Scoop.it for Jetpack Security & Risk Analysis

wordpress.org/plugins/scoopit-for-jetpack

Add a Scoop.it button to the Jetpack Sharing module

30 active installs v1.2 PHP + WP 3.9+ Updated Dec 8, 2016
jetpackscoop-itscoopitsharingwordpress-com
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Scoop.it for Jetpack Safe to Use in 2026?

Generally Safe

Score 85/100

Scoop.it for Jetpack has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The scoopit-for-jetpack plugin, version 1.2, exhibits a strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the potential attack surface. Furthermore, the code signals indicate a conscientious development approach with no dangerous functions, all SQL queries using prepared statements, and no file operations or external HTTP requests, which are all positive indicators of secure coding practices.

However, there are notable areas of concern. The most significant finding is that 100% of the output is not properly escaped. This means that any data displayed by the plugin that originates from user input or external sources is vulnerable to Cross-Site Scripting (XSS) attacks. The lack of nonce checks and capability checks on entry points, coupled with zero authorization checks on any identified entry points (though there are none identified), leaves the plugin's data and functionality potentially exposed if new entry points were to be introduced in future versions without proper security considerations.

The vulnerability history is completely clean, with no recorded CVEs. This suggests a history of stable and secure development or a lack of focused security auditing on this specific plugin in the past. While this is a positive sign, it should not be a reason to overlook the critical issue of unescaped output. The plugin's strengths lie in its limited attack surface and good internal coding practices for data handling (SQL). The primary weakness is the lack of output escaping, which presents a clear and present XSS risk.

Key Concerns

  • All output is unescaped
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Scoop.it for Jetpack Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Scoop.it for Jetpack Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped2 total outputs
Attack Surface

Scoop.it for Jetpack Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionplugins_loadedscoopit-for-jetpack.php:26
actionadmin_noticesscoopit-for-jetpack.php:28
filtersharing_servicesscoopit-for-jetpack.php:33
Maintenance & Trust

Scoop.it for Jetpack Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.32
Last updatedDec 8, 2016
PHP min version
Downloads5K

Community Trust

Rating100/100
Number of ratings2
Active installs30
Developer Profile

Scoop.it for Jetpack Developer Profile

Jeremy Herve

11 plugins · 2K total installs

90
trust score
Avg Security Score
94/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Scoop.it for Jetpack

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Scoop.it for Jetpack