SitePulse – See What’s Powering (or Slowing) Your Site Security & Risk Analysis

wordpress.org/plugins/sitepulse

See what's happening under your WordPress site: real-time performance insights, detect slow plugins/hooks, and keep your site fast and stable.

100 active installs v1.3.5 PHP 7.4+ WP 5.5+ Updated Mar 4, 2026
monitoringoptimizationperformanceprofilerspeed
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is SitePulse – See What’s Powering (or Slowing) Your Site Safe to Use in 2026?

Generally Safe

Score 100/100

SitePulse – See What’s Powering (or Slowing) Your Site has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

Based on the static analysis and vulnerability history, the "sitepulse" v1.3.5 plugin exhibits a generally strong security posture. The absence of any detected CVEs and the low number of common vulnerability types in its history suggest a well-maintained and secure plugin. The code analysis shows a commendable adherence to best practices, with a significant percentage of SQL queries utilizing prepared statements and a good number of nonce and capability checks in place. This indicates a proactive approach to mitigating common WordPress vulnerabilities.

However, there are areas that warrant attention. The output escaping is only 52% proper, which is a significant concern. This means a substantial portion of the plugin's output is not being sanitized, potentially opening it up to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is outputted directly without proper escaping. While the attack surface appears to be zero, this is often a result of the analysis tool's limitations or the specific nature of the plugin's functionality. The taint analysis showing zero flows with unsanitized paths is positive, but should be interpreted in conjunction with the output escaping metric. The presence of file operations and external HTTP requests also introduces potential vectors that, without robust sanitization and validation, could be exploited.

In conclusion, "sitepulse" v1.3.5 demonstrates strengths in its SQL handling and authentication checks. The lack of historical vulnerabilities is a major positive. Nevertheless, the low percentage of properly escaped output represents a notable weakness that attackers could target. The plugin's overall security is good, but the output escaping issue needs to be addressed to achieve a truly robust security profile.

Key Concerns

  • Output escaping is only 52% proper
Vulnerabilities
None known

SitePulse – See What’s Powering (or Slowing) Your Site Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

SitePulse – See What’s Powering (or Slowing) Your Site Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
6 prepared
Unescaped Output
544
586 escaped
Nonce Checks
17
Capability Checks
15
File Operations
5
External Requests
3
Bundled Libraries
0

SQL Query Safety

86% prepared7 total queries

Output Escaping

52% escaped1130 total outputs
Attack Surface

SitePulse – See What’s Powering (or Slowing) Your Site Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 48
actionadmin_enqueue_scriptsclass\backend.php:20
filteradmin_body_classclass\backend.php:21
actionadmin_menuclass\backend.php:24
actionadmin_initclass\backend.php:27
actioncurrent_screenclass\backend.php:29
filterall_pluginsclass\backend.php:32
filterhttp_request_argsclass\curloader.php:22
actionhttp_api_debugclass\curloader.php:24
filterhttp_request_timeoutclass\curloader.php:27
filterhttp_request_argsclass\curloader.php:28
filterwp_fatal_error_handler_enabledclass\error_handler.php:106
filterwp_fatal_error_handler_emailclass\error_handler.php:109
filterwp_mailclass\error_handler.php:113
actioninitclass\error_handler.php:120
actionwp_enqueue_scriptsclass\frontend.php:15
actionadmin_bar_menuclass\frontend.php:18
actionwp_footerclass\frontend.php:21
actionadmin_initclass\onboarding.php:36
actionadmin_menuclass\onboarding.php:37
actionadmin_enqueue_scriptsclass\onboarding.php:38
filteradmin_body_classclass\onboarding.php:39
filteradmin_titleclass\onboarding.php:40
actionload-admin_page_wpsp_sitepulse_onboardingclass\onboarding.php:42
actioninitclass\plugin.php:11
actionwp_enqueue_scriptsclass\plugin.php:14
actionadmin_enqueue_scriptsclass\plugin.php:15
actionplugins_loadedclass\plugin_profiler.php:190
actionshutdownclass\plugin_profiler.php:193
actionactivated_pluginclass\plugin_profiler.php:196
actionplugins_loadedclass\profiler.php:25
actionafter_setup_themeclass\profiler.php:28
actionshutdownclass\profiler.php:31
actioninitclass\settings.php:37
filterwp_mailclass\settings.php:221
filterwp_mail_smtp_get_mailerclass\settings.php:225
filterwp_mail_smtp_providers_smtp_get_optionsclass\settings.php:226
filterwp_mailclass\settings.php:230
filterwp_mail_smtp_get_mailerclass\settings.php:231
filterwp_mail_smtp_providers_smtp_get_optionsclass\settings.php:232
filtercron_requestclass\settings.php:247
filtercron_schedulesinc\ai_diagnostic_cron.php:39
actioninitinc\ai_diagnostic_cron.php:45
filterrest_pre_dispatchinc\api_backend.php:44
actionrest_api_initinc\api_backend.php:93
actionshutdowninc\api_backend.php:338
actioninitloader.php:134
actionadmin_noticesloader.php:155
actionadmin_noticesloader.php:157
Maintenance & Trust

SitePulse – See What’s Powering (or Slowing) Your Site Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 4, 2026
PHP min version7.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

SitePulse – See What’s Powering (or Slowing) Your Site Developer Profile

Nilbug

1 plugin · 100 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect SitePulse – See What’s Powering (or Slowing) Your Site

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sitepulse/assets/js//wp-content/plugins/sitepulse/assets/css//wp-content/plugins/sitepulse/inc/vendors/
Generator Patterns
SitePulse
Script Paths
sitepulse/assets/js/sitepulse-tracking.jssitepulse/assets/js/sitepulse-frontend.js
Version Parameters
sitepulse/assets/css/sitepulse-tracking.css?ver=sitepulse/assets/css/sitepulse-frontend.css?ver=sitepulse/assets/js/sitepulse-tracking.js?ver=sitepulse/assets/js/sitepulse-frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
sitepulse-admin-notice
HTML Comments
<!-- SitePulse PRO -->
Data Attributes
data-sitepulse-widget-iddata-sitepulse-performance-data
JS Globals
sitepulseDatasitepulseFrontend
REST Endpoints
/wp-json/sitepulse/v1/metrics/wp-json/sitepulse/v1/settings
Shortcode Output
[sitepulse_dashboard]
FAQ

Frequently Asked Questions about SitePulse – See What’s Powering (or Slowing) Your Site