Health and Server Condition – Integrated with Google Page Speed Security & Risk Analysis

wordpress.org/plugins/wp-condition

Display Health and Server Condition in Charts and Table for Google Page Speed, Database Performance, Memory Usage, Peak Memory Usage, Page load time & …

20 active installs v4.1.1 PHP + WP 5.0+ Updated Dec 17, 2025
conditiongoogle-page-speedpage-speedquerysite-health
78
B · Generally Safe
CVEs total1
Unpatched1
Last CVEApr 10, 2025
Safety Verdict

Is Health and Server Condition – Integrated with Google Page Speed Safe to Use in 2026?

Mostly Safe

Score 78/100

Health and Server Condition – Integrated with Google Page Speed is generally safe to use. 1 past CVE were resolved. Keep it updated.

1 known CVE 1 unpatched Last CVE: Apr 10, 2025Updated 3mo ago
Risk Assessment

The wp-condition v4.1.1 plugin presents a mixed security posture. While it demonstrates good practices in handling SQL queries with prepared statements and includes a nonce check, significant concerns arise from its attack surface and output sanitization. The presence of an unprotected AJAX handler is a critical entry point that could be exploited if not properly secured. Furthermore, only 10% of outputs are properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities, which aligns with its vulnerability history. The plugin has a known medium-severity CVE related to XSS that is currently unpatched, and the timestamp of the last vulnerability (2025-04-10) suggests it's either a future vulnerability or a typo in the data provided, but the presence of an unpatched vulnerability is a serious issue. Despite the use of prepared statements and a nonce check, the combination of an unprotected AJAX endpoint and poor output escaping, coupled with an unpatched XSS vulnerability, elevates the risk considerably. This plugin requires immediate attention to address the XSS flaw and secure the AJAX handler.

Key Concerns

  • Unprotected AJAX handler
  • Low output escaping percentage
  • Unpatched CVE (medium severity)
Vulnerabilities
1

Health and Server Condition – Integrated with Google Page Speed Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-32520medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

WordPress Health and Server Condition – Integrated with Google Page Speed <= 4.1.1 - Reflected Cross-Site Scripting

Apr 10, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Health and Server Condition – Integrated with Google Page Speed Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
138
16 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

10% escaped154 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

3 flows1 with unsanitized paths
display (includes\class.WP_Page_Condition_Stats.php:130)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Health and Server Condition – Integrated with Google Page Speed Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_wpfixit_con_analysisincludes\class.WP_Page_Condition_Stats.php:27
WordPress Hooks 8
actioninitincludes\class.WP_Page_Condition_Stats.php:13
actionwp_headincludes\class.WP_Page_Condition_Stats.php:16
actionwp_footerincludes\class.WP_Page_Condition_Stats.php:17
actionadmin_headincludes\class.WP_Page_Condition_Stats.php:20
actionadmin_footerincludes\class.WP_Page_Condition_Stats.php:21
actionadmin_menuincludes\class.WP_Page_Condition_Stats.php:22
actionadmin_enqueue_scriptsincludes\class.WP_Page_Condition_Stats.php:25
actionwp_enqueue_scriptsincludes\class.WP_Page_Condition_Stats.php:26
Maintenance & Trust

Health and Server Condition – Integrated with Google Page Speed Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 17, 2025
PHP min version
Downloads3K

Community Trust

Rating80/100
Number of ratings4
Active installs20
Developer Profile

Health and Server Condition – Integrated with Google Page Speed Developer Profile

M. Ali Saleem

6 plugins · 690 total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Health and Server Condition – Integrated with Google Page Speed

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-condition/style.css/wp-content/plugins/wp-condition/Chart.min.js
Version Parameters
wp-condition/style.css?ver=wp-condition/Chart.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
wpfixit_con
HTML Comments
<!-- The loader div --><!-- The div where the AJAX response will be displayed -->
Data Attributes
id="wpfixit_con"id="loader"id="content"name="wp_conditions_settings[wpcond_googleapis_key]"
JS Globals
ajaxurl
REST Endpoints
/wp-json/wpfixit_con_analysis
FAQ

Frequently Asked Questions about Health and Server Condition – Integrated with Google Page Speed