
Show Environment In Editor Security & Risk Analysis
wordpress.org/plugins/show-environment-in-editorShow the current server environment in the Gutenberg editor screen.
Is Show Environment In Editor Safe to Use in 2026?
Generally Safe
Score 100/100Show Environment In Editor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "show-environment-in-editor" v1.0.9 exhibits a strong security posture based on the provided static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the plugin's attack surface. Furthermore, the code analysis reveals no dangerous functions, raw SQL queries, file operations, external HTTP requests, or unsanitized taint flows. All identified outputs are properly escaped, and the plugin demonstrates good practices regarding SQL query preparedness. The lack of recorded vulnerabilities in its history further reinforces this positive security assessment.
While the plugin appears to be well-secured, the complete absence of capability checks is a notable weakness. In scenarios where a plugin might expose sensitive information or functionality, robust capability checks are crucial for ensuring that only authorized users can access these features. However, given the reported limited attack surface and absence of exploitable code signals, this weakness may not present an immediate, high-severity risk in the current version. The overall security is good, but a review of potential privilege escalation vectors would be beneficial.
Key Concerns
- Missing capability checks
Show Environment In Editor Security Vulnerabilities
Show Environment In Editor Code Analysis
Output Escaping
Show Environment In Editor Attack Surface
WordPress Hooks 2
Maintenance & Trust
Show Environment In Editor Maintenance & Trust
Maintenance Signals
Community Trust
Show Environment In Editor Alternatives
No alternatives data available yet.
Show Environment In Editor Developer Profile
6 plugins · 30K total installs
How We Detect Show Environment In Editor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/show-environment-in-editor/build/index.jsbuild/index.jsshow-environment-in-editor/build/index.js?ver=1.0.9HTML / DOM Fingerprints
seie_vars