
WP-ServerInfo Security & Risk Analysis
wordpress.org/plugins/wp-serverinfoDisplay your host's PHP, MYSQL & memcached (if installed) information on your WordPress dashboard.
Is WP-ServerInfo Safe to Use in 2026?
Generally Safe
Score 85/100WP-ServerInfo has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-serverinfo plugin v1.66 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and lacks known vulnerabilities, indicating a generally well-maintained codebase. However, several areas raise concerns. The presence of a 'system' function call is a significant risk, as it can be exploited to execute arbitrary system commands if not properly sanitized. Furthermore, the low percentage of properly escaped outputs (4%) suggests a high likelihood of cross-site scripting (XSS) vulnerabilities. The taint analysis revealing flows with unsanitized paths, while not reaching critical or high severity in this specific analysis, points to potential weaknesses in input validation. The absence of nonce checks on any entry points is also a notable oversight, increasing the risk of CSRF attacks, particularly if any of the file operations or the 'system' function were to be triggered by unauthenticated users.
Key Concerns
- Dangerous function 'system' detected
- Low percentage of properly escaped outputs (4%)
- Flows with unsanitized paths detected
- No nonce checks on entry points
- File operations present without explicit auth checks
WP-ServerInfo Security Vulnerabilities
WP-ServerInfo Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
WP-ServerInfo Attack Surface
WordPress Hooks 4
Maintenance & Trust
WP-ServerInfo Maintenance & Trust
Maintenance Signals
Community Trust
WP-ServerInfo Alternatives
Version Info – Server Health Monitor, PHP & MySQL Version Display, Environment Indicators
version-info
The #1 technical dashboard for WordPress professionals. Display PHP, MySQL, WP & server versions anywhere in admin. Monitor CPU, RAM, DB size & …
phpinfo() WP
phpinfo-wp
A simple plugin to look up server info and manage server configuration of wordpress site
PHP Server Info
php-server-info
A very simple plugin for displaying full PHP Info from within the WordPress Admin menu.
Diagnosis
diagnosis
Adds pages to the Dashboard menu with technical details about PHP, MySQL and other server details an administrator might need.
Phpinfo
phpinfo
Prints out your webservers php settings as well as other information about your WordPress installation.
WP-ServerInfo Developer Profile
20 plugins · 889K total installs
How We Detect WP-ServerInfo
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-serverinfo/serverinfo-js.js/wp-content/plugins/wp-serverinfo/serverinfo-js.jswp-serverinfo/serverinfo-js.js?ver=HTML / DOM Fingerprints
wrapwidefatid="GeneralOverview"id="PHPinfo"