
Scanfully Security & Risk Analysis
wordpress.org/plugins/scanfullyScanfully is your favorite WordPress performance and site health monitoring tool.
Is Scanfully Safe to Use in 2026?
Generally Safe
Score 100/100Scanfully has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of "scanfully" v1.3.1 reveals a generally strong security posture with no identified critical or high-severity issues in code signals or taint analysis. The plugin adheres to several security best practices, including using prepared statements for all SQL queries and properly escaping all output. The absence of file operations and external HTTP requests further minimizes the attack surface. However, the presence of 2 cron events and 2 nonce checks, while not immediately indicative of vulnerabilities, represent potential areas that would require careful review if these events or checks were to interact with user-supplied data in future versions. The vulnerability history being entirely clear is a significant positive indicator, suggesting a well-maintained and secure plugin to date.
Despite the clean slate, it's important to note that the static analysis did not include taint flows, which means potential vulnerabilities related to data manipulation might have been missed. The limited number of entry points (0 unprotected) is excellent, but the presence of 2 cron events warrants attention for any future development or modifications. The plugin's strengths lie in its proper handling of database queries and output, and its lack of a past vulnerability record. The main area for caution is the potential for undiscovered taint flows and the need for ongoing vigilance with its cron events.
Scanfully Security Vulnerabilities
Scanfully Release Timeline
Scanfully Code Analysis
SQL Query Safety
Output Escaping
Scanfully Attack Surface
WordPress Hooks 12
Scheduled Events 2
Maintenance & Trust
Scanfully Maintenance & Trust
Maintenance Signals
Community Trust
Scanfully Alternatives
Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity
logtivity
Logtivity is the activity log service for WordPress admins. Logtivity is a unified activity log platform that tracks activity and errors across all yo …
Talking Monkey Insights
tm-insights
Site health snapshot and REST monitoring API. Auto-detects WordFence/Defender, UpdraftPlus/Snapshot. Built for agencies running multiple sites.
Health Monitor
health-monitor
Health Monitor is designed to help you keep your website running smoothly. It continuously checks your site’s performance, security, and overall healt …
Unstoppable Activity Tracker
unstoppable-activity-tracker
Standalone activity tracker. Records site events to a local database table and exposes them via a secure, API-key-protected REST endpoint.
AVAR Server Monitor
avar-server-monitor
Privacy-first WordPress monitoring: uptime, SSL, cron and server checks, a Site Health score and an alert center, plus login protection.
Scanfully Developer Profile
1 plugin · 100 total installs
How We Detect Scanfully
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/scanfully/assets/css/admin.css/wp-content/plugins/scanfully/assets/css/not-connected-notice.cssscanfully/assets/css/not-connected-notice.css?ver=scanfully/assets/css/admin.css?ver=HTML / DOM Fingerprints
scanfully-not-connected-noticescanfully-notice-headerscanfully-notice-logoscanfully-secure-setup-wrapperscanfully-setup-logoscanfully-connect-noticesscanfully-setup-contentscanfully-connect-details+6 moredata-scanfully-connect-install