
Health and Server Condition – Integrated with Google Page Speed Security & Risk Analysis
wordpress.org/plugins/wp-conditionDisplay Health and Server Condition in Charts and Table for Google Page Speed, Database Performance, Memory Usage, Peak Memory Usage, Page load time & …
Is Health and Server Condition – Integrated with Google Page Speed Safe to Use in 2026?
Mostly Safe
Score 78/100Health and Server Condition – Integrated with Google Page Speed is generally safe to use. 1 past CVE were resolved. Keep it updated.
The wp-condition v4.1.1 plugin presents a mixed security posture. While it demonstrates good practices in handling SQL queries with prepared statements and includes a nonce check, significant concerns arise from its attack surface and output sanitization. The presence of an unprotected AJAX handler is a critical entry point that could be exploited if not properly secured. Furthermore, only 10% of outputs are properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities, which aligns with its vulnerability history. The plugin has a known medium-severity CVE related to XSS that is currently unpatched, and the timestamp of the last vulnerability (2025-04-10) suggests it's either a future vulnerability or a typo in the data provided, but the presence of an unpatched vulnerability is a serious issue. Despite the use of prepared statements and a nonce check, the combination of an unprotected AJAX endpoint and poor output escaping, coupled with an unpatched XSS vulnerability, elevates the risk considerably. This plugin requires immediate attention to address the XSS flaw and secure the AJAX handler.
Key Concerns
- Unprotected AJAX handler
- Low output escaping percentage
- Unpatched CVE (medium severity)
Health and Server Condition – Integrated with Google Page Speed Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WordPress Health and Server Condition – Integrated with Google Page Speed <= 4.1.1 - Reflected Cross-Site Scripting
Health and Server Condition – Integrated with Google Page Speed Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Health and Server Condition – Integrated with Google Page Speed Attack Surface
AJAX Handlers 1
WordPress Hooks 8
Maintenance & Trust
Health and Server Condition – Integrated with Google Page Speed Maintenance & Trust
Maintenance Signals
Community Trust
Health and Server Condition – Integrated with Google Page Speed Alternatives
Page Speed Insights
itman-page-speed-insights
Displays and measures page performance according to the Google PageSpeed Insights.
Widget Speed Test for Elementor
widget-speed-test-for-elementor
Identify Elementor widgets that are slowing down page rendering and load times.
Complianz – Terms and Conditions
complianz-terms-conditions
Configure your own Terms and Conditions specific to your service or webshop.
iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more
iubenda-cookie-law-solution
The solution for GDPR compliance + more. Get your cookie banner, privacy policy, terms and conditions and handle cookie consent in just one plugin.
Performance Lab
performance-lab
Performance plugin from the WordPress Performance Team, which is a collection of standalone performance features.
Health and Server Condition – Integrated with Google Page Speed Developer Profile
6 plugins · 690 total installs
How We Detect Health and Server Condition – Integrated with Google Page Speed
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-condition/style.css/wp-content/plugins/wp-condition/Chart.min.jswp-condition/style.css?ver=wp-condition/Chart.min.js?ver=HTML / DOM Fingerprints
wpfixit_con<!-- The loader div --><!-- The div where the AJAX response will be displayed -->id="wpfixit_con"id="loader"id="content"name="wp_conditions_settings[wpcond_googleapis_key]"ajaxurl/wp-json/wpfixit_con_analysis