
WP Healthcheck Security & Risk Analysis
wordpress.org/plugins/wp-healthcheckWP Healthcheck is a plugin to check the health of your WordPress install.
Is WP Healthcheck Safe to Use in 2026?
Generally Safe
Score 92/100WP Healthcheck has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-healthcheck plugin v1.4.0 exhibits a generally strong security posture with no recorded vulnerabilities or critical taint flows. The absence of known CVEs and the presence of nonce and capability checks suggest good development practices for entry points. However, the static analysis reveals some areas of concern that warrant attention. Specifically, the low percentage of properly escaped output is a significant weakness, potentially exposing the site to cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled with care. While the SQL query usage is decent with a majority prepared, the presence of raw SQL queries, even if a minority, can still be a vector for SQL injection if not meticulously sanitized. The single file operation and external HTTP request, while not inherently risky without further context, represent potential points of interaction that could be exploited if not secured properly.
While the plugin's attack surface appears minimal with no reported AJAX handlers, REST API routes, or shortcodes, the lack of proper output escaping remains the most prominent risk. The vulnerability history is reassuring, indicating a lack of past security incidents. However, a clean history does not guarantee future security, and the identified code weaknesses need to be addressed to maintain this favorable record. In conclusion, wp-healthcheck v1.4.0 is relatively secure due to its limited attack surface and lack of historical vulnerabilities, but the high proportion of unescaped output represents a notable risk that should be prioritized for remediation.
Key Concerns
- Low percentage of properly escaped output
- Presence of raw SQL queries
WP Healthcheck Security Vulnerabilities
WP Healthcheck Code Analysis
SQL Query Safety
Output Escaping
WP Healthcheck Attack Surface
WordPress Hooks 15
Maintenance & Trust
WP Healthcheck Maintenance & Trust
Maintenance Signals
Community Trust
WP Healthcheck Alternatives
Supervisor
supervisor
Supervisor is a powerful plugin designed to enhance both the performance and security of your WordPress installation.
0 Day Analytics
0-day-analytics
0 Day Analytics is a comprehensive WordPress debugging and operational
DiveWP – Boost Site Performance with Clear, Actionable Steps
divewp-boost-site-performance
Learn WP Best Practices Through Your Own Site! Get clear insights about Performance, Security, and Best Practices – explained in plain English.
Flush Transients
flush-transients
This plugin allows you to flush WordPress transients, plain and simple.
Revision Strike
revision-strike
Periodically purge old post revisions via WP Cron.
WP Healthcheck Developer Profile
2 plugins · 1K total installs
How We Detect WP Healthcheck
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-healthcheck/assets/wp-healthcheck.min.js/wp-content/plugins/wp-healthcheck/assets/wp-healthcheck.js/wp-content/plugins/wp-healthcheck/assets/wp-healthcheck.min.css/wp-content/plugins/wp-healthcheck/assets/wp-healthcheck.css/wp-content/plugins/wp-healthcheck/assets/wp-healthcheck.min.js/wp-content/plugins/wp-healthcheck/assets/wp-healthcheck.jswp-healthcheck/assets/wp-healthcheck.min.js?ver=wp-healthcheck/assets/wp-healthcheck.js?ver=wp-healthcheck/assets/wp-healthcheck.min.css?ver=wp-healthcheck/assets/wp-healthcheck.css?ver=HTML / DOM Fingerprints
wphc-btn-transients-helpwphc-btn-autoload-helpname="admin/transients"name="admin/autoload"name="admin/wp-updates"name="admin/support"wp-healthcheck-js