Scout Checkr Security & Risk Analysis

wordpress.org/plugins/scout-checkr

Manage and observe multiple Wordpress sites you manage in one comfortable view. Best way to be updated about your Site Health status you can monitor …

0 active installs v0.1.75 PHP 5.5+ WP 4.9+ Updated Jul 4, 2022
administrationgrafanasite-health
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Scout Checkr Safe to Use in 2026?

Generally Safe

Score 85/100

Scout Checkr has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The scout-checkr plugin exhibits a mixed security posture. On the positive side, the static analysis shows good practices in areas like SQL query handling, with 100% of queries using prepared statements, and output escaping, where all 46 outputs are properly escaped. There's also no history of known vulnerabilities, which is a strong indicator of a well-maintained and secure codebase over time. Furthermore, the absence of dangerous functions, file operations, and critical/high severity taint flows suggests careful coding.

However, significant security concerns are present due to the plugin's attack surface. The presence of one unprotected AJAX handler represents a critical entry point that could be exploited by unauthenticated users. The lack of nonce checks and capability checks on this handler further exacerbates the risk, allowing for potential Cross-Site Request Forgery (CSRF) or unauthorized action execution. While the plugin's vulnerability history is clean, this does not negate the immediate risks posed by the identified unprotected entry point. Addressing this unprotected AJAX handler is paramount to improving the plugin's overall security.

In conclusion, while scout-checkr demonstrates strengths in data handling and a clean vulnerability record, the single unprotected AJAX handler presents a significant and immediate security risk. This weakness outweighs the positive aspects and requires urgent remediation. The plugin needs to implement proper authentication and authorization checks for its AJAX endpoints to be considered reasonably secure.

Key Concerns

  • Unprotected AJAX handler
  • Missing nonce checks on AJAX
  • Missing capability checks on AJAX
Vulnerabilities
None known

Scout Checkr Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Scout Checkr Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
46 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
4
Bundled Libraries
0

Output Escaping

100% escaped46 total outputs
Attack Surface
1 unprotected

Scout Checkr Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_wp_status_installsrc\Plugin.php:66
WordPress Hooks 10
filtercron_schedulesplugin.php:35
filtercron_schedulesplugin.php:47
actionplugins_loadedplugin.php:78
actionadmin_menusrc\Admin\Settings.php:43
actionadmin_initsrc\Admin\Settings.php:44
actionadmin_noticessrc\Admin\Settings.php:45
actionadmin_initsrc\Admin\Settings.php:46
actionadmin_initsrc\Admin\Settings.php:47
filtercron_schedulessrc\Front\Cron.php:42
actionspiral_grafana_test_results_eventsrc\Front\Cron.php:44

Scheduled Events 1

spiral_grafana_test_results_event
Maintenance & Trust

Scout Checkr Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedJul 4, 2022
PHP min version5.5
Downloads719

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Scout Checkr Developer Profile

SpiralScout

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Scout Checkr

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/scout-checkr/assets/admin/api_settings.css/wp-content/plugins/scout-checkr/assets/admin/api_settings.js/wp-content/plugins/scout-checkr/images/ss_logomark.svg
Script Paths
/wp-content/plugins/scout-checkr/assets/admin/api_settings.js
Version Parameters
scout-checkr/assets/admin/api_settings.css?ver=scout-checkr/assets/admin/api_settings.js?ver=

HTML / DOM Fingerprints

CSS Classes
spiral-notification
HTML Comments
<!-- Scout Checkr. --><!-- Init hooks --><!-- --><!-- -->+12 more
Data Attributes
data-fields
FAQ

Frequently Asked Questions about Scout Checkr