Fullworks Security Scanner Security & Risk Analysis

wordpress.org/plugins/fullworks-scanner

Fullworks Security Scanner: Your Website's Guardian. Core, Themes, Plugins - Checked. Vulnerabilities - Squashed. Your Site - Secure.

20 active installs v1.3 PHP 7.4+ WP 5.0+ Updated Mar 3, 2025
malwarescanscannersecurity
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Fullworks Security Scanner Safe to Use in 2026?

Generally Safe

Score 92/100

Fullworks Security Scanner has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "fullworks-scanner" v1.3 plugin exhibits a generally strong security posture, with excellent adherence to output escaping and a significant portion of SQL queries utilizing prepared statements. The complete absence of known CVEs and a clean vulnerability history are positive indicators. However, the static analysis reveals a potential concern with a single taint flow identified as having an unsanitized path with high severity. While the attack surface is minimal and no critical issues were found in that area, this single high-severity taint flow warrants attention. The plugin also makes external HTTP requests, which, while not inherently insecure, can introduce risks if not handled with proper validation and sanitization on the receiving end. Overall, the plugin has good fundamental security practices but requires further investigation into the identified high-severity taint flow.

Key Concerns

  • High severity unsanitized path in taint flow
  • External HTTP requests made
Vulnerabilities
None known

Fullworks Security Scanner Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Fullworks Security Scanner Code Analysis

Dangerous Functions
0
Raw SQL Queries
5
14 prepared
Unescaped Output
0
63 escaped
Nonce Checks
10
Capability Checks
1
File Operations
0
External Requests
4
Bundled Libraries
0

SQL Query Safety

74% prepared19 total queries

Output Escaping

100% escaped63 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
<class-list-table-code-scan> (admin\class-list-table-code-scan.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Fullworks Security Scanner Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 19
actionadmin_enqueue_scriptsadmin\class-admin-pages.php:86
filterscreen_layout_columnsadmin\class-admin-pages.php:89
actionwpmu_new_blogfullworks-vulnerability-scanner.php:77
filterwpmu_drop_tablesfullworks-vulnerability-scanner.php:87
actionFULLWORKS_SCANNER_email_check_audit_completeincludes\class-audit-email.php:42
actionFULLWORKS_SCANNER_send_emailincludes\class-audit-email.php:43
actionFULLWORKS_SCANNER_get_current_pluginincludes\class-audit-plugin-code-scan.php:42
actionFULLWORKS_SCANNER_get_current_themeincludes\class-audit-theme-code-scan.php:54
actionFULLWORKS_SCANNER_check_vulndbincludes\class-audit-vulndb-scan.php:49
actionplugins_loadedincludes\class-core.php:117
actionadmin_menuincludes\class-core.php:134
filterset-screen-optionincludes\class-core.php:137
actionadmin_menuincludes\class-core.php:138
actionadmin_enqueue_scriptsincludes\class-core.php:154
actionadmin_enqueue_scriptsincludes\class-core.php:155
actionadmin_initincludes\class-core.php:156
actionupgrader_process_completeincludes\class-core.php:157
actioninitincludes\class-core.php:164
actionadmin_initincludes\class-core.php:165
Maintenance & Trust

Fullworks Security Scanner Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedMar 3, 2025
PHP min version7.4
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs20
Developer Profile

Fullworks Security Scanner Developer Profile

fullworks

13 plugins · 79K total installs

75
trust score
Avg Security Score
94/100
Avg Patch Time
1372 days
View full developer profile
Detection Fingerprints

How We Detect Fullworks Security Scanner

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/fullworks-scanner/assets/css/fullworks-scanner-admin.css/wp-content/plugins/fullworks-scanner/assets/css/fullworks-scanner-public.css/wp-content/plugins/fullworks-scanner/assets/js/fullworks-scanner-admin.js
Script Paths
/wp-content/plugins/fullworks-scanner/assets/js/fullworks-scanner-admin.js
Version Parameters
fullworks-scanner/assets/css/fullworks-scanner-admin.css?ver=fullworks-scanner/assets/css/fullworks-scanner-public.css?ver=fullworks-scanner/assets/js/fullworks-scanner-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
fullworks-scanner-settings
HTML Comments
<!-- WordPress core --><!-- WordPress core -->
Data Attributes
data-fullworks-scanner-nonce
JS Globals
fullworksScannerAdminfullworksScanner
REST Endpoints
/wp-json/fullworks-scanner/v1
FAQ

Frequently Asked Questions about Fullworks Security Scanner