
WP Server Security & Risk Analysis
wordpress.org/plugins/wp-serverShow average server load and uptime of your linux server on top in admin panel
Is WP Server Safe to Use in 2026?
Generally Safe
Score 85/100WP Server has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'wp-server' plugin v2.2.3 presents a mixed security posture. On the positive side, it demonstrates strong adherence to secure coding practices by utilizing prepared statements for all SQL queries, having no recorded historical vulnerabilities, and limiting its attack surface to zero exposed entry points without authentication. The presence of nonce and capability checks, although minimal, is also a good sign. However, significant concerns arise from the static analysis, specifically the presence of dangerous functions like 'exec' and 'shell_exec'. The taint analysis revealing a flow with unsanitized paths is particularly worrying, as it indicates a potential pathway for malicious input to be executed or used in unintended ways, even if currently not flagged as critical or high severity. Furthermore, 100% of output is not properly escaped, creating a risk of cross-site scripting (XSS) vulnerabilities.
The complete absence of known vulnerabilities in its history is a positive indicator, suggesting either a history of responsible development or a lack of public discovery. However, this cannot fully offset the immediate risks identified in the code. The combination of dangerous functions and unsanitized input flows, coupled with unescaped output, represents a significant potential risk that requires immediate attention. While the plugin has strengths in its limited attack surface and SQL handling, the identified code-level risks are substantial and could be exploited if not addressed.
Key Concerns
- Dangerous functions (exec, shell_exec) used
- Flow with unsanitized paths
- Output escaping: 0% properly escaped
WP Server Security Vulnerabilities
WP Server Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
WP Server Attack Surface
WordPress Hooks 5
Maintenance & Trust
WP Server Maintenance & Trust
Maintenance Signals
Community Trust
WP Server Alternatives
Server Status
server-status
Show server information widget in Dashboard and Network Admin Dashboard.(Currently, only RHEL is tested)
Media Sync
media-sync
Simple plugin to scan "uploads" directory and bring those files into Media Library.
Server Info
server-info
This plugin will show you very useful information about your hosting server such as PHP version, Server OS, Server IP etc.
atec System Info
atec-system-info
atec System Info (Operating system, server, memory, PHP and database details)
Better Resource Hints
better-resource-hints
Better Resource Hints will make your WordPress site or application faster and generally more performant by intelligently leveraging resource hints lik …
WP Server Developer Profile
5 plugins · 1K total installs
How We Detect WP Server
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
nabserver_main_options_sectionid="wp_server_status"name="nabserver_noncename"id="nabserver_noncename"name="action_nabserver"id="submit_nabserver"