
Simple Debug Security & Risk Analysis
wordpress.org/plugins/simple-debugAnalyzes WordPress website performance, helps to locate slow function hooks.
Is Simple Debug Safe to Use in 2026?
Generally Safe
Score 85/100Simple Debug has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "simple-debug" plugin version 1.5 exhibits a generally positive security posture, characterized by its lack of identified vulnerabilities in its history and the absence of critical findings in taint analysis. The plugin also demonstrates good practices by utilizing prepared statements for all SQL queries and having only one recorded file operation and one capability check. However, there are significant areas of concern that detract from its overall security.
The presence of the `passthru` function is a critical red flag, as it is highly susceptible to command injection if user-supplied data is passed to it without proper sanitization. While the static analysis did not report any taint flows with unsanitized paths, the inherent danger of `passthru` warrants extreme caution. Furthermore, the output escaping is only properly implemented for 10% of outputs, indicating a high risk of cross-site scripting (XSS) vulnerabilities, especially if any user-controllable data is displayed without adequate sanitization.
In conclusion, while the plugin's vulnerability history is clean and its SQL practices are sound, the presence of `passthru` and the low percentage of proper output escaping create substantial security risks. The lack of reported taint flows might be a limitation of the analysis performed, or the dangerous functions are not currently exposed to untrusted input in a way that the analysis could detect. Nevertheless, these specific code signals demand immediate attention and remediation.
Key Concerns
- Dangerous function 'passthru' detected
- Low percentage of properly escaped output (10%)
- No nonce checks on entry points
Simple Debug Security Vulnerabilities
Simple Debug Code Analysis
Dangerous Functions Found
Output Escaping
Simple Debug Attack Surface
WordPress Hooks 9
Maintenance & Trust
Simple Debug Maintenance & Trust
Maintenance Signals
Community Trust
Simple Debug Alternatives
Admin Menu Slide
admin-menu-slide
Adds a feature to hide admin menu and make it slide when hovering on the edge of the screen.
Database Performance Monitor
database-performance-monitor
Outputs some database query information on page load for logged in admins. Output is located as an html comment in the footer and also in the console.
Quick Disabler
quick-disabler
Easily disable all active plugins—except this one—with one click. Re-enable them anytime using AJAX. Perfect for debugging and troubleshooting.
Redux Framework
redux-framework
Redux is a simple, truly extensible, and fully responsive options framework for WordPress themes and plugins. It ships with an integrated demo.
Query Monitor – The developer tools panel for WordPress
query-monitor
Query Monitor is the developer tools panel for WordPress and WooCommerce.
Simple Debug Developer Profile
19 plugins · 2K total installs
How We Detect Simple Debug
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/simple-debug/assets/css/simple-debug-admin.css/wp-content/plugins/simple-debug/assets/js/simple-debug-admin.js/wp-content/plugins/simple-debug/assets/css/simple-debug.css/wp-content/plugins/simple-debug/assets/js/simple-debug-admin.jssimple-debug/assets/css/simple-debug-admin.css?ver=simple-debug/assets/js/simple-debug-admin.js?ver=simple-debug/assets/css/simple-debug.css?ver=HTML / DOM Fingerprints
simple-debug-admin-wrapsimple_debug_form<!-- Created by MyWebsiteAdvisor.com --><!-- Simple Debug Plugin --><!-- Simple Debug Settings --><!-- Simple Debug: Settings -->+4 moredata-simple-debug-admin-ajax-urldata-simple-debug-site-urlSimpleDebugAdminsimple_debug_ajax_object