
WP XHProf Profiler Security & Risk Analysis
wordpress.org/plugins/wp-xhprof-profilerAdds PHP profiling support to your Wordpress using Facebook's XHProf Profiler.
Is WP XHProf Profiler Safe to Use in 2026?
Generally Safe
Score 85/100WP XHProf Profiler has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-xhprof-profiler plugin, version 0.9, exhibits a mixed security posture. On one hand, the plugin demonstrates good practices by utilizing prepared statements for all its SQL queries and having no recorded CVEs or unpatched vulnerabilities. This suggests a generally stable and well-maintained history. However, the static analysis reveals several concerning areas. The complete lack of nonce and capability checks on any entry points, coupled with a significant percentage of unescaped output, presents a notable risk. The presence of dangerous functions like `proc_open` and `unserialize`, especially without clear sanitization demonstrated in the taint analysis, raises red flags regarding potential code execution and deserialization vulnerabilities. While taint analysis did not find critical or high severity issues, the 'flows with unsanitized paths' indicate potential avenues for exploitation if malicious data is introduced through the plugin's interactions. The bundled outdated jQuery library is another minor concern. Overall, the plugin has a clean vulnerability history, but the identified code-level weaknesses in input validation and output escaping, alongside the use of dangerous functions, necessitate careful consideration and potential remediation.
Key Concerns
- No nonce checks on any entry points
- No capability checks on any entry points
- 0% output escaping
- Dangerous function: proc_open
- Dangerous function: unserialize
- 2 flows with unsanitized paths
- Bundled outdated library: jQuery v1.2.6
WP XHProf Profiler Security Vulnerabilities
WP XHProf Profiler Code Analysis
Dangerous Functions Found
Bundled Libraries
Output Escaping
Data Flow Analysis
WP XHProf Profiler Attack Surface
WordPress Hooks 2
Maintenance & Trust
WP XHProf Profiler Maintenance & Trust
Maintenance Signals
Community Trust
WP XHProf Profiler Alternatives
MySQL Profiler
mysql-profiler
Displays a list of each page's SQL queries and the functions calling them that can be searched and sorted by time, type, etc.
Code Profiler – WordPress Performance Profiling and Debugging Made Easy
code-profiler
A profiler to measure the performance of your WordPress plugins and themes.
Error Log Viewer by BestWebSoft
error-log-viewer
Get latest error log messages to diagnose website problems. Define and fix issues faster.
Easy PHP Settings
easy-php-settings
An easy way to manage common PHP INI settings and WordPress debugging constants from the WordPress admin panel.
BugFu Console Debugger
bugfu-console-debugger
Log/Debug the PHP code in your Theme/Plugin with your Browser Console (no extension needed)
WP XHProf Profiler Developer Profile
4 plugins · 40 total installs
How We Detect WP XHProf Profiler
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-xhprof-profiler/facebook-xhprof/xhprof_html/css/xhprof.css/wp-content/plugins/wp-xhprof-profiler/facebook-xhprof/xhprof_html/js/xhprof.js/wp-content/plugins/wp-xhprof-profiler/facebook-xhprof/xhprof_html/js/xhprof.jsHTML / DOM Fingerprints
xhprof_headerxhprof_navxhprof_reportxhprof_tablexhprof_function_detailsxhprof_callgraph_containerxhprof----> <a href="