Hosting Benchmark tool Security & Risk Analysis

wordpress.org/plugins/wpbenchmark

Benchmark your hosting server CPU, memory and disk, compare with others using simple Wordpress plugin.

4K active installs v1.6.5 PHP 5.6+ WP 4.0+ Updated Jan 25, 2026
benchmarkhostingoptimizationperformancespeed
99
A · Safe
CVEs total1
Unpatched0
Last CVEApr 10, 2024
Safety Verdict

Is Hosting Benchmark tool Safe to Use in 2026?

Generally Safe

Score 99/100

Hosting Benchmark tool has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Apr 10, 2024Updated 2mo ago
Risk Assessment

The wpbenchmark plugin v1.6.5 exhibits a generally positive security posture, particularly in its handling of entry points and the absence of critical or high severity taint flows. The plugin effectively utilizes nonce checks and capability checks on most of its identified entry points, which is a good practice for mitigating common web vulnerabilities. Furthermore, the static analysis did not reveal any dangerous functions or unsanitized paths, suggesting a level of developer diligence in secure coding. However, there are areas for concern, notably the low percentage of properly escaped output and a significant number of file operations without explicit mention of security context. While no raw SQL queries are flagged as unescaped, the overall output escaping percentage is a weakness that could lead to cross-site scripting (XSS) vulnerabilities if not consistently handled elsewhere in the application logic.

The vulnerability history indicates a past medium-severity Cross-Site Request Forgery (CSRF) vulnerability. The fact that this vulnerability is currently unpatched is a significant concern. While there are no currently active critical or high vulnerabilities, the presence of a historical CSRF suggests a potential for similar issues to arise or persist if not thoroughly addressed. The relatively low number of CVEs overall is positive, but the unpatched status of the past medium vulnerability cannot be ignored in the risk assessment. In conclusion, wpbenchmark has strengths in its controlled attack surface and use of security checks, but weaknesses in output escaping and the concerning unpatched historical vulnerability warrant caution.

Key Concerns

  • Unpatched medium severity vulnerability
  • Low percentage of properly escaped output
Vulnerabilities
1

Hosting Benchmark tool Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-31922medium · 4.3Cross-Site Request Forgery (CSRF)

WordPress Hosting Benchmark tool <= 1.3.6 - Cross-Site Request Forgery via execute_plugin()

Apr 10, 2024 Patched in 1.3.7 (7d)
Code Analysis
Analyzed Mar 16, 2026

Hosting Benchmark tool Code Analysis

Dangerous Functions
0
Raw SQL Queries
11
12 prepared
Unescaped Output
9
1 escaped
Nonce Checks
5
Capability Checks
3
File Operations
19
External Requests
2
Bundled Libraries
0

SQL Query Safety

52% prepared23 total queries

Output Escaping

10% escaped10 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
admin_menu_options (wp-benchmark-io.php:124)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Hosting Benchmark tool Attack Surface

Entry Points4
Unprotected0

Shortcodes 4

[wpbenchmak_columns] class.wpbenchmarkio.php:835
[wpbenchmak_row] class.wpbenchmarkio.php:839
[wpbenchmak_section] class.wpbenchmarkio.php:843
[wpbenchmak_tabs] class.wpbenchmarkio.php:847
WordPress Hooks 12
filtertest_benchmark_filterclass.wpbenchmarkio.php:890
filterthe_contentclass.wpbenchmarkio.php:1249
filterthe_contentclass.wpbenchmarkio.php:1250
filterthe_contentclass.wpbenchmarkio.php:1251
filterthe_contentclass.wpbenchmarkio.php:1252
filterthe_contentclass.wpbenchmarkio.php:1253
filterthe_contentclass.wpbenchmarkio.php:1254
filterthe_contentclass.wpbenchmarkio.php:1257
actionadmin_initwp-benchmark-io.php:62
actionadmin_enqueue_scriptswp-benchmark-io.php:64
actioninitwp-benchmark-io.php:1504
actionwpbenchmark_schedulled_eventwp-benchmark-io.php:1509
Maintenance & Trust

Hosting Benchmark tool Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 25, 2026
PHP min version5.6
Downloads109K

Community Trust

Rating94/100
Number of ratings32
Active installs4K
Developer Profile

Hosting Benchmark tool Developer Profile

Anton Aleksandrov

2 plugins · 4K total installs

94
trust score
Avg Security Score
92/100
Avg Patch Time
7 days
View full developer profile
Detection Fingerprints

How We Detect Hosting Benchmark tool

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wpbenchmark-io/js/wpbenchmark-io.js/wp-content/plugins/wpbenchmark-io/css/wpbenchmark-io.css
Script Paths
https://cdnjs.cloudflare.com/ajax/libs/Chart.js/4.4.1/chart.umd.min.js
Version Parameters
wpbenchmark-io/js/wpbenchmark-io.js?ver=wpbenchmark-io/css/wpbenchmark-io.css?ver=

HTML / DOM Fingerprints

CSS Classes
wpio-panelwpio-headlinewpio-textwpio-buttonwpio-benchmark-run-nowwpio-benchmark-run-now-btnwpio-benchmark-schedulledwpio-schedulled-disable-btn+6 more
HTML Comments
<!-- START OF WPBENCHMARK.IO ADMIN MENU --><!-- END OF WPBENCHMARK.IO ADMIN MENU -->
Data Attributes
data-wpbenchmark-io-anonymize-after
JS Globals
wpbenchmark_io_chartjs_instancewpbenchmark_io_chart
FAQ

Frequently Asked Questions about Hosting Benchmark tool