Scotty Security & Risk Analysis

wordpress.org/plugins/scotty

Your WordPress engineer for superior site maintenance and optimization

0 active installs v1.1.2 PHP 7.4+ WP 6.2+ Updated Nov 15, 2024
cleanupcontroloptimized
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Scotty Safe to Use in 2026?

Generally Safe

Score 92/100

Scotty has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The 'scotty' plugin v1.1.2 demonstrates a strong security posture based on the provided static analysis and vulnerability history. The code exhibits excellent practices regarding SQL query preparation, with 83% of queries utilizing prepared statements, and a perfect record of 100% output escaping. Furthermore, the absence of file operations, external HTTP requests, and a lack of identified critical taint flows significantly reduces the potential for common web vulnerabilities.

The plugin's attack surface is minimal, with no identified AJAX handlers, REST API routes, shortcodes, or cron events. This, coupled with the absence of known CVEs and a history of no recorded vulnerabilities, suggests a well-maintained and secure codebase. The lack of specific code signals related to dangerous functions, nonces, or capability checks, while potentially indicating a limited feature set, does not inherently introduce security risks in this context as there are no entry points that would necessitate them.

In conclusion, 'scotty' v1.1.2 appears to be a very secure plugin. Its strengths lie in its disciplined coding practices and a clean vulnerability history. The primary weakness, if it can be called that, is the very limited attack surface, which might imply limited functionality. However, for the features it does offer, the security implementation seems robust and well-thought-out.

Vulnerabilities
None known

Scotty Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Scotty Code Analysis

Dangerous Functions
0
Raw SQL Queries
19
91 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

83% prepared110 total queries
Attack Surface

Scotty Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 23
filteradmin_footer_textplugin\Http\Controllers\Controller.php:12
filterupdate_footerplugin\Http\Controllers\Controller.php:13
actionwp_dashboard_setupplugin\Providers\DashboardWidget.php:16
filteradmin_footer_textplugin\Settings\WordPress\Admin\Appearance.php:22
filterupdate_footerplugin\Settings\WordPress\Admin\Appearance.php:27
actionadmin_initplugin\Settings\WordPress\Admin\Appearance.php:32
actionadmin_menuplugin\Settings\WordPress\Admin\Menu.php:22
actionadmin_menuplugin\Settings\WordPress\Admin\Menu.php:29
filterjson_enabledplugin\Settings\WordPress\General\ExternalAccess.php:24
filterjson_jsonp_enabledplugin\Settings\WordPress\General\ExternalAccess.php:25
filterrest_enabledplugin\Settings\WordPress\General\ExternalAccess.php:27
filterrest_jsonp_enabledplugin\Settings\WordPress\General\ExternalAccess.php:28
filterrest_authentication_errorsplugin\Settings\WordPress\General\ExternalAccess.php:29
filterxmlrpc_enabledplugin\Settings\WordPress\General\ExternalAccess.php:45
filterxmlrpc_methodsplugin\Settings\WordPress\General\ExternalAccess.php:46
filterxmlrpc_element_limitplugin\Settings\WordPress\General\ExternalAccess.php:49
filterxmlrpc_login_errorplugin\Settings\WordPress\General\ExternalAccess.php:52
filterwp_headersplugin\Settings\WordPress\General\ExternalAccess.php:55
filterthe_generatorplugin\Settings\WordPress\General\Security.php:27
filterlogin_errorsplugin\Settings\WordPress\General\Security.php:34
filterexcerpt_lengthplugin\Settings\WordPress\Reading\Theme.php:23
filtershow_admin_barplugin\Settings\WordPress\Reading\Theme.php:31
filterwp_revisions_to_keepplugin\Settings\WordPress\Writing\Posts.php:23
Maintenance & Trust

Scotty Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedNov 15, 2024
PHP min version7.4
Downloads606

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Scotty Developer Profile

gfazioli

5 plugins · 930 total installs

80
trust score
Avg Security Score
88/100
Avg Patch Time
73 days
View full developer profile
Detection Fingerprints

How We Detect Scotty

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/scotty/assets/dist/css/scotty.css/wp-content/plugins/scotty/assets/dist/js/scotty.js
Script Paths
/wp-content/plugins/scotty/assets/dist/js/scotty.js
Version Parameters
scotty/assets/dist/css/scotty.css?ver=scotty/assets/dist/js/scotty.js?ver=

HTML / DOM Fingerprints

JS Globals
NSScottyPlugin
REST Endpoints
/wp-json/scotty/v1/commentmeta//wp-json/scotty/v1/duplicates//wp-json/scotty/v1/postmeta/
FAQ

Frequently Asked Questions about Scotty