Support Monitor – WordPress Support Monitor Plugin Security & Risk Analysis

wordpress.org/plugins/support-monitor

A Simple Support Monitoring Tool for WordPress.

0 active installs v1.0.3 PHP 5.4+ WP 4.0+ Updated Unknown
support-monitorunresolved-issueswordpress-support-monitor
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Support Monitor – WordPress Support Monitor Plugin Safe to Use in 2026?

Generally Safe

Score 100/100

Support Monitor – WordPress Support Monitor Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "support-monitor" plugin version 1.0.3 demonstrates a generally positive security posture based on the provided static analysis. The absence of any known vulnerabilities in its history is a strong indicator of good development practices and diligent maintenance. Furthermore, the plugin effectively utilizes output escaping and capability checks, which are crucial for preventing common web vulnerabilities. The limited attack surface, consisting of a single shortcode with no unprotected entry points, also contributes to its security.

However, there are areas for improvement. The most significant concern is the use of raw SQL queries without prepared statements. This practice, seen in 4 out of 4 queries, introduces a substantial risk of SQL injection vulnerabilities, especially if any of the data involved in these queries originates from user input. The lack of nonce checks on its single entry point, while not directly exploitable without other factors, is a missed opportunity for enhanced security against CSRF attacks. While no critical taint flows were identified, the raw SQL queries represent a potential pathway for such issues to emerge if not addressed.

In conclusion, the "support-monitor" plugin is built on a solid foundation with no known historical exploits and good practices in output sanitization and authorization. Its strengths lie in its minimal attack surface and effective use of capability checks. The primary weakness lies in its handling of database interactions, specifically the reliance on un-prepared SQL statements, which presents a tangible risk that should be prioritized for remediation.

Key Concerns

  • Raw SQL queries without prepared statements
  • Missing nonce checks on entry points
Vulnerabilities
None known

Support Monitor – WordPress Support Monitor Plugin Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Support Monitor – WordPress Support Monitor Plugin Code Analysis

Dangerous Functions
0
Raw SQL Queries
4
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

0% prepared4 total queries
Attack Surface

Support Monitor – WordPress Support Monitor Plugin Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[vue-app] includes\Frontend.php:10
WordPress Hooks 8
actionadmin_menuincludes\Admin.php:10
actionadmin_enqueue_scriptsincludes\Admin.php:38
actionrest_api_initincludes\Api.php:19
actionadmin_enqueue_scriptsincludes\Assets.php:12
actionwp_enqueue_scriptsincludes\Assets.php:14
actionplugins_loadedplugin.php:82
actioninitplugin.php:205
actioninitplugin.php:208
Maintenance & Trust

Support Monitor – WordPress Support Monitor Plugin Maintenance & Trust

Maintenance Signals

WordPress version tested5.9.13
Last updatedUnknown
PHP min version5.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Alternatives

Support Monitor – WordPress Support Monitor Plugin Alternatives

No alternatives data available yet.

Developer Profile

Support Monitor – WordPress Support Monitor Plugin Developer Profile

Emtiaz Zahid

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Support Monitor – WordPress Support Monitor Plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/support-monitor/assets/css/style.css/wp-content/plugins/support-monitor/assets/js/backend.js
Script Paths
/wp-content/plugins/support-monitor/assets/js/backend.js
Version Parameters
support-monitor/assets/css/style.css?ver=support-monitor/assets/js/backend.js?ver=

HTML / DOM Fingerprints

JS Globals
SupportMonitor
REST Endpoints
/wp-json/supportmonitor/v1/get-plugins
FAQ

Frequently Asked Questions about Support Monitor – WordPress Support Monitor Plugin