
YLD Server Information Security & Risk Analysis
wordpress.org/plugins/yld-server-informationIt will show all server information in an admin page.
Is YLD Server Information Safe to Use in 2026?
Generally Safe
Score 85/100YLD Server Information has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "yld-server-information" v1.2 plugin exhibits a generally good security posture based on the provided static analysis and vulnerability history. The absence of dangerous functions, SQL injection vulnerabilities, file operations, and external HTTP requests are all positive indicators. Furthermore, the fact that the single SQL query found uses prepared statements is a strong security practice.
However, a significant concern arises from the complete lack of output escaping. This means that any data displayed by the plugin could potentially be injected with malicious code, leading to cross-site scripting (XSS) vulnerabilities. While the attack surface appears minimal, the lack of capability checks and nonce checks, combined with the unescaped output, creates a potential pathway for certain types of attacks if any input can be manipulated to influence the output.
The plugin's vulnerability history is clean, with no recorded CVEs, suggesting a history of secure development. This, coupled with the secure handling of SQL and absence of critical taint flows, indicates a developer who is likely aware of common vulnerabilities. Despite the clean history, the unescaped output is a notable weakness that needs addressing to solidify its security.
Key Concerns
- All outputs are unescaped
- No nonce checks on entry points
- No capability checks on entry points
YLD Server Information Security Vulnerabilities
YLD Server Information Release Timeline
YLD Server Information Code Analysis
SQL Query Safety
Output Escaping
YLD Server Information Attack Surface
WordPress Hooks 1
Maintenance & Trust
YLD Server Information Maintenance & Trust
Maintenance Signals
Community Trust
YLD Server Information Alternatives
Version Info – Server Health Monitor, PHP & MySQL Version Display, Environment Indicators
version-info
The #1 technical dashboard for WordPress professionals. Display PHP, MySQL, WP & server versions anywhere in admin. Monitor CPU, RAM, DB size & …
Diagnosis
diagnosis
Adds pages to the Dashboard menu with technical details about PHP, MySQL and other server details an administrator might need.
PHP Version Display
php-version-display
Display the currently PHP-MYSQL version at the end of "At a Glance" admin dashboard widget
Roosium Info
roosium-info
Display WordPress, PHP, Web Server, MySQL and Theme versions in wp-admin footer.
WP Tech Lookup
wp-tech-lookup
WP Tech Lookup plugin is to see all the necessary information about server at one place.
YLD Server Information Developer Profile
2 plugins · 9K total installs
How We Detect YLD Server Information
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/yld-server-information/style.cssyld-server-information/style.css?ver=