
Watchlog RUM Security & Risk Analysis
wordpress.org/plugins/watchlog-rumReal User Monitoring (RUM) for WordPress powered by Watchlog.
Is Watchlog RUM Safe to Use in 2026?
Generally Safe
Score 100/100Watchlog RUM has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "watchlog-rum" v0.2.0 plugin exhibits a strong security posture based on the static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. Furthermore, the code demonstrates good practices with 100% of SQL queries utilizing prepared statements and a high percentage (95%) of outputs being properly escaped. The single capability check also indicates an awareness of access control.
However, a notable concern arises from the complete lack of nonce checks. While the plugin has a very small attack surface and the available capability checks mitigate some risk, the absence of nonces on any potential (though currently zero) entry points leaves it vulnerable to Cross-Site Request Forgery (CSRF) attacks if new entry points are added in future versions without corresponding security measures. The taint analysis showing zero flows is positive, but this is likely due to the plugin's limited functionality and lack of user-supplied input processing, which could change.
The plugin's vulnerability history is clean, with no recorded CVEs. This, combined with the positive static analysis results, suggests the developers are either new or have a strong focus on security. The lack of historical vulnerabilities is a positive indicator, but the absence of nonce checks remains a concerning oversight that should be addressed to ensure robust security.
Key Concerns
- Missing nonce checks
Watchlog RUM Security Vulnerabilities
Watchlog RUM Code Analysis
Output Escaping
Watchlog RUM Attack Surface
WordPress Hooks 4
Maintenance & Trust
Watchlog RUM Maintenance & Trust
Maintenance Signals
Community Trust
Watchlog RUM Alternatives
SpeedVitals RUM
speedvitals-rum
Integrates SpeedVitals RUM Script in your WordPress Website
Vibes
vibes
Truthful user experience and browsing performances monitoring.
Site24x7 Real User Monitoring
site24x7-rum
Real User Monitoring (RUM) by Site24x7 provides deep and accurate insight into real users’experience on your WordPress setup.
Core Web Vitals – Real User Monitoring (RUM)
core-web-vitals-real-user-monitoring-rum
Track Core Web Vitals (LCP, INP, CLS, FCP, TTFB) from real users with comprehensive analytics, GA4 integration, and performance insights.
LinkRivers Site Monitor
linkrivers-site-monitor
Professional website monitoring for local businesses. Track uptime, SSL, page speed, SEO health, and Real User Monitoring.
Watchlog RUM Developer Profile
1 plugin · 0 total installs
How We Detect Watchlog RUM
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/watchlog-rum/includes/js/dist/bundle.js/wp-content/plugins/watchlog-rum/includes/js/dist/watchlog-rum-script.js/wp-content/plugins/watchlog-rum/includes/js/dist/bundle.js/wp-content/plugins/watchlog-rum/includes/js/dist/watchlog-rum-script.jswatchlog-rum/includes/js/dist/bundle.js?ver=watchlog-rum/includes/js/dist/watchlog-rum-script.js?ver=HTML / DOM Fingerprints
window.watchlogRumConfig