
WP Tracy Security & Risk Analysis
wordpress.org/plugins/wp-tracyWP Tracy is a plugin that automatically inserts debugger (Nette) Tracy into WordPress.
Is WP Tracy Safe to Use in 2026?
Generally Safe
Score 85/100WP Tracy has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-tracy" v2.0.1 plugin exhibits a strong overall security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points, coupled with the complete avoidance of dangerous functions and file operations, indicates a well-contained and minimal attack surface. Furthermore, all SQL queries are correctly implemented using prepared statements, which is a critical security practice for preventing SQL injection vulnerabilities. The lack of external HTTP requests and the use of secure coding practices for database interactions are positive indicators.
However, a significant concern arises from the output escaping analysis. With 5 total outputs and 0% properly escaped, this represents a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. Any dynamic data outputted by the plugin that is not properly escaped could be manipulated by attackers to inject malicious scripts, impacting users who interact with the affected content. The absence of recorded vulnerabilities in its history is a positive sign, suggesting a history of secure development or effective patching. Despite the clean vulnerability history, the unescaped output remains a critical weakness that needs immediate attention.
In conclusion, while the "wp-tracy" plugin demonstrates good practices in attack surface reduction, SQL query handling, and avoiding dangerous functions, the critical flaw in output escaping presents a clear and present danger of XSS. The strong foundation in other areas is overshadowed by this oversight. Addressing the unescaped output is paramount to improving the plugin's security.
Key Concerns
- 0% output escaping
WP Tracy Security Vulnerabilities
WP Tracy Code Analysis
Output Escaping
WP Tracy Attack Surface
WordPress Hooks 4
Maintenance & Trust
WP Tracy Maintenance & Trust
Maintenance Signals
Community Trust
WP Tracy Alternatives
Debug This
debug-this
Peek under the hood with sixty debugging reports just one click away.
Kint PHP Debugger
kint-php-debugger
Kint is a modern and powerful PHP debugging helper, which requires zero-setup and replaces var_dump(), print_r() and debug_backtrace().
wp-dBug
wp-dbug
Plugin implements the awesome dBug class created by Kwaku Otchere for use in WordPress plugin debugging
DP Debug Menu
dp-debug-menu
Quickly shows the template used for current page, number of queries, and execution time for PHP code.
Debug Toolkit
debug-toolkit
Code debug made easier and more enjoyable.
WP Tracy Developer Profile
1 plugin · 100 total installs
How We Detect WP Tracy
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-tracy/tracy/bar.css/wp-content/plugins/wp-tracy/tracy/dumper.css/wp-content/plugins/wp-tracy/tracy/tracy.js/wp-content/plugins/wp-tracy/tracy/tracy.jswp-tracy/tracy.js?ver=wp-tracy/bar.css?ver=wp-tracy/dumper.css?ver=HTML / DOM Fingerprints
tracy-bartracy-dumperTracy