Scalenut Security & Risk Analysis

wordpress.org/plugins/scalenut

Effortlessly boost your SEO with Scalenut's Content Optimizer for WordPress.

40 active installs v1.1.5 PHP 8.2+ WP 6.7+ Updated Feb 16, 2026
blog-optimizationcontent-optimizereditorscalenutseo
78
B · Generally Safe
CVEs total1
Unpatched1
Last CVEJan 20, 2026
Download
Safety Verdict

Is Scalenut Safe to Use in 2026?

Mostly Safe

Score 78/100

Scalenut is generally safe to use. 1 past CVE were resolved.

1 known CVE 1 unpatched Last CVE: Jan 20, 2026Updated 3mo ago
Risk Assessment

The Scalenut plugin v1.1.5 exhibits a generally good security posture based on the static analysis, with a strong emphasis on secure coding practices. The plugin demonstrates excellent adherence to output escaping (97%), avoids dangerous functions, and correctly uses prepared statements for all SQL queries. The presence of nonce and capability checks on its single AJAX handler is also a positive indicator. However, the existence of a known, currently unpatched medium severity vulnerability is a significant concern that overrides some of the positive findings. This indicates a potential for exploitation that has not yet been addressed by the developers.

The static analysis reveals a very small attack surface, with only one entry point (an AJAX handler) which is confirmed to have authorization checks. The absence of any taint analysis findings or critical/high severity code signals further suggests a well-written codebase in terms of immediate exploitability through common code injection vectors. Despite these strengths, the single unpatched vulnerability, classified as medium severity and historically a 'Missing Authorization' type, suggests a recurring pattern of authorization flaws that users should be aware of.

In conclusion, while Scalenut v1.1.5 benefits from robust secure coding practices in its static composition, the single unpatched medium severity vulnerability necessitates caution. This indicates a need for diligent patching by users and suggests that the developers should prioritize addressing authorization-related security weaknesses in future releases to maintain a strong security posture.

Key Concerns

  • Unpatched medium severity CVE
Vulnerabilities
1 published

Scalenut Security Vulnerabilities

CVEs by Year

1 CVE in 2026 · unpatched
2026
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-68882medium · 5.3Missing Authorization

Scalenut <= 1.1.3 - Missing Authorization

Jan 20, 2026Unpatched
Version History

Scalenut Release Timeline

v1.1.41 CVE
v1.1.31 CVE
v1.1.21 CVE
v1.1.11 CVE
v1.1.01 CVE
v1.0.21 CVE
v1.0.11 CVE
Code Analysis
Analyzed Mar 16, 2026

Scalenut Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
29 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Guzzle

Output Escaping

97% escaped30 total outputs
Attack Surface

Scalenut Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_scnt_disconnectincludes\scnt-admin-menu.php:23
WordPress Hooks 8
actionadmin_menuincludes\scnt-admin-menu.php:21
actionadmin_enqueue_scriptsincludes\scnt-admin-menu.php:22
actionrest_api_initincludes\scnt-api-handler.php:21
actionadmin_noticesscalenut.php:103
actionadmin_noticesscalenut.php:106
actionshutdownscalenut.php:136
actioninitscalenut.php:209
actionadmin_enqueue_scriptsscalenut.php:210
Maintenance & Trust

Scalenut Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedFeb 16, 2026
PHP min version8.2
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs40
Developer Profile

Scalenut Developer Profile

Scalenut

1 plugin · 40 total installs

79
trust score
Avg Security Score
78/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Scalenut

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/scalenut/includes/css/scnt-global.css
Version Parameters
scalenut/includes/css/scnt-global.css?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Scalenut