
Screeney Security & Risk Analysis
wordpress.org/plugins/screeneyConnects your website with the Screeney bug tracking web application.
Is Screeney Safe to Use in 2026?
Generally Safe
Score 85/100Screeney has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'screeney' v1.0.0 plugin exhibits a concerning security posture primarily due to a significant lack of authentication and authorization checks on its identified entry points. While the plugin demonstrates good practices in avoiding dangerous functions and utilizing prepared statements for SQL queries, these strengths are overshadowed by critical weaknesses in how it handles user input and access control.
The static analysis reveals one AJAX handler that lacks any authentication checks, presenting a direct pathway for unauthenticated users to interact with plugin functionalities. This is further exacerbated by the taint analysis, which found three flows with unsanitized paths, indicating potential vulnerabilities where user-supplied data might be improperly handled. The absence of nonce checks and capability checks on this AJAX handler is a major security concern, as it allows any visitor to potentially trigger plugin actions.
Despite the lack of recorded vulnerability history, which is a positive indicator, the presence of critical weaknesses in the code itself suggests a high potential for exploitation. The plugin's limited attack surface (one AJAX handler) is problematic because that single point is completely unprotected. In conclusion, while the plugin avoids some common pitfalls like raw SQL or dangerous functions, the fundamental lack of security measures on its primary entry point makes it a high-risk plugin. Improvements are urgently needed to implement proper authentication, authorization, and input sanitization.
Key Concerns
- AJAX handler without auth checks
- Flows with unsanitized paths
- Missing nonce checks
- Missing capability checks
- Low output escaping percentage
Screeney Security Vulnerabilities
Screeney Release Timeline
Screeney Code Analysis
Output Escaping
Data Flow Analysis
Screeney Attack Surface
AJAX Handlers 1
WordPress Hooks 7
Maintenance & Trust
Screeney Maintenance & Trust
Maintenance Signals
Community Trust
Screeney Alternatives
Editoria11y Accessibility Checker
editoria11y-accessibility-checker
Content accessibility checker written to be intuitive and useful for non-technical authors and editors.
O3 CLI Services
o3-cli-services
O3 CLI Services integrates any WordPress site with the O3 CLI (https://www.npmjs.com/package/o3-cli) tool.
PrecisionQA
precisionqa
A comprehensive testing utility for WordPress developers and QA testers.
QA Assistant
qa-assistant
A comprehensive tool for Software Quality Assurance Engineers with advanced Git branch management capabilities.
QAlimucho for WooCommerce
qalimucho-for-woocommerce
Enable automated checkout testing for WooCommerce without real payments.
Screeney Developer Profile
4 plugins · 120 total installs
How We Detect Screeney
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/screeney/admin/css/screeney-admin.css/wp-content/plugins/screeney/includes/js/screeney-public.js/wp-content/plugins/screeney/admin/js/screeney-admin.jsscreeney-admin.css?ver=screeney-public.js?ver=screeney-admin.js?ver=