WordPress.PHP.DevelopmentFunctions.prevent_path_disclosure_error_reporting

prevent path disclosure error reporting

Development or debugging behavior appears in code that may run in production.

medium weight

Why It Shows Up

The scan found logging, debugging, path disclosure, `phpinfo()`, error-reporting changes, or similar development-oriented functions.

Why It Matters

Debug output can leak paths, configuration, request data, stack details, or sensitive runtime information.

How to Fix

  • Remove temporary debugging calls before release.
  • If logging is required, guard it with `WP_DEBUG` or a plugin setting intended for administrators.
  • Never show debug details to unauthenticated visitors or normal front-end users.

Affected Plugins

RankPluginScoreErrorsWarningsInstallsAddedUpdatedTop Issue
#101UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP236932,43620k+Non-prefixed hook name
#102WHMCS Bridge232474724k+Nonce verification recommended
#103WP BackItUp Community Edition232579896k+Non-prefixed global variable
#104Clone2324426240k+Output is not escaped
#105WP-Lister Lite for Amazon233,0614,177800Output is not escaped
#106Dynamic Team Manager – Team Member Showcase with grid, slider, table Elementor widget & shortcode239332,002900Non-prefixed global variable
#107Yatra – Travel Booking & Tour Operator Software232,2113,994600Non-prefixed global variable
#108Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress232,3171,7145k+Output is not escaped
#109Zephyr Project Manager236672,4541k+Non-prefixed global variable
#110404 Solution244861,33810k+Non-prefixed class
#111Anti Spam and list cleaner – AcyChecker2446288400Output is not escaped
#112AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress245,2301,4647k+Output is not escaped
#113Ad Inserter – Ad Manager & AdSense Ads244,241811300k+Output is not escaped
#114Ivory Search – WordPress Search Plugin241,1731,688100k+Non-prefixed global variable
#115Advanced Contact form 7 DB247641,96070k+Non-prefixed global variable
#116All-In-One Security (AIOS) – Security and Firewall245521,2281m+Non-prefixed global variable
#117Popup Box – Create Countdown, Coupon, Video, Contact Form Popups244821,25350k+Non-prefixed global variable
#118Backuply – Backup, Restore, Migrate and Clone24704551700k+Non-prefixed global variable
#119Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale)241,8371,0631k+Text Domain Mismatch
#120Product Feed Manager For WooCommerce – Sell on 200+ Online Marketplaces242,2483,33810k+slow db query meta key
#121Buttonizer – Floating Menus, Sticky Buttons, & Popup Builder245761,34470k+Non-prefixed global variable
#122Calculated Fields Form2428359940k+Non-prefixed global variable
#123Smart Online Order for Clover241,7461,2461k+Text Domain Mismatch
#124CRM Perks Forms – WordPress Form Builder248195771k+Output is not escaped
#125DSGVO All in one for WP24751,63720k+Non-prefixed global variable
#126Easy Modal245642997k+Unsafe printing function
#127Etsy Integration For WooCommerce241,2464,643900Non-prefixed global variable
#128Football Pool241,0857331k+Output is not escaped
#129Simple Calendar – Google Calendar Plugin242,05359250k+Missing direct file access protection
#130HT Mega Addons for Elementor – Elementor Widgets & Template Builder2410,89444070k+Text Domain Mismatch
#131Hummingbird Performance – Cache & Page Speed Optimization for Core Web Vitals | Critical CSS | Minify CSS | Defer CSS Javascript | CDN243,41086670k+Text Domain Mismatch
#132InstaWP Connect – 1-click WP Staging & Migration2425381140k+Non-prefixed global variable
#133Joli Table Of Contents246531,7557k+Non-prefixed global variable
#134Mang Board WP241,2494,7209k+Non-prefixed global variable
#135Media Library Folders2488980710k+Text Domain Mismatch
#136NEX-Forms – Ultimate Forms Plugin for WordPress242,0081,1956k+Text Domain Mismatch
#137Participants Database249518947k+SQL query is not prepared
#138PDF for Gravity Forms + Drag And Drop Template Builder241,457260400wp function not compatible with requires wp
#139PeproDev Ultimate Invoice243792344k+Output is not escaped
#140Database Manager – WP Adminer241,0052,75220k+Non-prefixed global variable
#141Post Status Notifier Lite24984451700Missing direct file access protection
#142Product Catalog Simple241,5551,9821k+Output is not escaped
#143Post Affiliate Pro24293335500Nonce verification recommended
#144SEO Engine – Smart SEO with AI, Schema & Redirection for WordPress242393041k+Direct Query
#145ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization2492632210k+Output is not escaped
#146SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery248311,9034k+Non-prefixed global variable
#147Sunshine Photo Cart – Client Photo Gallery & Photo Proofing for Photographers243601,4721k+Nonce verification recommended
#148Unlimited Elements For Elementor247102,093300k+Non-prefixed global variable
#149VikRentItems Flexible Rental Management System244,7554,639600Non-prefixed global variable
#150EU VAT Assistant for WooCommerce241,7424955k+Non Singular String Literal Domain