & Diagnostics Suite Developer Profile
4 plugins · 4K total installs
How We Detect Server Info – System Health & Diagnostics Suite
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/server-info/assets/css/style.cssserver-info/assets/css/style.css?ver=HTML / DOM Fingerprints
serverinfo_dashboard_widgetdashboard_inf_tableinfohouse_table