
BrightLeaf Digital PHP Compatibility Scanner Security & Risk Analysis
wordpress.org/plugins/brightleaf-digital-php-compatibility-scannerThis plugin scans your installed plugins and themes for potential PHP compatibility issues when upgrading to newer PHP versions.
Is BrightLeaf Digital PHP Compatibility Scanner Safe to Use in 2026?
Generally Safe
Score 100/100BrightLeaf Digital PHP Compatibility Scanner has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The brightleaf-digital-php-compatibility-scanner plugin version 1.0.1 demonstrates a generally strong security posture. The static analysis reveals no dangerous functions, all SQL queries utilize prepared statements, and there are no known CVEs associated with this plugin, suggesting a history of secure development. The presence of nonce and capability checks on its AJAX handlers is also a positive indicator, contributing to a secure attack surface.
However, a concern arises from the output escaping. With only 65% of outputs properly escaped, there is a risk of cross-site scripting (XSS) vulnerabilities. While no taint analysis flows were found with unsanitized paths, the incomplete output escaping means that user-supplied or dynamically generated data that reaches these unescaped outputs could be exploited.
Overall, the plugin is built on a solid foundation with good security practices in place, particularly concerning SQL injection and external threats. The primary area for improvement lies in ensuring all output is rigorously escaped to mitigate potential XSS risks. The lack of historical vulnerabilities is encouraging, but the current static analysis highlights a specific, addressable weakness.
Key Concerns
- Unescaped output detected
BrightLeaf Digital PHP Compatibility Scanner Security Vulnerabilities
BrightLeaf Digital PHP Compatibility Scanner Code Analysis
Output Escaping
BrightLeaf Digital PHP Compatibility Scanner Attack Surface
AJAX Handlers 5
WordPress Hooks 4
Maintenance & Trust
BrightLeaf Digital PHP Compatibility Scanner Maintenance & Trust
Maintenance Signals
Community Trust
BrightLeaf Digital PHP Compatibility Scanner Alternatives
Advanced Automatic Updates
automatic-updater
Adds extra options to WordPress' built-in Automatic Updates feature.
Plugin Compatibility Checker
plugin-compatibility-checker
Scan and check your plugins for PHP and WordPress compatibility. Requires a $1/month Portal subscription to obtain a license key.
KP Zip Downloader
kp-zip-downloader
This plugin allows administrators to download installed plugins and themes as ZIP files directly from the WordPress dashboard.
Export Plugins and Templates
export-plugins-and-templates
Export Plugins and Templates allows you to export any template or plugin already installed in your WordPress.
Plugin Security Scanner
plugin-security-scanner
This plugin alerts you if any of your plugins have security vulnerabilities. It does this by utilising the WPScan Vulnerability Database once a day.
BrightLeaf Digital PHP Compatibility Scanner Developer Profile
4 plugins · 100 total installs
How We Detect BrightLeaf Digital PHP Compatibility Scanner
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/brightleaf-digital-php-compatibility-scanner/build/php-compat-scanner.css/wp-content/plugins/brightleaf-digital-php-compatibility-scanner/build/php-compat-scanner.js/wp-content/plugins/brightleaf-digital-php-compatibility-scanner/build/php-compat-scanner.jsbrightleaf-digital-php-compatibility-scanner/build/php-compat-scanner.css?ver=brightleaf-digital-php-compatibility-scanner/build/php-compat-scanner.js?ver=HTML / DOM Fingerprints
php-compat-scanner-admin-pagephp-compat-scanner-plugin-row-badgedata-plugin-slugdata-scan-targetdata-scan-status-urldata-scan-cancel-urldata-scan-pause-urlbrightleaf_digital_php_checker_ajax_object/wp-json/brightleaf-digital-php-checker/v1/scan/wp-json/brightleaf-digital-php-checker/v1/scan-status/wp-json/brightleaf-digital-php-checker/v1/scan-cancel/wp-json/brightleaf-digital-php-checker/v1/scan-toggle-pause