
ScanCircle Security & Risk Analysis
wordpress.org/plugins/scancircleShortcode handler for the scan widget on ScanCircle partner websites.
Is ScanCircle Safe to Use in 2026?
Generally Safe
Score 99/100ScanCircle has a strong security track record. Known vulnerabilities have been patched promptly.
The "scancircle" plugin v2.9.3 demonstrates a generally strong security posture based on the static analysis. The absence of dangerous functions, proper SQL prepared statement usage, and 100% output escaping are commendable practices. Furthermore, the plugin exhibits no untainted flows and a limited attack surface with no immediately apparent unprotected entry points. This indicates a developer who is likely mindful of common web security vulnerabilities.
However, the vulnerability history presents a significant concern. The presence of a known medium-severity Cross-Site Scripting (XSS) vulnerability, even though currently patched, signals a potential weakness in input sanitization or output encoding, despite the static analysis reporting 100% output escaping. The fact that a vulnerability was discovered as recently as December 2024, even if patched, suggests that future vulnerabilities might be possible if coding practices are not consistently applied or if new attack vectors are discovered.
In conclusion, while the current static analysis of v2.9.3 is positive, the historical vulnerability data, specifically the medium-severity XSS, warrants a degree of caution. Developers should ensure continued rigorous security testing and adherence to secure coding practices to mitigate the risk of future exploitable flaws. The lack of nonce and capability checks on its entry points could also be a point of concern for more complex attack scenarios, though the low number of entry points mitigates this risk somewhat.
Key Concerns
- Past medium severity XSS vulnerability
- No nonce checks on entry points
- No capability checks on entry points
ScanCircle Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
ScanCircle <= 2.9.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
ScanCircle Code Analysis
Output Escaping
ScanCircle Attack Surface
Shortcodes 2
Maintenance & Trust
ScanCircle Maintenance & Trust
Maintenance Signals
Community Trust
ScanCircle Alternatives
Contact Form by BestWebSoft – Advanced WP Contact Form Builder for WordPress
contact-form-plugin
The most powerful and user-friendly WordPress contact form plugin. Create beautiful contact forms, widgets and pages using shortcodes.
resmio button & widget
resmio-button-and-widget
Resmio provides you with an online reservation system software for your restaurant that allows you to manage all reservations received in your restaur …
Dropcaps Shortcode and Widget
dropcaps-shortcodes-and-widget
Create Dropcaps. Nice and easy interface. Insert anywhere in your site - page/post editor, sidebars, template files.
Quotes Shortcode and Widget
quotes-shortcode-and-widget
Create Quotes. Nice and easy interface. Insert anywhere in your site - page/post editor, sidebars, template files.
Button Generator
button-generator-plugin
Easy and simple create booking, shopping cart, payment plugin code, just copy and paste to your website
ScanCircle Developer Profile
1 plugin · 60 total installs
How We Detect ScanCircle
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/scancircle/scancircle.js?plugin=WordPress2.9.3HTML / DOM Fingerprints
scancircle_buttonid="scancircle"id="scancircle_button"<div id="scancircle">
<a href="http<iframe src="