
WP Scraper Security & Risk Analysis
wordpress.org/plugins/wp-scraperThis Wordpress Scraper allows you to move a non-Wordpress website into a Wordpress site.
Is WP Scraper Safe to Use in 2026?
Generally Safe
Score 96/100WP Scraper has a strong security track record. Known vulnerabilities have been patched promptly.
The wp-scraper plugin v5.8.2 demonstrates a mixed security posture. On the positive side, the static analysis shows excellent adherence to secure coding practices with 100% of SQL queries using prepared statements, all output being properly escaped, and no file operations or critical taint flows detected. The plugin also implements a reasonable number of nonce and capability checks. However, a significant concern arises from the presence of an unprotected AJAX handler, which represents a direct entry point into the plugin's functionality without any authorization validation. This, coupled with a history of 3 known medium severity vulnerabilities, including SSRF and Missing Authorization, suggests a past pattern of exploitable flaws. While no currently unpatched CVEs exist, the historical trend and the identified unprotected AJAX handler warrant caution. The overall risk is moderate, with the unprotected entry point being the most immediate technical concern, and the past vulnerabilities suggesting a potential for recurring issues in authorization or input validation.
Key Concerns
- Unprotected AJAX handler
- History of medium severity vulnerabilities
WP Scraper Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
WP Scraper <= 5.8.1 - Authenticated (Administrator+) Server-Side Request Forgery
WP Scraper <= 5.8 - Authenticated (Subscriber+) Server-Side Request Forgery
WP Scraper <= 5.7 - Missing Authorization to Arbitrary Page/Post Creation
WP Scraper Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Scraper Attack Surface
AJAX Handlers 1
WordPress Hooks 4
Maintenance & Trust
WP Scraper Maintenance & Trust
Maintenance Signals
Community Trust
WP Scraper Alternatives
Content Fetcher
content-fetcher
Fetch content from any website with simple shortcode
Post/Page Import Export – Migrate Content with Custom Fields & Taxonomies
postpage-import-export-with-custom-fields-taxonomies
Export and import WordPress posts & pages as JSON files with full support for custom fields, taxonomies, ACF fields, and featured images.
JHMG Converter For Elementor to Divi
jhmg-converter-for-elementor-to-divi
Convert and export your Elementor-built pages to Divi with precision and ease. Save hours of rebuilding work with this migration tool.
Magic Export & Import
magic-export-import
The ultimate tool to migrate any content including posts, terms, users, comments, WooCommerce shop orders, menus and ACF Options pages.
RSSInjection
rss-injection
Inject content into your RSS feed to entice people to subscribe or allow you to add a message so if the feed it aggregated onto another site it is at …
WP Scraper Developer Profile
3 plugins · 6K total installs
How We Detect WP Scraper
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-scraper/images/Cube-m.jpg/wp-content/plugins/wp-scraper/images/WP-Scraper-Pro-Ad.jpg/wp-content/plugins/wp-scraper/images/Live-Scrape-Ad.jpg/wp-content/plugins/wp-scraper/includes/simpledomselector.js/wp-content/plugins/wp-scraper/includes/wp-scraper-ingest.jswp-scraper/includes/simpledomselector.js?ver=wp-scraper/includes/wp-scraper-ingest.js?ver=HTML / DOM Fingerprints
wpsf-formdata-wpscf-urlwpsf_scrape[wpscrape]