WP Console – WordPress PHP Console powered by PsySH Security & Risk Analysis

wordpress.org/plugins/wp-console

An in-browser PHP console for WordPress powered by PsySH

20K active installs v2.6.0 PHP 7.4+ WP 5.3.12+ Updated Nov 8, 2025
autocompletebrowserdumpreplshell
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Console – WordPress PHP Console powered by PsySH Safe to Use in 2026?

Generally Safe

Score 100/100

WP Console – WordPress PHP Console powered by PsySH has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The 'wp-console' v2.6.0 plugin exhibits a strong security posture based on the provided static analysis. It demonstrates excellent adherence to secure coding practices by avoiding dangerous functions, utilizing prepared statements for all SQL queries, and properly escaping all output. The absence of any identified taint flows with unsanitized paths further reinforces this positive assessment, indicating no critical or high-severity data flow vulnerabilities were detected.

While the plugin has a clean vulnerability history with zero recorded CVEs, this can be both a strength and a potential area for caution. It suggests a well-maintained codebase with a proactive approach to security. However, the lack of historical data also means there's less empirical evidence of its long-term resilience against sophisticated attacks. The presence of file operations, though not explicitly flagged as problematic, warrants a minor consideration due to their potential to introduce vulnerabilities if not handled with extreme care, especially in conjunction with user-supplied input (which the taint analysis did not detect any issues with). The lack of any attack surface points (AJAX, REST API, shortcodes, cron) is a significant security advantage, as it minimizes potential entry points for malicious actors.

In conclusion, 'wp-console' v2.6.0 appears to be a secure plugin, characterized by robust coding practices, no detected critical vulnerabilities in static analysis or taint flows, and a clean historical record. The minor concern regarding file operations is mitigated by the absence of other identified risks. The plugin's strengths heavily outweigh its weaknesses, making it a low-risk option.

Key Concerns

  • File operations detected
Vulnerabilities
None known

WP Console – WordPress PHP Console powered by PsySH Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP Console – WordPress PHP Console powered by PsySH Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
5
File Operations
3
External Requests
0
Bundled Libraries
0
Attack Surface

WP Console – WordPress PHP Console powered by PsySH Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 18
actionadmin_bar_menuincludes\AdminBar.php:19
actionadmin_menuincludes\AdminBar.php:20
actionwp_after_admin_bar_renderincludes\AdminBar.php:22
filterwp_console_rest_controllersincludes\Core\Console\Console.php:15
filterwp_console_user_settings_schemaincludes\Core\Console\Console.php:16
filterwp_console_rest_controllersincludes\Core\DebugLog\DebugLog.php:15
filterwp_console_controllersincludes\Core\UserSettings\UserSettings.php:15
filterwp_console_rest_controllersincludes\Core\UserSettings\UserSettings.php:16
filterbody_classincludes\Hooks.php:15
filteradmin_body_classincludes\Hooks.php:16
actioninitincludes\Scripts.php:19
actioninitincludes\Scripts.php:20
actionadmin_enqueue_scriptsincludes\Scripts.php:21
actionwp_enqueue_scriptsincludes\Scripts.php:22
actionadmin_noticesincludes\WPConsole.php:74
actionplugins_loadedincludes\WPConsole.php:78
actioninitincludes\WPConsole.php:150
actionrest_api_initincludes\WPConsole.php:151
Maintenance & Trust

WP Console – WordPress PHP Console powered by PsySH Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedNov 8, 2025
PHP min version7.4
Downloads1.9M

Community Trust

Rating100/100
Number of ratings20
Active installs20K
Developer Profile

WP Console – WordPress PHP Console powered by PsySH Developer Profile

Edi Amin

2 plugins · 20K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP Console – WordPress PHP Console powered by PsySH

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-console/assets/css/wp-console.css
Script Paths
/wp-content/plugins/wp-console/assets/js/wp-console.js/wp-content/plugins/wp-console/assets/vendor/ace-builds/src-min-noconflict/ace.js/wp-content/plugins/wp-console/assets/vendor/ace-builds/src-min-noconflict/ext-language_tools.js
Version Parameters
wp-console.asset.phpwp-console.asset.phpwp-console.css?ver=wp-console.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-wp-console-nonce
JS Globals
wpConsole
REST Endpoints
/wp-json/wp-console/v1/console
FAQ

Frequently Asked Questions about WP Console – WordPress PHP Console powered by PsySH