
SQL Executioner Security & Risk Analysis
wordpress.org/plugins/sql-executionerExecute arbitrary SQL queries against your WordPress database from the Admin.
Is SQL Executioner Safe to Use in 2026?
Generally Safe
Score 85/100SQL Executioner has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'sql-executioner' v1.4 presents a generally positive security posture based on the static analysis. The complete absence of identified AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. Furthermore, the code analysis indicates a strong adherence to secure coding practices, with all SQL queries utilizing prepared statements and a high percentage of output correctly escaped. The presence of a nonce check and file operation handling, while not inherently concerning, warrant careful review of their implementation if they were to be used in conjunction with an expanded attack surface.
The vulnerability history is remarkably clean, with no known CVEs recorded. This, combined with the clean taint analysis, suggests a well-developed and secure plugin. However, the complete lack of capability checks is a notable weakness. While the current attack surface is zero, if any future functionality is added, the absence of proper authorization checks could become a critical security flaw. The single file operation, though not indicative of a problem on its own, is an area that would require scrutiny in a deeper audit to ensure it's not susceptible to path traversal or other file manipulation vulnerabilities. Overall, the plugin appears secure due to its limited functionality and good coding practices, but the lack of capability checks is a potential future risk if the plugin evolves.
Key Concerns
- Missing capability checks
SQL Executioner Security Vulnerabilities
SQL Executioner Code Analysis
Output Escaping
SQL Executioner Attack Surface
WordPress Hooks 2
Maintenance & Trust
SQL Executioner Maintenance & Trust
Maintenance Signals
Community Trust
SQL Executioner Alternatives
WP phpMyAdmin
wp-phpmyadmin-extension
[ ✅ 𝐒𝐄𝐂𝐔𝐑𝐄 𝐏𝐋𝐔𝐆𝐈𝐍𝐒 𝐵𝓎 𝒫𝓊𝓋𝑜𝓍 ] phpMyAdmin - Database Browser & Manager (for MySQL & MariaDB)
DbTable to DataTable
dbtable-to-datatable
Display mysql datas into datatable.
SM – SQL logs
sm-sql-logs
Record and view all SQL queries that your WordPress is requesting. Browse formated and highlighted syntax queries for debug and speedup your site.
SQLog
sqlog
Log WordPress MySQL queries in csv file (and log file). Useful when you need to improve the performance or debug something.
Database Backup for WordPress
wp-db-backup
Database Backup for WordPress is your one-stop database backup solution for WordPress.
SQL Executioner Developer Profile
3 plugins · 2K total installs
How We Detect SQL Executioner
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sql-executioner/style.css/wp-content/plugins/sql-executioner/script.js/wp-content/plugins/sql-executioner/script.jssql-executioner/style.css?ver=sql-executioner/script.js?ver=