YLD Server Information Security & Risk Analysis

wordpress.org/plugins/yld-server-information

It will show all server information in an admin page.

10 active installs v1.2 PHP 5.6+ WP 5.0.4+ Updated Dec 7, 2019
informationmysqlphpserverversion
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is YLD Server Information Safe to Use in 2026?

Generally Safe

Score 85/100

YLD Server Information has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The "yld-server-information" v1.2 plugin exhibits a generally good security posture based on the provided static analysis and vulnerability history. The absence of dangerous functions, SQL injection vulnerabilities, file operations, and external HTTP requests are all positive indicators. Furthermore, the fact that the single SQL query found uses prepared statements is a strong security practice.

However, a significant concern arises from the complete lack of output escaping. This means that any data displayed by the plugin could potentially be injected with malicious code, leading to cross-site scripting (XSS) vulnerabilities. While the attack surface appears minimal, the lack of capability checks and nonce checks, combined with the unescaped output, creates a potential pathway for certain types of attacks if any input can be manipulated to influence the output.

The plugin's vulnerability history is clean, with no recorded CVEs, suggesting a history of secure development. This, coupled with the secure handling of SQL and absence of critical taint flows, indicates a developer who is likely aware of common vulnerabilities. Despite the clean history, the unescaped output is a notable weakness that needs addressing to solidify its security.

Key Concerns

  • All outputs are unescaped
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

YLD Server Information Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

YLD Server Information Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

YLD Server Information Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
2
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

0% escaped2 total outputs
Attack Surface

YLD Server Information Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionadmin_menuyld-server-info.php:11
Maintenance & Trust

YLD Server Information Maintenance & Trust

Maintenance Signals

WordPress version tested5.3.21
Last updatedDec 7, 2019
PHP min version5.6
Downloads986

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

YLD Server Information Developer Profile

devparis

2 plugins · 9K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect YLD Server Information

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/yld-server-information/style.css
Version Parameters
yld-server-information/style.css?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about YLD Server Information