WordPress.PHP.DevelopmentFunctions.error_log_error_log

error log error log

Development or debugging behavior appears in code that may run in production.

medium weight

Why It Shows Up

The scan found logging, debugging, path disclosure, `phpinfo()`, error-reporting changes, or similar development-oriented functions.

Why It Matters

Debug output can leak paths, configuration, request data, stack details, or sensitive runtime information.

How to Fix

  • Remove temporary debugging calls before release.
  • If logging is required, guard it with `WP_DEBUG` or a plugin setting intended for administrators.
  • Never show debug details to unauthenticated visitors or normal front-end users.

Affected Plugins

RankPluginScoreErrorsWarningsInstallsAddedUpdatedTop Issue
#551Custom Sidebars – Dynamic Sidebar Classic Widget Area Manager3432307100k+Non-prefixed global variable
#552Datafeedr API34307486k+Output is not escaped
#553ePayco Plugin for WooCommerce341551363k+Text Domain Mismatch
#554FastPixel Cache – Optimize Page Speed: Compress Images, Minify, Clean Database & CDN34493244k+Request data is not unslashed
#555Forms: 3rd-Party Integration342341125k+Output is not escaped
#556Garden Gnome Package34116514k+Text Domain Mismatch
#557Inavii Social Feed – Live Social Proof Gallery345321809k+Text Domain Mismatch
#558IP2Location Country Blocker342958830k+Output is not escaped
#559Meow Lightbox34755210k+Non Singular String Literal Domain
#560Multi Step Form342771369k+Output is not escaped
#561Ni WooCommerce Custom Order Status342561392k+Text Domain Mismatch
#562One User Avatar | User Profile Picture3468190100k+Non-prefixed global variable
#563Optima Express IDX347123710k+Non-prefixed class
#564Child Theme Creator by Orbisius34863910k+Output is not escaped
#565المنتور فارسی34525040k+curl curl setopt
#566PushEngage – Web Push Notifications, WooCommerce Automation & Chat Widget34543049k+Missing nonce verification
#567Throws SPAM Away3432712310k+Missing Arg Domain
#568Tidio – Live Chat & AI Chatbots34521980k+curl curl setopt
#569Tools for Twitter34135871k+Output is not escaped
#570Easy Booking – WooCommerce Booking & Reservation Plugin341381724k+Output is not escaped
#571Product Tabs for WooCommerce341969310k+Text Domain Mismatch
#572WP Mail Logging3476258300k+Nonce verification recommended
#573Advanced Custom Fields: Image Aspect Ratio Crop Field35703720k+Text Domain Mismatch
#574SOOZ – AI for SEO – Bulk Generate Focus Keyphrases, Metadata, Alt Text (SEO Autopilot)35443942k+Nonce verification recommended
#575Akismet Anti-spam: Spam Protection3533996m+Non-prefixed global variable
#576BabyLoveGrowth Integration35291k+Direct Query
#577BackWPup – WordPress Backup & Restore Plugin3512779500k+Non-prefixed global variable
#578bbPress Notify (No-Spam)3562662k+wp function not compatible with requires wp
#579BotWriter – AI Writer & SEO Content Generator35165033k+Direct Query
#580Custom Order Status Manager for WooCommerce356306730k+Text Domain Mismatch
#581C3 Cloudfront Cache Controller35109603k+Non Singular String Literal Domain
#582CF7 Views – Complete Entry Management for Contact Form 7351721811k+Output is not escaped
#583Cloudflare352785200k+Non-prefixed namespace
#584Cookie Information – Cookie Banner with Consent Mode v235185282k+Output is not escaped
#585Core Framework35706210k+Text Domain Mismatch
#586CrowdSec351301192k+Output is not escaped
#587Custom Order Numbers for WooCommerce3555420k+Non-prefixed hook name
#588Datafeedr Product Sets356022065k+Output is not escaped
#589Deposits & Partial Payments for WooCommerce351721445k+Text Domain Mismatch
#590DesignSetGo35203134k+Non-prefixed global variable
#591PiWeb Disable payment method / Partial payment for WooCommerce35552214k+Non-prefixed class
#592Disk Usage Sunburst3530349k+Output is not escaped
#593Elementor Website Builder – more than just a page builder354642810m+Non-prefixed global variable
#594AI Popup Builder & Popup Maker by OptiMonk3581654k+Text Domain Mismatch
#595Pixel Cat – Conversion Pixel Manager3525321540k+Output is not escaped
#596GA4WP – Analytics Dashboard for the Website354341572k+Text Domain Mismatch
#597Glossary35169932k+Non Singular String Literal Domain
#598Gravitec.net – Web Push Notifications3547521k+wp function not compatible with requires wp
#599Image Widget3516531100k+Output is not escaped
#600Keyring352332031k+Output is not escaped