
Eli's PHP Compatibility Scanner Security & Risk Analysis
wordpress.org/plugins/eli-php-compatibility-scannerA comprehensive WordPress plugin that scans your plugins and themes for PHP version compatibility issues using the PHPCompatibility ruleset.
Is Eli's PHP Compatibility Scanner Safe to Use in 2026?
Generally Safe
Score 100/100Eli's PHP Compatibility Scanner has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "eli-php-compatibility-scanner" plugin version 1.1.1 exhibits a mixed security posture. On the positive side, it demonstrates good practices in output escaping, SQL query preparation, and has no recorded historical vulnerabilities. This suggests a commitment to secure coding principles in these areas.
However, significant concerns arise from the static analysis. The plugin exposes 9 AJAX handlers with no authentication or capability checks, representing a substantial attack surface with direct entry points. Furthermore, taint analysis reveals 3 flows with unsanitized paths, including 2 critical severity issues, indicating potential for sensitive data to be manipulated or exposed. The presence of 3 dangerous function calls (exec) also raises a red flag, especially when combined with the unprotected AJAX endpoints.
While the lack of known CVEs is reassuring, it does not negate the critical risks identified in the current code analysis. The high number of unprotected AJAX handlers and critical taint flows, coupled with the use of dangerous functions, presents a clear and present danger. The plugin requires immediate attention to address these security weaknesses.
Key Concerns
- Unprotected AJAX handlers
- Critical severity taint flows
- Dangerous function calls (exec)
- Flows with unsanitized paths
Eli's PHP Compatibility Scanner Security Vulnerabilities
Eli's PHP Compatibility Scanner Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Eli's PHP Compatibility Scanner Attack Surface
AJAX Handlers 9
WordPress Hooks 3
Maintenance & Trust
Eli's PHP Compatibility Scanner Maintenance & Trust
Maintenance Signals
Community Trust
Eli's PHP Compatibility Scanner Alternatives
FakerPress
fakerpress
FakerPress is a clean way to generate fake and dummy content to your WordPress, great for developers who need testing
Unbounce Landing Pages
unbounce
Unbounce is the most powerful standalone landing page builder available.
Plugin Compatibility Checker
plugin-compatibility-checker
Scan and check your plugins for PHP and WordPress compatibility. Requires a $1/month Portal subscription to obtain a license key.
Plugin Check (PCP)
plugin-check
Plugin Check is a WordPress.org tool which provides checks to help plugins meet the directory requirements and follow various best practices.
Instapage Plugin
instapage
Instapage plugin - the best way for WordPress to seamlessly publish landing pages as a natural extension of your WordPress blog or website.
Eli's PHP Compatibility Scanner Developer Profile
2 plugins · 110 total installs
How We Detect Eli's PHP Compatibility Scanner
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/eli-php-compatibility-scanner/assets/dist/admin.css/wp-content/plugins/eli-php-compatibility-scanner/assets/dist/admin.js/wp-content/plugins/eli-php-compatibility-scanner/assets/dist/admin.jseli-php-compatibility-scanner/assets/dist/admin.css?ver=eli-php-compatibility-scanner/assets/dist/admin.js?ver=HTML / DOM Fingerprints
PHPCompatChecker