Websitescanner Custom Schema Security & Risk Analysis

wordpress.org/plugins/websitescanner-custom-schema

Adds custom field to the post & pages editor for custom JSON-ld schema markup also known as structured data.

600 active installs v1.3.7 PHP 5.2.4+ WP 3.0.1+ Updated Jul 24, 2021
json-ldrich-snippetsschemaschema-markupstructured-data
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Websitescanner Custom Schema Safe to Use in 2026?

Generally Safe

Score 85/100

Websitescanner Custom Schema has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The "websitescanner-custom-schema" plugin v1.3.7 exhibits a generally strong security posture, particularly in its lack of exposed entry points and the absence of known vulnerabilities. The static analysis reveals no dangerous functions, file operations, or external HTTP requests, and all SQL queries are properly prepared. Furthermore, the presence of nonce and capability checks, albeit only one of each, indicates an awareness of essential WordPress security mechanisms. However, a significant concern arises from the output escaping, where only 43% of outputs are properly escaped. This leaves a considerable portion of the plugin's output potentially vulnerable to cross-site scripting (XSS) attacks, which could be exploited if an attacker can influence the data being outputted. The absence of taint analysis results is not necessarily a negative, but it means we cannot rule out potential complex vulnerabilities that might be identified through such analysis. Given the clean vulnerability history and the absence of critical code issues, the primary risk lies with the unescaped output. Overall, while the plugin avoids common pitfalls like raw SQL and large attack surfaces, the insufficient output escaping necessitates caution and improvement.

Key Concerns

  • Low percentage of properly escaped outputs
Vulnerabilities
None known

Websitescanner Custom Schema Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Websitescanner Custom Schema Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
6 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

43% escaped14 total outputs
Attack Surface

Websitescanner Custom Schema Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionplugins_loadedincludes\class-websitescanner-custom-schema.php:132
actionadmin_initincludes\class-websitescanner-custom-schema.php:147
actionsave_postincludes\class-websitescanner-custom-schema.php:148
actionadmin_enqueue_scriptsincludes\class-websitescanner-custom-schema.php:149
actionadmin_enqueue_scriptsincludes\class-websitescanner-custom-schema.php:150
filtermanage_pages_columnsincludes\class-websitescanner-custom-schema.php:152
actionmanage_pages_custom_columnincludes\class-websitescanner-custom-schema.php:153
filtermanage_posts_columnsincludes\class-websitescanner-custom-schema.php:155
actionmanage_posts_custom_columnincludes\class-websitescanner-custom-schema.php:156
actionwp_headincludes\class-websitescanner-custom-schema.php:171
actionamp_post_template_headincludes\class-websitescanner-custom-schema.php:172
Maintenance & Trust

Websitescanner Custom Schema Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedJul 24, 2021
PHP min version5.2.4
Downloads10K

Community Trust

Rating100/100
Number of ratings1
Active installs600
Developer Profile

Websitescanner Custom Schema Developer Profile

Tim van Iersel

3 plugins · 2K total installs

69
trust score
Avg Security Score
85/100
Avg Patch Time
946 days
View full developer profile
Detection Fingerprints

How We Detect Websitescanner Custom Schema

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/websitescanner-custom-schema/admin/css/websitescanner-custom-schema-admin.css/wp-content/plugins/websitescanner-custom-schema/admin/js/websitescanner-custom-schema-admin.js
Script Paths
/wp-content/plugins/websitescanner-custom-schema/admin/js/websitescanner-custom-schema-admin.js
Version Parameters
websitescanner-custom-schema/admin/css/websitescanner-custom-schema-admin.css?ver=websitescanner-custom-schema/admin/js/websitescanner-custom-schema-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
websitescanner-custom-schema-icon
Data Attributes
websitescanner_custom_schema_post_data
FAQ

Frequently Asked Questions about Websitescanner Custom Schema