
Plugin Security Scanner Security & Risk Analysis
wordpress.org/plugins/plugin-security-scannerThis plugin alerts you if any of your plugins have security vulnerabilities. It does this by utilising the WPScan Vulnerability Database once a day.
Is Plugin Security Scanner Safe to Use in 2026?
Use With Caution
Score 63/100Plugin Security Scanner has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The plugin-security-scanner v2.0.2 exhibits a mixed security posture. On the positive side, the static analysis reveals no obvious critical vulnerabilities like dangerous functions, file operations, or external HTTP requests. SQL queries are all handled with prepared statements, which is a strong practice. Taint analysis also shows no concerning unsanitized flows. However, a significant concern arises from its vulnerability history, with one unpatched medium severity CVE related to Cross-site Scripting. The fact that this vulnerability is recent and unpatched suggests a potential ongoing risk that users need to be aware of.
The static analysis also flags some areas for improvement. While the attack surface is reported as zero unprotected entry points, the output escaping is only at 33% proper, which is a notable weakness. This indicates that some user-supplied data might not be sufficiently neutralized before being displayed, potentially leading to XSS vulnerabilities if not properly handled by the theme or other plugins. The presence of a capability check is good, but the absence of nonce checks on any potential entry points, although currently reported as zero, is a point to monitor. The single cron event also warrants a closer look to ensure its execution is secured.
In conclusion, the plugin has strengths in its handling of SQL and its lack of overtly dangerous code patterns. However, the unpatched XSS vulnerability and the low percentage of properly escaped output are significant weaknesses that demand attention. Users should prioritize patching the known CVE and developers should focus on improving output sanitization to mitigate XSS risks.
Key Concerns
- Unpatched medium severity CVE
- Low percentage of properly escaped output
Plugin Security Scanner Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Plugin Security Scanner <= 2.0.2 - Authenticated (Administrator+) Stored Cross-Site Scripting
Plugin Security Scanner Code Analysis
Output Escaping
Plugin Security Scanner Attack Surface
WordPress Hooks 4
Scheduled Events 1
Maintenance & Trust
Plugin Security Scanner Maintenance & Trust
Maintenance Signals
Community Trust
Plugin Security Scanner Alternatives
MalCare WordPress Security Plugin – Malware Scanner, Cleaner, Security Firewall
malcare-security
Get Bulletproof Security for your WordPress site. WordPress security plugin packed with comprehensive Firewall, malware scanner, cleaner & more.
BulletProof Security
bulletproof-security
WordPress Security Protection: Malware scanner, Firewall, Login Security, DB Backup, Anti-Spam...
Bang Vulnerability Scanner
bang-vulnerability-scanner
Reports if your WordPress site has any known vulnerabilities.
Simple WP Vulnerability Watcher
simple-wp-vulnerability-watcher
Real-time monitoring of WordPress core, themes, and plugins for known vulnerabilities.
Safe Headers Scanner
safe-headers-scanner
Scan themes and plugins for potential header issues such as whitespace before/after PHP tags or direct output before headers.
Plugin Security Scanner Developer Profile
4 plugins · 920 total installs
How We Detect Plugin Security Scanner
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/plugin-security-scanner/plugin-security-scanner.phpHTML / DOM Fingerprints
wrapname="plugin-security-scanner[api_token]"name="plugin-security-scanner[email_notification]"name="plugin-security-scanner[webhook_notification]"name="plugin-security-scanner[webhook_notification_url]"