
Watchtower Security & Risk Analysis
wordpress.org/plugins/watchtowerUptime and performance auditing, monitoring and alerting for WordPress.
Is Watchtower Safe to Use in 2026?
Generally Safe
Score 85/100Watchtower has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "watchtower" v0.2 plugin exhibits a generally good security posture with a very small attack surface. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits potential entry points for attackers. Furthermore, the code analysis reveals no dangerous functions or raw SQL queries, with all SQL operations utilizing prepared statements. The high percentage of properly escaped output is also a positive indicator.
However, there are areas of concern. The presence of two taint flows with unsanitized paths, despite the lack of critical or high severity, suggests potential weaknesses in how data is handled. While the plugin has no recorded vulnerabilities and a clean history, the lack of any capability checks or nonce checks on the identified entry points (even if they are currently zero) represents a potential future risk. If new entry points are introduced without these fundamental security measures, it could lead to vulnerabilities.
In conclusion, "watchtower" v0.2 is off to a promising start regarding security, particularly due to its minimal attack surface and good SQL practices. Nevertheless, the identified taint flows and the complete absence of capability and nonce checks warrant attention. Addressing these areas proactively will be crucial for maintaining a strong security posture as the plugin evolves.
Key Concerns
- Taint flow with unsanitized path
- Taint flow with unsanitized path
- No capability checks
- No nonce checks
- Output not properly escaped (13% of 167)
Watchtower Security Vulnerabilities
Watchtower Release Timeline
Watchtower Code Analysis
Output Escaping
Data Flow Analysis
Watchtower Attack Surface
WordPress Hooks 7
Maintenance & Trust
Watchtower Maintenance & Trust
Maintenance Signals
Community Trust
Watchtower Alternatives
Unifyca Audit Connector
unifyca-audit-connector
Audit, monitor and maintain WordPress websites. Optionally connect to Unifyca to manage multiple websites, documentation and maintenance from one dash …
SYSSY – Monitoring Websites
syssy
Connects your WordPress website with SYSSY for monitoring and security issue reporting. Requires account on https://www.syssy.net.
Pluginventory
pluginventory
Know exactly which plugins run across your WordPress portfolio — search any plugin instantly and catch problems before a site breaks.
Unstoppable Activity Tracker
unstoppable-activity-tracker
Standalone activity tracker. Records site events to a local database table and exposes them via a secure, API-key-protected REST endpoint.
Kovalenko Admin Change Audit
kovalenko-admin-change-audit
Records important WordPress activity and provides an owner-only log viewer for monitoring client changes.
Watchtower Developer Profile
2 plugins · 2K total installs
How We Detect Watchtower
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/watchtower/assets/js/src/connect.js/wp-content/plugins/watchtower/assets/js/dist/chart.min.js/wp-content/plugins/watchtower/assets/js/dist/index.js/wp-content/plugins/watchtower/assets/css/admin.cssassets/js/src/connect.jsassets/js/dist/chart.min.jsassets/js/dist/index.jswatchtower-admin-css?ver=0.2HTML / DOM Fingerprints
watchtowerContactstokenWindow