N0WPScan Security & Risk Analysis

wordpress.org/plugins/n0wpscan

Secure your Wordpress of WPScan Prevent hackers using WPScan to find vulnerabilities in your site, disable this plugin when you are security testing o …

40 active installs v5.6 PHP + WP 5.2+ Updated Jan 15, 2020
firewallhackersscanningsecuritywpscan
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is N0WPScan Safe to Use in 2026?

Generally Safe

Score 85/100

N0WPScan has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The n0wpscan v5.6 plugin exhibits a very strong security posture based on the provided static analysis and vulnerability history. The complete absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the plugin's attack surface, with no unprotected entry points detected. The code signals also indicate good practices, with no dangerous functions or file operations, and all SQL queries utilizing prepared statements. The sole capability check suggests intentional access control, and the 50% output escaping, while not perfect, is a reasonable level given the limited number of outputs. The taint analysis revealing no flows with unsanitized paths further reinforces the plugin's security. The vulnerability history is equally impressive, with no known CVEs recorded, indicating a history of secure development and maintenance. While the lack of any recorded vulnerabilities is a significant strength, the minimal number of outputs (4) and the fact that only 50% are properly escaped could be a minor area for review if the plugin were to expand its functionality. Overall, n0wpscan v5.6 appears to be a very secure plugin with minimal to no exploitable vulnerabilities based on this analysis.

Key Concerns

  • Unescaped output detected
Vulnerabilities
None known

N0WPScan Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

N0WPScan Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
2 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

50% escaped4 total outputs
Attack Surface

N0WPScan Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionwp_dashboard_setupN0WPScan.php:57
actioninitN0WPScan.php:99
actiondo_robotsN0WPScan.php:127
filterwp_xmlrpc_server_classN0WPScan.php:143
filterthe_generatorN0WPScan.php:153
filterrewrite_rulesN0WPScan.php:160
actioninitN0WPScan.php:344
Maintenance & Trust

N0WPScan Maintenance & Trust

Maintenance Signals

WordPress version tested
Last updatedJan 15, 2020
PHP min version
Downloads4K

Community Trust

Rating80/100
Number of ratings2
Active installs40
Developer Profile

N0WPScan Developer Profile

GeekParadize

1 plugin · 40 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect N0WPScan

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/n0wpscan/nowpscan.png

HTML / DOM Fingerprints

HTML Comments
<!-- <!--
FAQ

Frequently Asked Questions about N0WPScan