Website Security Check Security & Risk Analysis

wordpress.org/plugins/website-security-check

Website Security Check detects if your WordPress website has vulnerabilities and security flaws. You get a full report with the list of security issue …

100 active installs v1.2.00 PHP 5.6+ WP 4.3+ Updated Aug 27, 2020
securitysecurity-checkwebsite-security-checkwordpress-security-check
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Website Security Check Safe to Use in 2026?

Generally Safe

Score 85/100

Website Security Check has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "website-security-check" plugin version 1.2.00 exhibits a generally good security posture, with no reported historical vulnerabilities (CVEs) and a strong emphasis on secure coding practices such as prepared statements for all SQL queries and the presence of capability checks. The static analysis reveals a minimal attack surface with no unprotected entry points, which is a significant strength. However, concerns arise from the taint analysis, which shows two flows with unsanitized paths, indicating potential vulnerabilities if these paths are exposed to user input without proper sanitization. Furthermore, the low percentage of properly escaped output (4%) is a notable weakness, suggesting a high risk of Cross-Site Scripting (XSS) vulnerabilities in most of its output operations. While the plugin has no recorded vulnerabilities, this could be due to its history or the limited scope of analysis rather than inherent invulnerability. The plugin needs to address the unsanitized paths and significantly improve its output escaping to mitigate the identified risks.

Key Concerns

  • Flows with unsanitized paths found
  • Low percentage of properly escaped output
Vulnerabilities
None known

Website Security Check Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Website Security Check Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

Website Security Check Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
51
2 escaped
Nonce Checks
2
Capability Checks
5
File Operations
4
External Requests
14
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

4% escaped53 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
showDebug (debug\index.php:149)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Website Security Check Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
filterinitclasses\Tools.php:41
filterplugin_row_metaclasses\Tools.php:44
filterplugin_action_linksclasses\Tools.php:47
actionadmin_bar_menucontrollers\Menu.php:24
actionwp_dashboard_setupcontrollers\Menu.php:25
Maintenance & Trust

Website Security Check Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedAug 27, 2020
PHP min version5.6
Downloads5K

Community Trust

Rating100/100
Number of ratings2
Active installs100
Developer Profile

Website Security Check Developer Profile

John Darrel

2 plugins · 100K total installs

80
trust score
Avg Security Score
89/100
Avg Patch Time
68 days
View full developer profile
Detection Fingerprints

How We Detect Website Security Check

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/website-security-check/debug/js/debug.js/wp-content/plugins/website-security-check/css/settings.css/wp-content/plugins/website-security-check/css/bootstrap.min.css/wp-content/plugins/website-security-check/css/font-awesome.min.css
Script Paths
/wp-content/plugins/website-security-check/debug/js/debug.js
Version Parameters
website-security-check/bootstrap.min.css?ver=website-security-check/font-awesome.min.css?ver=website-security-check/settings.css?ver=

HTML / DOM Fingerprints

CSS Classes
wsc_security_check
HTML Comments
<!-- Security Check -->
FAQ

Frequently Asked Questions about Website Security Check