
System information Security & Risk Analysis
wordpress.org/plugins/system-informationAdds a system information page that include all the details on your WordPress configuration.
Is System information Safe to Use in 2026?
Generally Safe
Score 85/100System information has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "system-information" plugin v1.0.1 exhibits a mixed security posture. On the positive side, it demonstrates strong adherence to secure coding practices by avoiding dangerous functions, utilizing prepared statements exclusively for SQL queries, and having no file operations or external HTTP requests. The lack of known CVEs in its history also suggests a potentially stable codebase.
However, significant concerns arise from the static analysis. The most critical finding is that 100% of outputs are not properly escaped. This presents a high risk of Cross-Site Scripting (XSS) vulnerabilities, as any user-controlled data that is outputted by the plugin could potentially be injected with malicious scripts. Additionally, the taint analysis reveals two flows with unsanitized paths, which, while not flagged as critical or high severity in this report, warrant investigation as they could lead to unexpected behavior or potential vulnerabilities if data is not handled correctly.
In conclusion, while the plugin has a clean vulnerability history and employs good practices in areas like SQL and file handling, the complete lack of output escaping is a critical flaw. This, combined with the presence of unsanitized paths, significantly elevates the risk associated with this plugin. The absence of nonces and capability checks on any entry points (though none were identified) also means that if any were introduced in future versions without proper checks, the plugin would be vulnerable.
Key Concerns
- 100% of outputs unescaped
- Unsanitized paths in taint analysis
- No nonce checks identified
- No capability checks identified
System information Security Vulnerabilities
System information Code Analysis
Output Escaping
Data Flow Analysis
System information Attack Surface
WordPress Hooks 1
Maintenance & Trust
System information Maintenance & Trust
Maintenance Signals
Community Trust
System information Alternatives
Phpinfo
phpinfo
Prints out your webservers php settings as well as other information about your WordPress installation.
Dev Info Bar
dev-info-bar
A simple WordPress extension which adds itself to the admin bar, providing system information such as PHP, MySQL version and details of the WordPress …
Admin Bar Queries
admin-bar-queries
MySQL queries and load details added to your admin bar.
Apermo Xdebug
apermo-xdebug
This plugin helps developers that use Xdebug.
Pretty Debug
pretty-debug
A WordPress plugin that makes var_dump and print_r pretty!
System information Developer Profile
9 plugins · 1K total installs
How We Detect System information
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
wrappoststuffui-sortablepostboxopenedreadonlyrowscolswrapstyleonfocus