
Web Server Information Security & Risk Analysis
wordpress.org/plugins/wpheka-web-server-informationWeb Server Information plugin will give you detailed information about your hosting server's configuration and installed modules.
Is Web Server Information Safe to Use in 2026?
Generally Safe
Score 100/100Web Server Information has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wpheka-web-server-information plugin v1.7 exhibits a mixed security posture. While the attack surface appears to be zero, and all SQL queries utilize prepared statements, several concerning code signals are present. The use of `unserialize` without apparent sanitization or input validation is a significant risk, as it can lead to Remote Code Execution (RCE) if malicious serialized data is processed. Furthermore, only 26% of output is properly escaped, indicating a potential for Cross-Site Scripting (XSS) vulnerabilities. The presence of two flows with unsanitized paths in the taint analysis also raises red flags, suggesting that user-supplied data might be processed in a way that could be exploited. The plugin's vulnerability history is clean, with no known CVEs, which is a positive indicator. However, the internal code signals of concern, particularly the `unserialize` function and the taint analysis results, suggest that the plugin's security relies heavily on the assumption that its inputs are always trusted, which is rarely the case in real-world scenarios. The lack of nonce checks and capability checks on potential entry points (even if currently zero) is also a weakness that could become a vulnerability if new entry points are introduced.
Key Concerns
- Dangerous function 'unserialize' used
- Low percentage of properly escaped output
- Flows with unsanitized paths found
- No nonce checks implemented
- No capability checks implemented
Web Server Information Security Vulnerabilities
Web Server Information Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Web Server Information Attack Surface
WordPress Hooks 9
Maintenance & Trust
Web Server Information Maintenance & Trust
Maintenance Signals
Community Trust
Web Server Information Alternatives
Server Info for Debugging
server-info-for-debugging
Displays server stats and WordPress system information for debugging purposes.
WP Tech Lookup
wp-tech-lookup
WP Tech Lookup plugin is to see all the necessary information about server at one place.
PHP Server Configuration
php-server-configuration
A simple Light weight plugin to look up information about PHP Info and manage PHP configurations values.
PHP Server Info
php-server-info
A very simple plugin for displaying full PHP Info from within the WordPress Admin menu.
Debugger & Troubleshooter
debugger-troubleshooter
A WordPress plugin for debugging & troubleshooting. Safely simulate plugin deactivation, theme switching, and WP_DEBUG.
Web Server Information Developer Profile
4 plugins · 2K total installs
How We Detect Web Server Information
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpheka-web-server-information/assets/css/admin.csswpheka-web-server-information/assets/css/admin.css?ver=