
Site Info Security & Risk Analysis
wordpress.org/plugins/site-info-dashboard-widgetWordPress dashboard widget displaying the main site info.
Is Site Info Safe to Use in 2026?
Use With Caution
Score 64/100Site Info has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The plugin "site-info-dashboard-widget" v1.1 exhibits a mixed security posture. On the positive side, the static analysis reveals no critical code signals like dangerous functions, raw SQL queries, or file operations. It also correctly uses prepared statements for all SQL queries and has a small attack surface with no apparent unprotected entry points. However, there are some areas of concern. The output escaping is only 50% properly implemented, meaning there's a potential for cross-site scripting (XSS) vulnerabilities if user-controlled data is directly outputted without proper sanitization. The complete absence of nonce and capability checks on what would typically be considered entry points (even though the reported number is zero) is also a red flag that might be an artifact of the analysis or an oversight in the plugin's design. The vulnerability history is a significant concern, with one low-severity, but currently unpatched, CVE for exposure of sensitive information. The fact that this is the only known vulnerability type and it remains unpatched suggests a potential pattern of oversight in security hygiene, especially given its recency.
In conclusion, while the plugin demonstrates some good security practices, particularly in its handling of SQL and its limited attack surface, the partial output escaping and the unpatched low-severity CVE are significant weaknesses. The lack of nonce and capability checks, even if not directly exploitable in this reported static analysis, points to a need for more robust security implementations. Users should be cautious due to the unpatched vulnerability and the potential for XSS if the output escaping is insufficient for all dynamic content.
Key Concerns
- Unpatched CVE exists
- Output escaping is only 50% proper
- No nonce checks reported
- No capability checks reported
Site Info Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Site Info <= 1.1 - Authenticated (Editor+) Information Exposure
Site Info Code Analysis
Output Escaping
Site Info Attack Surface
WordPress Hooks 2
Maintenance & Trust
Site Info Maintenance & Trust
Maintenance Signals
Community Trust
Site Info Alternatives
Dashboard Welcome for Elementor
dashboard-welcome-for-elementor
Replaces the default WordPress dashboard welcome panel with custom designed Elementor template.
Error Log Monitor
error-log-monitor
Adds a Dashboard widget that displays the latest messages from your PHP error log. It can also send logged errors to email.
Widget Disable
wp-widget-disable
Disable sidebar and dashboard widgets with an easy to use interface.
Dashboard Welcome for Beaver Builder
dashboard-welcome-for-beaver-builder
Replaces the default WordPress dashboard welcome panel with custom designed Beaver Builder template.
Dashboard To-Do List
dashboard-to-do-list
A dashboard to-do list widget with the option to show the to-do list on the website. This is a great tool for web developers building a new website.
Site Info Developer Profile
4 plugins · 250 total installs
How We Detect Site Info
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
<table><tr><td><strong>Site Name :</strong></td><td>