WordPress.PHP.DevelopmentFunctions.error_log_error_log

error log error log

Development or debugging behavior appears in code that may run in production.

medium weight

Why It Shows Up

The scan found logging, debugging, path disclosure, `phpinfo()`, error-reporting changes, or similar development-oriented functions.

Why It Matters

Debug output can leak paths, configuration, request data, stack details, or sensitive runtime information.

How to Fix

  • Remove temporary debugging calls before release.
  • If logging is required, guard it with `WP_DEBUG` or a plugin setting intended for administrators.
  • Never show debug details to unauthenticated visitors or normal front-end users.

Affected Plugins

RankPluginScoreErrorsWarningsInstallsAddedUpdatedTop Issue
#1Live Shopping & Shoppable Videos For WooCommerce078175400Non-prefixed global variable
#2JetBackup – Backup, Restore & Migrate101,559145100k+Exception output is not escaped
#3Efí Bank17886553400Exception output is not escaped
#4JetFormBuilder — Dynamic Blocks Form Builder182,0931,58990k+Text Domain Mismatch
#5Podlove Podcast Publisher182,3261,4293k+Output is not escaped
#6RestroPress – Online Food Ordering System185213,0831k+Non-prefixed global variable
#7WPPizza – A Restaurant Plugin184,6892,7031k+Text Domain Mismatch
#8Download Monitor194251,36480k+Non-prefixed hook name
#9Go Fetch Jobs (for WP Job Manager)191,4101,741700Non-prefixed global variable
#10Matomo Analytics – Powerful, Privacy-First Insights for WordPress191,909878100k+Exception output is not escaped
#11Netgsm193382981k+Setting is missing a sanitization callback
#12Realtyna Organic IDX plugin + WPL Real Estate199473,6532k+Non-prefixed global variable
#13Really Simple Security – Simple and Performant Security (formerly Really Simple SSL)195413853m+Missing Translators Comment
#14Membership Plugin – Kadence Memberships195,0822,9829k+Text Domain Mismatch
#15SendPress Newsletters192,2931,4222k+Output is not escaped
#16SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments195261,11990k+Non-prefixed global variable
#17WordLift – AI powered SEO – Schema19393955400Non-prefixed hook name
#18WP Email Template193423502k+Exception output is not escaped
#19WPOSS阿里云对象存储192693151k+Non-prefixed namespace
#20Broadstreet20434273700Output is not escaped
#21Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC)207362,112900Non-prefixed global variable
#22DMCA Protection Badge204,4252171k+Output is not escaped
#23Event Espresso – Event Registration & Ticketing Sales2012,6982,135600Text Domain Mismatch
#24GiveWP – Donation Plugin and Fundraising Platform203,4353,575100k+Output is not escaped
#25Leaky Paywall20320776700Nonce verification recommended
#26Link Library201,9411,39710k+Unsafe printing function
#27MBE eShip205277401k+Non-prefixed global variable
#28Brevo – Email, SMS, Web Push, Chat, and more.20460646100k+Request data is not unslashed
#29MAS Videos205191,6931k+Non-prefixed global variable
#30Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization201,2922,6839k+Output is not escaped
#31Microthemer Lite – Visual Editor to Customize CSS201,0041,69910k+Non-prefixed global variable
#32Nimble Page Builder201,5911,68430k+Missing Arg Domain
#33Shipping for Nova Poshta20598923500Output is not escaped
#34پلاگین پرداخت دلخواه20584446900Text Domain Mismatch
#35PeachPay — Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net, NMI)20440750400Missing direct file access protection
#36Pix por Piggly (para Woocommerce)205471954k+Exception output is not escaped
#37SpeakOut! Email Petitions208509943k+Missing nonce verification
#38Events Manager – OpenStreetMaps20559444700Output is not escaped
#39Trace My IP – Visitor IP Tracker, Stats Analytics & Page Views Counter with Email Alerts208663381k+wp function not compatible with requires wp
#40Razorpay for WooCommerce20974855100k+Non-prefixed function
#41Backup Migration219811,09380k+Non-prefixed global variable
#42Forumax – AI Powered Advanced Community Forum Plugin214,9364,357600Text Domain Mismatch
#43CallTrackingMetrics219232863k+Unsafe printing function
#44CartFlows – Funnel Builder & Checkout Plugin for WooCommerce21462654200k+Text Domain Mismatch
#45Smart Grid-Layout Design for Contact Form 7211,12673410k+Output is not escaped
#46Daily Prayer Time219471,7801k+Non-prefixed global variable
#47Free Downloads WooCommerce214303594k+Output is not escaped
#48Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More212,5721,2771m+Output is not escaped
#49Ebook Store216661,087700Non-prefixed global variable
#50eRoom – Webinar & Meeting Plugin for Zoom, Google Meet, Microsoft Teams211864379k+Non-prefixed global variable