phpinfo() WP – Site Health, PHP Compatibility & Server Audit
phpinfo() WP – Site Health, PHP Compatibility & Server Audit has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2023 and 2024; all 2 are fixed as of September 2026. Their average CVSS score is 5.3, and the most serious one scores 5.4 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (50%). Other recurring categories include Exposure Of Sensitive Information To An Unauthorized Actor.
Every one of the 2 issues recorded for phpinfo() WP – Site Health, PHP Compatibility & Server Audit has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. phpinfo() WP – Site Health, PHP Compatibility & Server Audit is installed on roughly 3,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2023-26542phpinfo() WP <= 4.0 - Cross-Site Request Forgery
Read the full analysisVulnerability Records

phpinfo() WP – Site Health, PHP Compatibility & Server Audit
Author
Exeebit
phpinfo() WP is a modern, actively-maintained WordPress site health and server audit plugin. It is the exact in-admin tool freelancers and agencies install on every fresh site to instantly see what is wrong, what is about to break, and what to fix, all without a SaaS subscription, without external dashboards, and without leaving the WordPress admin panel. Think of it as the official “Health Check & Troubleshooting” plugin, but built for professional production sites. Our Troubleshooting Mode runs completely in a per-user session. Visitors and clients continue to see the live site normally while you safely debug and isolate conflicts without a single second of downtime. The free version covers what every WordPress site owner actually needs: phpinfo() viewer: Clean, searchable, and modern (the original feature, completely restyled). Host-Friendly Compatibility Scanner: Scan all plugins and themes for PHP version conflicts before upgrading, built to work smoothly even on strict managed hosts. Update Guard: Complete pre-update & post-update safety suite. Preview core upgrade stability, scan pending plugin and theme updates for breaking changes, and auto-verify site health 60s after every update. Zero-Downtime Troubleshooting: Safely debug theme and plugin conflicts in your own admin session without affecting visitors or live sales. PHP EOL Timeline: Every PHP version’s end-of-life date, current status, and days remaining. Config Grader summary: Overall A-F grade of your PHP config against WordPress best practices. PHP Config editor (.htaccess / .user.ini): Set or change php.ini directives safely from your dashboard, with automatic backups and safety rollback. Admin bar health scoreboard: Live grade and most-urgent issue on every admin page, like PageSpeed for your server. Dashboard widget: Site health at a glance the moment you log in. Activity log, Extensions, and Basic info: Everything the original plugin did, completely restyled. AI-Ready API (WP 7.0): Exposes audit data so AI assistants and plugins can inspect server health through a standard core interface. AI Explanations (WP 7.0): Instantly explain failing checks in plain English using the core AI Client connection. Pro adds the tooling agencies and serious site owners actually need: Safeguard: Don’t break your site 1-Click Auto-Fix with Rollback: Fix config issues instantly. Writes optimization rules to .htaccess or .user.ini and auto-reverts if the server hits a 500 error. Pre-Update PHP check: Scan plugin updates before upgrading to verify they do not require a PHP version you do not have. Update Guard Pro: Automatic interception on the WordPress Updates page, changelog breaking-change risk analysis, WP.org abandonment alerts, post-update diagnostic health checks (loopback, error log delta, cron), and AI-written remediation steps. Config Snapshots: Weekly automatic snapshots of every php.ini directive, with visual diffs. Security Headers Auditor: Grade your HTTP response headers (CSP, HSTS, X-Frame-Options) with fix suggestions. Web Server Snippet Library: Optimized Nginx and Apache configuration blocks for caching, security, and bad bot blocking, with 1-click injection for Apache and LiteSpeed. SSL Certificate Monitor: Track certificate expiry and domain mismatches to avoid security warnings. Insight: Know what is wrong before clients call Full Config Grader: Detailed grading with the exact recommended values and why each directive matters. Database Health: Engine version, EOL status, size, and autoload bloat detection. External API Monitor: Track response times, status codes, and SSL expiry for third-party endpoints your site depends on. Permissions Audit: Recursive file and directory permission auditor. OPcache Dashboard: Memory usage, hit rate, cached scripts, and one-click reset. Object Cache Monitor: Status, backend detection, hit/miss metrics, and Redis/Memcached verification. Live Error Log Viewer: Filterable error stream directly inside wp-admin. WP-Cron Monitor: Catch missed tasks, runaway jobs, and stuck schedules. Mail Deliverability: Test wp_mail(), inspect PHPMailer transport, and send test emails. Health Alerts: Real-time email notifications and Slack/Discord webhook alerts when critical issues occur. Deliver: Look professional to clients Email Alerts: Get notified on PHP EOL, config drift, OPcache drops, and SSL expiry. Weekly Digest: Full server health summary delivered to your inbox every Monday (Unlimited or Lifetime). Integrations: Slack, Discord, and Webhook support for real-time alerts (Unlimited or Lifetime). Multi-Site Dashboard: Network-wide dashboard widget support on every subsite. Why use this instead of 5 different plugins? Most WordPress site health tools force you to install separate plugins for PHP compatibility, SSL monitoring, security headers, OPcache, error logs, cron, and reports. Each one is another plugin to update, another menu item, and another set of options. phpinfo() WP gives you one in-admin plugin that covers all of it, with a single dashboard widget and a single PDF audit report. No external SaaS dashboard, no per-site monthly fees, and no separate logins. Pricing Single Site: $29/year (1 site, essential Pro features, branded PDF, 3 snapshots, 1 API monitor) Unlimited Sites: $69/year (the popular pick, works on every site, fully white-labeled, unlimited snapshots and API monitors) Lifetime: $149 once (founders pricing, first 50 buyers, unlimited sites, fully white-labeled) 14-day money-back guarantee. Instant license delivery. Site-locked license keys. Buy at exeebit.com/phpinfo-wp.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C