@ Chris
(italics are quotes from your last reply, just for clarification, nothing more)
Sorry, still disagree. “And like I said with the plugin pulling the info they can simply pass through the plugin>database/database>plugin.” Where do you think this info is coming from? This info is supplied by WordPress/PHP. A plugin is not needed to hand serve up to the minute server config. The data Connections shows actually contains no server config info. Examples of server config being the Apache conf files, htaccess files, and maybe even php.ini files. There’s actually quite a few files beyond those for server config. If “the hacker has to find loop holes in any of the plugins”. The hacker would very likely already know far, far, more info than the few basics than are presented in the widget.
Many plugins far more popular than Connections show a whole heck of a lot more and in some cases do stuff that is able to alter the WordPress configuration. A few quick example off the top of my head…
WordPress SEO by Yoast includes a htaccess file editor.
Wordpress includes a plugin and theme editor.
Easy Digital Downloads has a screen chock-full of info.
BackupBuddy, now there system info tool that is of envy, details galore. One can even manipulate the db (check/repair) and crons.
If it were best practice not to have this, trust me, it would not exist in Connections. But I have not read one article anywhere in the WP community that thinks this is a bad idea.
I really do thank you for pointing this out and why this concerns you. I do value constructive feedback and the time it takes to write it. It really is nice to have eyes looking at it from a different angle, so again, thanks!
