
WP Scanner – Performance and Security Security & Risk Analysis
wordpress.org/plugins/wp-scannerScan your WordPress site and receive recommendations on how to improve load time, performance and security.
Is WP Scanner – Performance and Security Safe to Use in 2026?
Generally Safe
Score 85/100WP Scanner – Performance and Security has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-scanner v1.0.2 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by using prepared statements for all its SQL queries and has no recorded vulnerability history, indicating a potentially well-maintained codebase. It also correctly implements nonce and capability checks for one of its entry points. However, there are significant concerns stemming from the static analysis. The plugin exposes one AJAX handler without any authentication or permission checks. This creates a direct pathway for unauthenticated attackers to interact with the plugin's functionality, potentially leading to unexpected behavior or exploitation if the handler performs sensitive operations. Furthermore, a concerning 100% of its output is not properly escaped. This makes it highly susceptible to Cross-Site Scripting (XSS) vulnerabilities, where attackers could inject malicious scripts through these unescaped outputs, impacting users of the WordPress site.
Key Concerns
- AJAX handler without authentication
- 100% of outputs not escaped
WP Scanner – Performance and Security Security Vulnerabilities
WP Scanner – Performance and Security Code Analysis
SQL Query Safety
Output Escaping
WP Scanner – Performance and Security Attack Surface
AJAX Handlers 2
WordPress Hooks 4
Maintenance & Trust
WP Scanner – Performance and Security Maintenance & Trust
Maintenance Signals
Community Trust
WP Scanner – Performance and Security Alternatives
WPLifeCycle – Free PHP Version Info & Website Manager
free-php-version-info
This plugin shows your current PHP version, its lifecycle security support days, and can send version data to the WPLifeCycle for proactive planning.
Sajjetti – AI Audit
sajjetti-audit
AI-assisted theme and plugin scanner for security, performance, and best practices. Provides clear, actionable insights.
Wordfence Security – Firewall, Malware Scan, and Login Security
wordfence
Firewall, Malware Scanner, Two Factor Auth, and Comprehensive Security Features, powered by our 24-hour team. Make security a priority with Wordfence.
Jetpack – WP Security, Backup, Speed, & Growth
jetpack
Improve your WP security with powerful one-click tools like backup, WAF, and malware scan. Includes free tools like stats, CDN and social sharing.
All-In-One Security (AIOS) – Security and Firewall
all-in-one-wp-security-and-firewall
Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plugin designed especially for WordPress.
WP Scanner – Performance and Security Developer Profile
3 plugins · 260 total installs
How We Detect WP Scanner – Performance and Security
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-scanner/assets/js/script.js/wp-content/plugins/wp-scanner/assets/js/script.min.js/wp-content/plugins/wp-scanner/assets/js/script.js/wp-content/plugins/wp-scanner/assets/js/script.min.jswp-scanner/assets/js/script.js?ver=wp-scanner/assets/js/script.min.js?ver=HTML / DOM Fingerprints
Copyright (c) 2016 WP Scanner. All rights reserved. Released under the GPL license http://www.opensource.org/licenses/gpl-license.php **********************************************************************+4 morewp_scanner_settings[key]wp_scanner_settings[secret]wpScanner