atec Dir Scan Security & Risk Analysis

wordpress.org/plugins/atec-dir-scan

atec Dir Scan & Statistics (Number of files and size per directory)

40 active installs v1.4.29 PHP 7.4+ WP 4.9+ Updated Jan 8, 2026
including-file-count-and-file-sizenavigate-through-the-whole-directory-tree-of-your-wp-installation
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is atec Dir Scan Safe to Use in 2026?

Generally Safe

Score 100/100

atec Dir Scan has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The 'atec-dir-scan' plugin v1.4.29 presents a mixed security profile. On the positive side, it demonstrates strong adherence to secure coding practices by utilizing prepared statements for all SQL queries and ensuring nearly all output is properly escaped. The absence of known vulnerabilities and common vulnerability types in its history is a significant strength, suggesting a relatively stable and well-maintained codebase. Furthermore, the plugin does not bundle any external libraries, mitigating risks associated with outdated dependencies.

However, a significant concern arises from the plugin's attack surface. It exposes one AJAX handler that lacks authentication checks. This unprotected entry point could potentially be exploited by unauthenticated users to interact with the plugin in unintended ways, leading to information disclosure or even more severe consequences if the AJAX handler performs sensitive operations. The static analysis did not reveal any critical or high-severity taint flows, which is reassuring, but the presence of an unprotected AJAX handler remains a critical oversight.

In conclusion, while 'atec-dir-scan' v1.4.29 excels in areas like SQL handling and output escaping, and has a clean vulnerability history, the single unprotected AJAX handler is a notable weakness. This single point of potential compromise significantly elevates the risk profile, requiring immediate attention and remediation.

Key Concerns

  • AJAX handler without authentication
Vulnerabilities
None known

atec Dir Scan Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

atec Dir Scan Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
264 escaped
Nonce Checks
2
Capability Checks
5
File Operations
14
External Requests
1
Bundled Libraries
0

Output Escaping

99% escaped266 total outputs
Attack Surface
1 unprotected

atec Dir Scan Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_atec_admin_notice_dismissincludes\ATEC\LOADER.php:109
WordPress Hooks 6
actionadmin_menuatec-dir-scan.php:29
actionadmin_enqueue_scriptsincludes\ATEC\INIT.php:564
actionadmin_noticesincludes\ATEC\INIT.php:647
actionadmin_footerincludes\ATEC\INIT.php:688
actionadmin_noticesincludes\ATEC\INIT.php:720
actionadmin_enqueue_scriptsincludes\atec-wpds-install.php:6
Maintenance & Trust

atec Dir Scan Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 8, 2026
PHP min version7.4
Downloads5K

Community Trust

Rating100/100
Number of ratings2
Active installs40
Alternatives

atec Dir Scan Alternatives

No alternatives data available yet.

Developer Profile

atec Dir Scan Developer Profile

docjojo

16 plugins · 3K total installs

99
trust score
Avg Security Score
99/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect atec Dir Scan

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/atec-dir-scan/includes/ATEC/js/menu-toggle.js/wp-content/plugins/atec-dir-scan/includes/ATEC/css/admin-menu.css
Script Paths
/wp-content/plugins/atec-dir-scan/includes/ATEC/js/menu-toggle.js
Version Parameters
atec-dir-scan/includes/ATEC/js/menu-toggle.js?ver=atec-dir-scan/includes/ATEC/css/admin-menu.css?ver=

HTML / DOM Fingerprints

CSS Classes
atec-admin-bar-row
Data Attributes
data-atec-slugdata-atec-actiondata-atec-nav
JS Globals
atec_wpds_ajax_cb
REST Endpoints
/wp-json/atec-dir-scan/v1/scan
FAQ

Frequently Asked Questions about atec Dir Scan