WordPress.PHP.DevelopmentFunctions.prevent_path_disclosure_error_reporting

prevent path disclosure error reporting

Development or debugging behavior appears in code that may run in production.

medium weight

Why It Shows Up

The scan found logging, debugging, path disclosure, `phpinfo()`, error-reporting changes, or similar development-oriented functions.

Why It Matters

Debug output can leak paths, configuration, request data, stack details, or sensitive runtime information.

How to Fix

  • Remove temporary debugging calls before release.
  • If logging is required, guard it with `WP_DEBUG` or a plugin setting intended for administrators.
  • Never show debug details to unauthenticated visitors or normal front-end users.

Affected Plugins

RankPluginScoreErrorsWarningsInstallsUpdatedTop Issue
#1BulletProof Security05,0484,94920k+2026-05-20Output Not Escaped
#2JetBackup – Backup, Restore & Migrate101,559145100k+2026-05-03Exception Not Escaped
#3Prime Slider Addons for Elementor183,500230100k+2026-06-15Text Domain Mismatch
#4Download Monitor194251,36480k+2026-06-16Non Prefixed Hookname Found
#5Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution191,218901100k+2026-06-09Exception Not Escaped
#6Matomo Analytics – Powerful, Privacy-First Insights for WordPress191,909878100k+2026-06-16Exception Not Escaped
#7GiveWP – Donation Plugin and Fundraising Platform203,4353,580100k+2026-06-15Output Not Escaped
#8Microthemer Lite – Visual Editor to Customize CSS201,0041,69910k+2026-04-15Non Prefixed Variable Found
#9Razorpay for WooCommerce20974855100k+2026-06-19Non Prefixed Function Found
#10Store Locator WordPress212,3721,57210k+2026-06-03Text Domain Mismatch
#11Backup Migration219811,09380k+2026-06-05Non Prefixed Variable Found
#12Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More212,5721,2771m+2026-05-22Output Not Escaped
#13FileOrganizer – WordPress File Manager21536241200k+2026-06-10unlink unlink
#14Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages211,1732,9839k+2026-06-02Non Prefixed Variable Found
#15Wordfence Security – Firewall, Malware Scan, and Login Security211,5922,9735m+2026-05-13Output Not Escaped
#16WP phpMyAdmin214,5286,43550k+2025-10-17Missing Arg Domain
#17Booking for Appointments and Events Calendar – Amelia221,48948090k+2026-06-18Exception Not Escaped
#18Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots221,6042,01910k+2026-06-10Direct Query
#19Directorist: AI-Powered Business Directory, Listings & Classified Ads224432,12920k+2026-06-09Non Prefixed Variable Found
#20Download Manager222,2901,301100k+2026-06-16Output Not Escaped
#21File Manager Pro – Filester22565391100k+2026-05-23Missing Unslash
#22GeoDirectory – WP Business Directory Plugin and Classified Listings Directory224,4623,97210k+2026-06-10Output Not Escaped
#23Anti-Malware Security and Brute-Force Firewall22544965100k+2026-03-09Output Not Escaped
#24InfiniteWP Client222,2861,812200k+2026-02-26Exception Not Escaped
#25Molongui Authorship – Author Boxes, Guest Authors & Co-Authors for WordPress229191,23010k+2026-02-16Output Not Escaped
#26NinjaFirewall (WP Edition) – Advanced Security Plugin and Firewall221,2652,065100k+2026-06-07Non Prefixed Variable Found
#27Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App221,5812,326300k+2026-06-03Non Prefixed Variable Found
#28Seraphinite Accelerator2259425550k+2026-06-19Output Not Escaped
#29NextScripts: Social Networks Auto-Poster222,4081,13330k+2026-02-26Output Not Escaped
#30Search & Replace Everything – Quick and Easy Way to Find and Replace Text, Links221,0441,79720k+2026-05-27Non Prefixed Variable Found
#31URL Shortify – Simple and Easy URL Shortener221,5202,68910k+2026-06-04Non Prefixed Variable Found
#32ManageWP Worker225075651m+2026-05-11Non Prefixed Class Found
#33File Manager227405201m+2026-04-21Unsafe Printing Function
#34WP Umbrella: Update Backup Restore & Monitoring2291590570k+2026-06-10Exception Not Escaped
#35WP Super Minify • Minify, Compress and Cache HTML, CSS & JavaScript221642579k+2026-05-24Non Prefixed Constant Found
#36YaySMTP – WP Mail SMTP with Email Logs, Tracking & Reports2265443510k+2026-06-16Exception Not Escaped
#37Advanced Contact form 7 DB237611,95970k+2026-04-20Non Prefixed Variable Found
#38Business Directory Plugin – Easy Listing Directories for WordPress236111,05810k+2026-05-19Non Prefixed Variable Found
#39IP Geo Block233995899k+2019-01-22Output Not Escaped
#40MailPoet – Newsletters, Email Marketing, and Automation23858711500k+2026-06-17Exception Not Escaped
#41MaxButtons – Create buttons2365540970k+2025-09-15Output Not Escaped
#42Media Library Assistant231,1443,94370k+2026-06-08Recommended
#43ND Shortcodes236212,42620k+2025-03-18Non Prefixed Variable Found
#44Postie2340726110k+2026-01-29Output Not Escaped
#45PowerPress Podcasting plugin by Blubrry234,8072,39420k+2026-06-17Output Not Escaped
#46Seriously Simple Podcasting2354862730k+2026-05-21Non Prefixed Hookname Found
#47UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP236952,43420k+2026-06-12Non Prefixed Hookname Found
#48Clone2324426240k+2025-10-30Output Not Escaped
#49WP Compress – Instant Performance & Speed Optimization233,0532,38410k+2026-04-15Non Singular String Literal Domain
#50404 Solution244831,08710k+2026-05-24Missing Unslash