
Custonis – Security Exposure Scanner Security & Risk Analysis
wordpress.org/plugins/custonis-security-exposure-scannerDetect publicly exposed backup files, debug logs and sensitive data on your WordPress site.
Is Custonis – Security Exposure Scanner Safe to Use in 2026?
Generally Safe
Score 100/100Custonis – Security Exposure Scanner has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "custonis-security-exposure-scanner" v1.1.4 plugin exhibits a generally good security posture with notable strengths in its handling of SQL queries and output escaping. The vast majority of SQL queries utilize prepared statements, and over 96% of output is properly escaped, significantly mitigating risks related to SQL injection and cross-site scripting (XSS). The plugin also demonstrates awareness of WordPress security best practices with the inclusion of nonce and capability checks. However, a significant concern arises from the presence of an unprotected AJAX handler. This direct entry point into the plugin's functionality without proper authentication or authorization could be exploited by unauthenticated users to trigger unintended actions or potentially gain information. The limited taint analysis, while showing no critical or high-severity flows, should be viewed in conjunction with the unprotected AJAX handler, as this unprotected entry point could potentially be a vector for such flows if not carefully developed.
The plugin's vulnerability history is currently clean, with no recorded CVEs. This indicates a positive track record so far, suggesting the developers are either proactive in addressing vulnerabilities or have not yet encountered any significant security flaws. While this is encouraging, it should not lead to complacency, especially given the identified unprotected AJAX handler. The presence of dangerous functions like `set_time_limit` and `ini_set` is a minor concern that warrants careful review of their implementation to ensure they are not being used in a way that could be abused or negatively impact server performance.
In conclusion, the plugin has strong fundamentals in secure coding practices, particularly concerning data handling. The primary weakness lies in the unprotected AJAX handler, which represents a direct and exploitable attack surface. The absence of historical vulnerabilities is a positive indicator but does not negate the risks posed by the current code. Further investigation into the specific functionality of the unprotected AJAX handler is recommended to fully assess its impact.
Key Concerns
- Unprotected AJAX handler
- Use of dangerous functions (set_time_limit, ini_set)
Custonis – Security Exposure Scanner Security Vulnerabilities
Custonis – Security Exposure Scanner Release Timeline
Custonis – Security Exposure Scanner Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Custonis – Security Exposure Scanner Attack Surface
AJAX Handlers 2
WordPress Hooks 7
Scheduled Events 1
Maintenance & Trust
Custonis – Security Exposure Scanner Maintenance & Trust
Maintenance Signals
Community Trust
Custonis – Security Exposure Scanner Alternatives
Track Debug
track-debug
Track Debug is a WordPress debugging, performance monitoring, plugin analytics, page speed, memory usage, uptime check, security risk, WooCommerce deb …
Wordfence Security – Firewall, Malware Scan, and Login Security
wordfence
Firewall, Malware Scanner, Two Factor Auth, and Comprehensive Security Features, powered by our 24-hour team. Make security a priority with Wordfence.
Security Optimizer – The All-In-One Protection Plugin
sg-security
Secure your WordPress site from brute-force attacks, threats, malware, and bots. Free to use and easy to set up.
MalCare WordPress Security Plugin – Malware Scanner, Cleaner, Security Firewall
malcare-security
Get Bulletproof Security for your WordPress site. WordPress security plugin packed with comprehensive Firewall, malware scanner, cleaner & more.
Anti-Malware Security and Brute-Force Firewall
gotmls
This Anti-Malware scanner searches for Malware, Viruses, and other security threats and vulnerabilities on your server and it helps you fix them.
Custonis – Security Exposure Scanner Developer Profile
1 plugin · 0 total installs
How We Detect Custonis – Security Exposure Scanner
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/custonis-security-exposure-scanner/assets/css/custonis-admin.css/wp-content/plugins/custonis-security-exposure-scanner/assets/js/custonis-admin.js/wp-content/plugins/custonis-security-exposure-scanner/assets/js/custonis-scan-status.js/wp-content/plugins/custonis-security-exposure-scanner/assets/js/custonis-admin.js/wp-content/plugins/custonis-security-exposure-scanner/assets/js/custonis-scan-status.jscustonis-security-exposure-scanner/assets/css/custonis-admin.css?ver=custonis-security-exposure-scanner/assets/js/custonis-admin.js?ver=custonis-security-exposure-scanner/assets/js/custonis-scan-status.js?ver=HTML / DOM Fingerprints
custonis-admin-wrapcustonis-scan-progress-bar<!-- Custonis Security Exposure Scanner --><!-- Custonis: Security Exposure Scanner --><!-- Custonis Security Exposure Scanner: Scan Status --><!-- Custonis Security Exposure Scanner: Scan Results -->data-custonis-scan-status-urldata-custonis-scan-noncecustonisScanStatuscustonisScanNonce/wp-json/custonis/v1/scan/status/wp-json/custonis/v1/scan/run