
SiteSignal Security & Risk Analysis
wordpress.org/plugins/sitesignalSiteSignal WordPress connector for AI visibility, website health, performance monitoring, and technical audits.
Is SiteSignal Safe to Use in 2026?
Generally Safe
Score 100/100SiteSignal has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'sitesignal' plugin, version 1.0.0, exhibits a generally good security posture based on the provided static analysis. The plugin boasts a zero-day vulnerability history and has implemented robust protections for its identified entry points, with no unprotected AJAX handlers or REST API routes found. The use of prepared statements for SQL queries is reasonably high at 65%, and a significant majority of output is properly escaped (74%). However, there are areas of concern that warrant attention. The presence of one taint flow with an unsanitized path, identified as high severity, is a critical finding that suggests a potential vulnerability for code injection or other harmful operations. Additionally, while the plugin has a low percentage of SQL queries without prepared statements, the sheer volume of queries (78) means that the remaining 35% could still represent a significant risk if not properly handled. The number of external HTTP requests (6) also introduces a minor risk as it expands the plugin's attack surface to external services, though the analysis does not indicate any immediate issues with these.
Overall, 'sitesignal' v1.0.0 demonstrates good security practices by securing its direct entry points and implementing output escaping. The lack of known vulnerabilities is a positive indicator. Nevertheless, the high-severity taint flow with an unsanitized path is a significant weakness that needs immediate investigation and remediation. The moderate use of prepared statements for SQL queries, while not a critical flaw given the other security measures, could be improved to further harden the plugin against SQL injection. Without further information on the nature of the taint flow, it's difficult to assign a precise risk level beyond what the analysis indicates, but it represents the most pressing concern.
Key Concerns
- High severity taint flow with unsanitized path
- SQL queries not using prepared statements
- Output escaping not fully implemented
SiteSignal Security Vulnerabilities
SiteSignal Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
SiteSignal Attack Surface
REST API Routes 12
WordPress Hooks 19
Scheduled Events 1
Maintenance & Trust
SiteSignal Maintenance & Trust
Maintenance Signals
Community Trust
SiteSignal Alternatives
DreamCore Monitor
dreamcore-monitor
WordPress monitoring solution that tracks login attempts, core status, plugin updates, theme status, and file integrity.
Loginizer
loginizer
Loginizer is a WordPress security plugin which helps you fight against bruteforce attacks.
WP Ghost (Hide My WP Ghost) – Security & Firewall
hide-my-wp
Hide and Secure WP paths, wp-login, wp-admin, and more. Hack Prevention, Security, Brute Force protection, 8G Firewall, 2FA Passkey Login, and more.
Unauthorised Login Redirect
unauthorised-login-redirect
This plugin allows you to effectively hide your wp-login.php and wp-admin by requiring that you access it via a custom URL.
Protector – Login Security & Hide Admin URL
wp-admin-protect
Protect your WP Admin access. Easily change your wp-login URL by adding a secret term to hide your login page from bots and unwanted visitors.
SiteSignal Developer Profile
1 plugin · 10 total installs
How We Detect SiteSignal
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sitesignal/admin/css/dreamcore-monitor-admin.cssdreamcore-monitor-admin.css?ver=HTML / DOM Fingerprints
integrity-statsstat-itemstat-item.not-modifiedstat-item.modifiedstat-item.missingstat-numberstat-labeldreamcore-monitor-notice+10 moredata-sitesignal-noncesitesignal_ajax_object/wp-json/sitesignal/v1/logins/wp-json/sitesignal/v1/core-status/wp-json/sitesignal/v1/plugin-updates/wp-json/sitesignal/v1/theme-status/wp-json/sitesignal/v1/file-integrity/wp-json/sitesignal/v1/woocommerce-orders