
WP Signals Security & Risk Analysis
wordpress.org/plugins/wp-signalsBecome a data-driven marketer. Setup your Facebook pixels in less than a minute with our powerful Wizard. Try it out now for free.
Is WP Signals Safe to Use in 2026?
Generally Safe
Score 85/100WP Signals has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-signals" v2.0.0 plugin presents a mixed security posture. On the positive side, it demonstrates good practices regarding SQL query handling by exclusively using prepared statements, and it has no known historical vulnerabilities (CVEs). This suggests a potentially well-maintained and audited codebase in the past.
However, significant concerns arise from the static analysis. The plugin exposes two REST API routes without any permission callbacks, creating a substantial attack surface with direct, unprotected entry points. Furthermore, the taint analysis reveals that all seven analyzed flows involve unsanitized paths, though thankfully these did not escalate to critical or high severity in this analysis. The presence of dangerous functions like `set_time_limit` without clear context can also be a risk if not properly managed. The relatively low percentage of properly escaped output (46%) also indicates a potential for cross-site scripting (XSS) vulnerabilities.
In conclusion, while the absence of historical vulnerabilities and sound SQL practices are strengths, the unprotected REST API endpoints and unsanitized taint flows are critical security weaknesses that require immediate attention. The overall risk is moderate, leaning towards high due to the open attack surface.
Key Concerns
- REST API routes without permission callbacks
- Taint flows with unsanitized paths
- Low percentage of properly escaped output
- Dangerous function usage (set_time_limit)
- No nonce checks on entry points
WP Signals Security Vulnerabilities
WP Signals Release Timeline
WP Signals Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
WP Signals Attack Surface
REST API Routes 2
WordPress Hooks 17
Maintenance & Trust
WP Signals Maintenance & Trust
Maintenance Signals
Community Trust
WP Signals Alternatives
Insert Headers And Footers
wp-headers-and-footers
Include inline javascript, stylesheets, CSS code or anything you want in Header and Footer areas of your WordPress with ease.
Pixel Manager for WooCommerce – Conversion Tracking, Google Ads, GA4, TikTok, Dynamic Remarketing
woocommerce-google-adwords-conversion-tracking-tag
Conversion tracking for WooCommerce. Google Ads, GA4, Meta/Facebook Pixel, TikTok & more. Recover 30% more conversions with server-side tracking!
Pixel Cat – Conversion Pixel Manager
facebook-conversion-pixel
Add Meta & Facebook Pixel, Google Analytics (GA4) and any header script to your site. Everything you need to track users, ads, events & conversions.
Tag Manager – Header, Body And Footer
tag-manager-header-body-footer
Simple plugin that allow you add head, body and footer codes for google tag manager, analytics & facebook pixel codes.
Controls for Contact Form 7 (Redirects, Analytics & Tracking)
contact-form-7-extras
Analytics, tracking, redirects and storage for Contact Form 7.
WP Signals Developer Profile
1 plugin · 10 total installs
How We Detect WP Signals
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-signals/Admin/css/wp-signals-admin.min.css/wp-content/plugins/wp-signals/Admin/css/wp-signals-admin.css/wp-content/plugins/wp-signals/public/css/wp-signals-public.min.css/wp-content/plugins/wp-signals/public/css/wp-signals-public.css/wp-content/plugins/wp-signals/public/js/wp-signals-public.min.js/wp-content/plugins/wp-signals/public/js/wp-signals-public.jswp-signals-admin.css?ver=wp-signals-admin.min.css?ver=wp-signals-public.css?ver=wp-signals-public.min.css?ver=wp-signals-public.js?ver=wp-signals-public.min.js?ver=