
Server & Website Info Security & Risk Analysis
wordpress.org/plugins/server-website-infoDisplay comprehensive server, database, and WordPress information in a clean, modern interface.
Is Server & Website Info Safe to Use in 2026?
Generally Safe
Score 92/100Server & Website Info has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'server-website-info' plugin v1.0.0 exhibits a generally good security posture based on static analysis, with no recorded vulnerabilities and a strong adherence to secure coding practices such as prepared statements for SQL and proper output escaping. The plugin also boasts a minimal attack surface with no exposed AJAX handlers, REST API routes, shortcodes, or cron events that lack authentication or permission checks.
However, a significant concern arises from the presence of the 'shell_exec' function. While the static analysis doesn't explicitly reveal a taint flow that would lead to immediate exploitation, the capability of this function to execute arbitrary operating system commands presents a high-risk potential if it were to be used with user-supplied input that is not rigorously sanitized. The lack of nonce checks and capability checks, though seemingly mitigated by the absence of direct entry points, could become a liability if the plugin's functionality were to be expanded or if a future vulnerability were introduced.
Given the clean vulnerability history and the overall low apparent risk, this plugin appears to be developed with security in mind. The critical area to address is the use of 'shell_exec', which, even without a current exploit, represents a latent threat that should be re-evaluated or secured with robust input validation and output sanitization if its use is essential.
Key Concerns
- Use of dangerous function (shell_exec)
- Missing nonce checks
- Missing capability checks
Server & Website Info Security Vulnerabilities
Server & Website Info Code Analysis
Dangerous Functions Found
Output Escaping
Server & Website Info Attack Surface
WordPress Hooks 3
Maintenance & Trust
Server & Website Info Maintenance & Trust
Maintenance Signals
Community Trust
Server & Website Info Alternatives
Server Info for Debugging
server-info-for-debugging
Displays server stats and WordPress system information for debugging purposes.
atec System Info
atec-system-info
atec System Info (Operating system, server, memory, PHP and database details)
What Template Am I Using
what-template-am-i-using
This plugin is intended for theme developers to use. It shows the current template being used to render the page, current post type, and much more.
BugTrace – Debug Log Tool
debug-log-tool
Essential WordPress debug tool: View/download logs, toggle debug settings & inspect server info. Troubleshoot PHP errors & site issues faster!
Display Server Info
display-server-info
Displays server, PHP, and database info in the dashboard, admin bar, and footer, with shortcode and multilingual support.
Server & Website Info Developer Profile
1 plugin · 10 total installs
How We Detect Server & Website Info
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/server-website-info/assets/css/admin.css/wp-content/plugins/server-website-info/assets/js/admin.js/wp-content/plugins/server-website-info/assets/js/admin.jsserver-website-info/assets/css/admin.css?ver=server-website-info/assets/js/admin.js?ver=HTML / DOM Fingerprints
serverWebsiteInfo