Scouting OpenID Connect Security & Risk Analysis

wordpress.org/plugins/scouting-openid-connect

WordPress plugin for logging in with Scouting Nederland OpenID Connect Server.

10 active installs v2.3.0 PHP 8.2+ WP 6.6.0+ Updated Feb 16, 2026
oidcopenid-connectscoutingscouting-nederlandsol
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Scouting OpenID Connect Safe to Use in 2026?

Generally Safe

Score 100/100

Scouting OpenID Connect has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The scouting-openid-connect plugin v2.3.0 exhibits a generally strong security posture based on the provided static analysis. The complete absence of dangerous functions, raw SQL queries, and file operations is commendable. Furthermore, the high percentage of properly escaped output and the presence of nonce checks on all identified entry points (shortcodes) are positive indicators of secure coding practices. The plugin also has no recorded vulnerability history, suggesting a mature and well-maintained codebase.

However, a significant concern is the complete lack of capability checks on its entry points (shortcodes). While nonce checks are present, the absence of role-based access control means that any authenticated user, regardless of their privileges, could potentially interact with the shortcode functionality. This could lead to unintended actions or information disclosure if the shortcode logic is not designed with this in mind.

In conclusion, the plugin demonstrates good security fundamentals, particularly in its handling of SQL and output. The primary weakness lies in the missing capability checks, which represent a potential risk that should be addressed to ensure only authorized users can leverage the plugin's features. The absence of past vulnerabilities is a positive sign, but the current lack of permission controls is a notable gap.

Key Concerns

  • Missing capability checks on entry points
Vulnerabilities
None known

Scouting OpenID Connect Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Scouting OpenID Connect Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
74 escaped
Nonce Checks
3
Capability Checks
0
File Operations
0
External Requests
3
Bundled Libraries
0

Output Escaping

90% escaped82 total outputs
Attack Surface

Scouting OpenID Connect Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[scouting_oidc_button] scouting-openid-connect.php:72
[scouting_oidc_link] scouting-openid-connect.php:73
WordPress Hooks 19
actionlogin_formscouting-openid-connect.php:69
filterwp_mailscouting-openid-connect.php:79
actionshow_user_profilescouting-openid-connect.php:84
actionedit_user_profilescouting-openid-connect.php:85
actionadmin_enqueue_scriptsscouting-openid-connect.php:89
actionadmin_enqueue_scriptsscouting-openid-connect.php:90
actionplugins_loadedscouting-openid-connect.php:92
actionadmin_menuscouting-openid-connect.php:95
actionadmin_menuscouting-openid-connect.php:96
actionadmin_menuscouting-openid-connect.php:97
actionadmin_menuscouting-openid-connect.php:98
actionadmin_initscouting-openid-connect.php:101
actiontemplate_redirectscouting-openid-connect.php:104
filterlogin_messagescouting-openid-connect.php:107
filterall_pluginsscouting-openid-connect.php:110
filtersafe_style_cssscouting-openid-connect.php:113
actionwp_loginscouting-openid-connect.php:119
actionwp_logoutscouting-openid-connect.php:122
filterallowed_redirect_hostssrc\auth\Auth.php:294
Maintenance & Trust

Scouting OpenID Connect Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 16, 2026
PHP min version8.2
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Scouting OpenID Connect Developer Profile

Scouting Nederland

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Scouting OpenID Connect

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/scouting-openid-connect/src/js/enqueue.js/wp-content/plugins/scouting-openid-connect/src/js/enqueue_hide_field.js
Script Paths
/wp-content/plugins/scouting-openid-connect/src/js/enqueue.js/wp-content/plugins/scouting-openid-connect/src/js/enqueue_hide_field.js
Version Parameters
scouting-openid-connect/src/js/enqueue.js?ver=scouting-openid-connect/src/js/enqueue_hide_field.js?ver=

HTML / DOM Fingerprints

Shortcode Output
[scouting_oidc_button][scouting_oidc_link]
FAQ

Frequently Asked Questions about Scouting OpenID Connect