Rank Tools Security & Risk Analysis

wordpress.org/plugins/ranktool

Check any numbers of domain ranking from a page.

10 active installs v1.0 PHP + WP 3.2.1+ Updated Oct 30, 2013
ranking-checksandeveloperseo-tools
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Rank Tools Safe to Use in 2026?

Generally Safe

Score 85/100

Rank Tools has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The RankTool v1.0 plugin exhibits a generally good security posture based on the provided static analysis. The plugin utilizes prepared statements for all SQL queries, and a high percentage of output is properly escaped, which are strong indicators of secure coding practices. The absence of known CVEs and recorded vulnerability history further contributes to this positive assessment. The attack surface appears minimal, with no AJAX handlers or REST API routes found, and the single shortcode is not explicitly listed as unprotected.

However, there are significant concerns that temper the overall good impression. The most glaring issue is the complete lack of nonce checks and capability checks. This means that any user, regardless of their role or permissions, could potentially trigger the functionality associated with the shortcode. While the current static analysis did not reveal any critical or high-severity taint flows, the absence of proper authorization checks creates a substantial risk. Any sensitive operation exposed through the shortcode could be exploited by unauthorized users.

In conclusion, while the plugin demonstrates commendable practices in SQL and output handling, the complete omission of nonce and capability checks represents a critical security weakness. This oversight opens the door to potential unauthorized actions and could lead to security vulnerabilities if the shortcode's functionality involves sensitive operations or data manipulation. The lack of past vulnerabilities might be due to the limited attack surface or the relative simplicity of the current functionality, rather than a consistent pattern of robust security.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
  • 88% output escaping (2% not escaped)
Vulnerabilities
None known

Rank Tools Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Rank Tools Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
6 prepared
Unescaped Output
3
22 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
6
Bundled Libraries
0

SQL Query Safety

100% prepared6 total queries

Output Escaping

88% escaped25 total outputs
Attack Surface

Rank Tools Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[RANKING-TOOL] ranktool.php:38
WordPress Hooks 1
actionadmin_menuranktool.php:13
Maintenance & Trust

Rank Tools Maintenance & Trust

Maintenance Signals

WordPress version tested3.7.41
Last updatedOct 30, 2013
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Rank Tools Developer Profile

santosh Mahato

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Rank Tools

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Shortcode Output
[RANKING-TOOL]
FAQ

Frequently Asked Questions about Rank Tools