Whook Security Security & Risk Analysis

wordpress.org/plugins/whook-security

Our plugin Scans other plugins vulnerabilities listed in the WPScan Database of vulnerabilities.

10 active installs v1.3 PHP + WP 3.4+ Updated Apr 12, 2018
hackscansecurityvulnerabilitywpscan
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Whook Security Safe to Use in 2026?

Generally Safe

Score 85/100

Whook Security has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The whook-security plugin version 1.3 presents a concerning security posture due to significant gaps in its defense mechanisms, despite a clean vulnerability history. While the plugin avoids dangerous functions and uses prepared statements for SQL, its handling of output and entry points is critically weak. A substantial portion of its code signals indicates a lack of proper output escaping, meaning that user-supplied data or dynamically generated content could be exposed to cross-site scripting (XSS) attacks. Furthermore, the presence of an unprotected AJAX handler without any authentication or capability checks represents a direct and severe entry point for attackers. The absence of taint analysis results might suggest a limited scope of analysis or a plugin with minimal data manipulation, but it doesn't negate the clear risks identified in other areas.

The vulnerability history being clean is a positive indicator, suggesting the developers may have a good track record or that the plugin hasn't been a target. However, this should not be relied upon as a sole security measure, especially given the identified weaknesses in the current version. The combination of unescaped output and an unprotected AJAX endpoint creates a fertile ground for potential exploits. The plugin needs immediate attention to address these critical security flaws to mitigate the risk of compromise.

Key Concerns

  • Unprotected AJAX handler found
  • Output escaping not properly implemented
  • No nonce checks on AJAX handlers
  • No capability checks on AJAX handlers
Vulnerabilities
None known

Whook Security Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Whook Security Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
3
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped7 total outputs
Attack Surface
1 unprotected

Whook Security Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_whook_plg_scaninclude-classes\whook-class.php:10
WordPress Hooks 3
actionadmin_enqueue_scriptswhook-security.php:36
actionwp_dashboard_setupwhook-security.php:38
filteradmin_headwhook-security.php:146
Maintenance & Trust

Whook Security Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedApr 12, 2018
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Whook Security Developer Profile

darteweb

3 plugins · 20 total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Whook Security

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/whook-security/css/tooltipster.bundle.min.css/wp-content/plugins/whook-security/js/tooltipster.bundle.min.js/wp-content/plugins/whook-security/js/whook-js.js/wp-content/plugins/whook-security/css/whook-style.css
Script Paths
/wp-content/plugins/whook-security/js/tooltipster.bundle.min.js/wp-content/plugins/whook-security/js/whook-js.js
Version Parameters
whook-security/css/tooltipster.bundle.min.css?ver=whook-security/js/tooltipster.bundle.min.js?ver=whook-security/js/whook-js.js?ver=whook-security/css/whook-style.css?ver=

HTML / DOM Fingerprints

CSS Classes
whook-security-areagreen-areamsg-boxred-areawhook-tooltipyellow-area
Data Attributes
title
JS Globals
Whook_Plg_Url
FAQ

Frequently Asked Questions about Whook Security