
Vibes Security & Risk Analysis
wordpress.org/plugins/vibesTruthful user experience and browsing performances monitoring.
Is Vibes Safe to Use in 2026?
Generally Safe
Score 98/100Vibes has a strong security track record. Known vulnerabilities have been patched promptly.
The 'vibes' plugin v2.3.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices in SQL query handling with 85% prepared statements and excellent output escaping at 92%. The absence of critical or high-severity taint flows, dangerous functions, and bundled libraries are also strengths. However, there are significant areas of concern. The attack surface includes 3 AJAX handlers, with 2 of them lacking authentication checks, presenting a direct risk for unauthorized execution of actions. Furthermore, the plugin has a documented history of a high-severity 'SQL Injection' vulnerability, even though it is currently patched. This historical pattern suggests a potential recurring weakness in how user-supplied data is handled in SQL queries, which requires ongoing vigilance.
Key Concerns
- Unprotected AJAX handlers
- High severity SQL Injection vulnerability history
Vibes Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Vibes <= 2.2.0 - Unauthenticated SQL Injection via `resource` Parameter
Vibes Code Analysis
SQL Query Safety
Output Escaping
Vibes Attack Surface
AJAX Handlers 3
Shortcodes 4
WordPress Hooks 39
Maintenance & Trust
Vibes Maintenance & Trust
Maintenance Signals
Community Trust
Vibes Alternatives
Real User Monitoring by RapidSpike
rapidspike-real-user-monitoring
Live performance data via Real User Monitoring. Track real user experience - traffic volume and page load speed - by country, browser and device.
Site24x7 Real User Monitoring
site24x7-rum
Real User Monitoring (RUM) by Site24x7 provides deep and accurate insight into real users’experience on your WordPress setup.
SpeedVitals RUM
speedvitals-rum
Integrates SpeedVitals RUM Script in your WordPress Website
Core Web Vitals – Real User Monitoring (RUM)
core-web-vitals-real-user-monitoring-rum
Track Core Web Vitals (LCP, INP, CLS, FCP, TTFB) from real users with comprehensive analytics, GA4 integration, and performance insights.
WP Fastest Cache – WordPress Cache Plugin
wp-fastest-cache
The simplest and fastest WP Cache system
Vibes Developer Profile
12 plugins · 15K total installs
How We Detect Vibes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/vibes/assets/css/vibes.css/wp-content/plugins/vibes/assets/js/vibes.js/wp-content/plugins/vibes/assets/css/vibes-admin.css/wp-content/plugins/vibes/assets/js/vibes-admin.js/wp-content/plugins/vibes/assets/css/vibes-admin-settings.css/wp-content/plugins/vibes/assets/js/vibes-admin-settings.js/wp-content/plugins/vibes/assets/css/vibes-admin-view.css/wp-content/plugins/vibes/assets/js/vibes-admin-view.js+10 more/wp-content/plugins/vibes/assets/js/vibes.js/wp-content/plugins/vibes/assets/js/vibes-admin.js/wp-content/plugins/vibes/assets/js/vibes-admin-settings.js/wp-content/plugins/vibes/assets/js/vibes-admin-view.js/wp-content/plugins/vibes/assets/js/vibes-frontend.js/wp-content/plugins/vibes/includes/libraries/daterangepicker/moment.min.js+4 morevibes/assets/css/vibes.css?ver=vibes/assets/js/vibes.js?ver=vibes/assets/css/vibes-admin.css?ver=vibes/assets/js/vibes-admin.js?ver=vibes/assets/css/vibes-admin-settings.css?ver=vibes/assets/js/vibes-admin-settings.js?ver=vibes/assets/css/vibes-admin-view.css?ver=vibes/assets/js/vibes-admin-view.js?ver=vibes/assets/css/vibes-frontend.css?ver=vibes/assets/js/vibes-frontend.js?ver=vibes-moment-with-localevibes-daterangepickervibes-chartistvibes-chartist-tooltipHTML / DOM Fingerprints
vibes-dashboardvibes-rowvibes-colvibes-cardvibes-card-headervibes-card-bodyvibes-tablevibes-table-responsive+5 moreProvide a admin-facing view for the pluginThis file is used to markup the admin-facing aspects of the plugin.data-featherlight-opendata-featherlight-closedata-featherlight-close-textVIBES_ASSETS_IDVIBES_PRODUCT_NAMEVIBES_VERSIONPERFOO_ALLOWED_HTML_FOR_DASHBOARDPERFOO_ALLOWED_PROTOCOLS_FOR_DASHBOARDvibes_object+5 more/wp-json/vibes/v1/analytics[vibes-libraries][vibes-changelog][vibes-wpcli]