
Support Monitor – WordPress Support Monitor Plugin Security & Risk Analysis
wordpress.org/plugins/support-monitorA Simple Support Monitoring Tool for WordPress.
Is Support Monitor – WordPress Support Monitor Plugin Safe to Use in 2026?
Generally Safe
Score 100/100Support Monitor – WordPress Support Monitor Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "support-monitor" plugin version 1.0.3 demonstrates a generally positive security posture based on the provided static analysis. The absence of any known vulnerabilities in its history is a strong indicator of good development practices and diligent maintenance. Furthermore, the plugin effectively utilizes output escaping and capability checks, which are crucial for preventing common web vulnerabilities. The limited attack surface, consisting of a single shortcode with no unprotected entry points, also contributes to its security.
However, there are areas for improvement. The most significant concern is the use of raw SQL queries without prepared statements. This practice, seen in 4 out of 4 queries, introduces a substantial risk of SQL injection vulnerabilities, especially if any of the data involved in these queries originates from user input. The lack of nonce checks on its single entry point, while not directly exploitable without other factors, is a missed opportunity for enhanced security against CSRF attacks. While no critical taint flows were identified, the raw SQL queries represent a potential pathway for such issues to emerge if not addressed.
In conclusion, the "support-monitor" plugin is built on a solid foundation with no known historical exploits and good practices in output sanitization and authorization. Its strengths lie in its minimal attack surface and effective use of capability checks. The primary weakness lies in its handling of database interactions, specifically the reliance on un-prepared SQL statements, which presents a tangible risk that should be prioritized for remediation.
Key Concerns
- Raw SQL queries without prepared statements
- Missing nonce checks on entry points
Support Monitor – WordPress Support Monitor Plugin Security Vulnerabilities
Support Monitor – WordPress Support Monitor Plugin Code Analysis
SQL Query Safety
Support Monitor – WordPress Support Monitor Plugin Attack Surface
Shortcodes 1
WordPress Hooks 8
Maintenance & Trust
Support Monitor – WordPress Support Monitor Plugin Maintenance & Trust
Maintenance Signals
Community Trust
Support Monitor – WordPress Support Monitor Plugin Alternatives
No alternatives data available yet.
Support Monitor – WordPress Support Monitor Plugin Developer Profile
1 plugin · 0 total installs
How We Detect Support Monitor – WordPress Support Monitor Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/support-monitor/assets/css/style.css/wp-content/plugins/support-monitor/assets/js/backend.js/wp-content/plugins/support-monitor/assets/js/backend.jssupport-monitor/assets/css/style.css?ver=support-monitor/assets/js/backend.js?ver=HTML / DOM Fingerprints
SupportMonitor/wp-json/supportmonitor/v1/get-plugins