
CyStack Security – Vulnerability Scanner & Security Monitoring Security & Risk Analysis
wordpress.org/plugins/cystack-securityCyStack Security constantly monitors your websites and servers to detect security issues and vulnerabilities.
Is CyStack Security – Vulnerability Scanner & Security Monitoring Safe to Use in 2026?
Generally Safe
Score 85/100CyStack Security – Vulnerability Scanner & Security Monitoring has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "cystack-security" v1.0.4 plugin presents a significant security risk due to its large, unprotected attack surface. All 12 AJAX handlers lack authentication checks, meaning any unauthenticated user can trigger these functions, potentially leading to unauthorized actions or information disclosure. While the code exhibits good practices in other areas like SQL query handling and output escaping (75% proper), the absence of proper authorization for such a substantial portion of its entry points overshadows these strengths. The lack of known vulnerabilities in its history is a positive indicator, suggesting past security diligence. However, the current state of the code, with its numerous unprotected AJAX endpoints, creates a critical security gap that could be easily exploited. Without immediate patching of these authorization flaws, the plugin remains highly vulnerable.
Key Concerns
- 12 unprotected AJAX handlers
- 1 nonce check, but 12 AJAX handlers unprotected
- 3 of 4 outputs not properly escaped
CyStack Security – Vulnerability Scanner & Security Monitoring Security Vulnerabilities
CyStack Security – Vulnerability Scanner & Security Monitoring Code Analysis
Output Escaping
CyStack Security – Vulnerability Scanner & Security Monitoring Attack Surface
AJAX Handlers 12
WordPress Hooks 4
Maintenance & Trust
CyStack Security – Vulnerability Scanner & Security Monitoring Maintenance & Trust
Maintenance Signals
Community Trust
CyStack Security – Vulnerability Scanner & Security Monitoring Alternatives
SecuSeek – Web Security Scanner & Vulnerability Assessment
secuseek
Professional web security scanning and vulnerability assessment plugin. Comprehensive security analysis, real-time threat detection, and detailed secu …
AntiVirus
antivirus
Security plugin to protect your blog or website against exploits and spam injections.
Malcure Malware Shield — Removal, Repair, Monitor
wp-malware-removal
Fast malware removal & security shield. Fix hacks, stop redirects, clean SEO spam. Real-time threat intelligence. No bloat.
WPScan – WordPress Security Scanner
wpscan
WPScan WordPress Security Scanner - Scans your system for security vulnerabilities listed in the WPScan Vulnerability Database.
SiteLock Security – WP Hardening, Login Security & Malware Scans
sitelock
Free, lightweight WordPress security. Harden your site with login protection & 2FA, see Site Health clearly and run on-demand checks—setup in minutes.
CyStack Security – Vulnerability Scanner & Security Monitoring Developer Profile
1 plugin · 10 total installs
How We Detect CyStack Security – Vulnerability Scanner & Security Monitoring
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cystack-security/assets/cystack.css/wp-content/plugins/cystack-security/assets/cystack-bridge.css/wp-content/plugins/cystack-security/js/dist/cystack.js/wp-content/plugins/cystack-security/js/dist/cystack.jscystack-csscystack-bridge-csscystack-jsHTML / DOM Fingerprints
cystackConfig/wp-json/cystack/v1/clear_meta/wp-json/cystack/v1/registration