
SQLog Security & Risk Analysis
wordpress.org/plugins/sqlogLog WordPress MySQL queries in csv file (and log file). Useful when you need to improve the performance or debug something.
Is SQLog Safe to Use in 2026?
Generally Safe
Score 85/100SQLog has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The sqlog plugin v1.0.0 demonstrates a generally good security posture based on the provided static analysis. The complete absence of AJAX handlers, REST API routes, and shortcodes, combined with the fact that all entry points are protected by authentication checks, significantly reduces the attack surface. Furthermore, the plugin exclusively uses prepared statements for SQL queries and incorporates nonce and capability checks, which are strong indicators of secure coding practices. The lack of any recorded vulnerabilities, including CVEs and common vulnerability types, further supports this positive assessment. However, a notable area for improvement lies in output escaping, where only 51% of outputs are properly escaped, leaving nearly half potentially vulnerable to cross-site scripting (XSS) attacks. While taint analysis shows no current exploitable flows, this unescaped output represents a latent risk that should be addressed.
Despite the strong foundation in protecting its limited attack surface and database interactions, the significant portion of unescaped output represents the primary security concern. The plugin's history of zero vulnerabilities is a positive signal, suggesting diligent development or a lack of historical exposure. The overall security of sqlog v1.0.0 is good, with its strengths in authentication and SQL handling outweighing its weaknesses. However, addressing the output escaping is crucial to achieving a robust security profile and mitigating potential XSS vulnerabilities.
Key Concerns
- Poor output escaping
SQLog Security Vulnerabilities
SQLog Code Analysis
Output Escaping
SQLog Attack Surface
WordPress Hooks 19
Scheduled Events 1
Maintenance & Trust
SQLog Maintenance & Trust
Maintenance Signals
Community Trust
SQLog Alternatives
SQL Executioner
sql-executioner
Execute arbitrary SQL queries against your WordPress database from the Admin.
myRepono WordPress Backup Plugin
myrepono-wordpress-backup-plugin
Automate your WordPress, website & database backups using the myRepono remote website backup service.
info
info
Plugin shows in the admin bar the number of SQL queries, the amount of time in seconds and memory load.
DbTable to DataTable
dbtable-to-datatable
Display mysql datas into datatable.
Admin Bar Queries
admin-bar-queries
MySQL queries and load details added to your admin bar.
SQLog Developer Profile
4 plugins · 180 total installs
How We Detect SQLog
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sqlog/assets/css/sqlog-admin.css/wp-content/plugins/sqlog/assets/js/sqlog-admin.js/wp-content/plugins/sqlog/assets/css/sqlog-public.css/wp-content/plugins/sqlog/assets/js/sqlog-public.js/wp-content/plugins/sqlog/assets/js/sqlog-admin.js/wp-content/plugins/sqlog/assets/js/sqlog-public.jssqlog/assets/css/sqlog-admin.css?ver=sqlog/assets/js/sqlog-admin.js?ver=sqlog/assets/css/sqlog-public.css?ver=sqlog/assets/js/sqlog-public.js?ver=HTML / DOM Fingerprints
sqlog-admin-wrappersqlog-public-wrapper<!-- BEGIN SQLog --><!-- END SQLog -->data-sqlog-urldata-sqlog-targetsqlog_admin_paramssqlog_public_params/wp-json/sqlog/v1/logs[sqlog_display_logs]