
WP Spell Check Security & Risk Analysis
wordpress.org/plugins/wp-spell-checkProofread & Audit your WordPress website with One Click! Find & fix the errors and build a professional image for your business.
Is WP Spell Check Safe to Use in 2026?
Generally Safe
Score 96/100WP Spell Check has a strong security track record. Known vulnerabilities have been patched promptly.
The "wp-spell-check" v10.1 plugin presents a mixed security posture. While it demonstrates strong output escaping (97%) and a good number of nonce and capability checks, significant concerns arise from its attack surface and taint analysis. The plugin exposes 23 AJAX handlers, with a concerning 21 lacking authentication checks, creating a large potential entry point for unauthorized actions. The taint analysis reveals 16 flows with unsanitized paths, all flagged as high severity, indicating a substantial risk of vulnerabilities like Cross-Site Scripting (XSS) or SQL injection if not handled carefully. The plugin's vulnerability history, with 6 past CVEs including one high-severity issue, and common types like XSS and CSRF, suggests a pattern of past weaknesses that, combined with the current high-severity taint flows, warrants significant caution. Despite positive aspects like proper output escaping and a lack of bundled libraries, the high number of unprotected AJAX endpoints and critical taint flows are primary areas of concern.
Key Concerns
- High number of AJAX handlers without auth checks
- High severity taint flows (unsanitized paths)
- Past high-severity vulnerability
- Dangerous function: preg_replace with /e modifier
- Significant portion of SQL queries not prepared
WP Spell Check Security Vulnerabilities
CVEs by Year
Severity Breakdown
6 total CVEs
WP Spell Check <= 9.21 - Cross-Site Request Forgery
WP Spell Check <= 9.17 - Cross-Site Request Forgery
WP Spell Check <= 9.12 - Authenticated (Admin+) Stored Cross-Site Scripting
WP Spell Check <= 9.12 - Cross-Site Request Forgery
WP Spell Check <= 9.2 - Reflected Cross-Site Scripting
WP Spell Check <= 7.1.9 - Cross-Site Request Forgery
WP Spell Check Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Spell Check Attack Surface
AJAX Handlers 23
WordPress Hooks 66
Maintenance & Trust
WP Spell Check Maintenance & Trust
Maintenance Signals
Community Trust
WP Spell Check Alternatives
Perfect Tense – Spelling and Grammar Checker
perfect-tense
Perfect Tense is an AI-powered, spelling and grammar corrector. Perfect Tense will automatically detect and fix mistakes, proofread entire blog posts, …
WProofreader spell & grammar check plugin for WordPress
webspellchecker
WProofreader checks spelling, grammar, and style in real-time while editing in WordPress.
Qalam Arabic AI Writing Assistant Plugin | Qalam
qalam
Qalam plugin for WordPress adds AI based grammar, spell check, and Tashkeel "Diacritization" capabilities to your website content in Arabic Language.
Spotfix – proofreading, spelling and grammar reviews by visitors
spotfix-content-review
Collect visitors’ questions and suggestions directly on your website pages. Make proofreading, spell checking, and grammar reviews easy.
Dynamic Month & Year into Posts
dynamic-month-year-into-posts
Automate SEO and content with dynamic shortcodes for dates, years, months, age calculations, seasons and countdowns in content, titles and meta.
WP Spell Check Developer Profile
1 plugin · 2K total installs
How We Detect WP Spell Check
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-spell-check/css/global-admin-styles.css/wp-content/plugins/wp-spell-check/admin/css/uninstall-page.csswp-spell-check/css/global-admin-styles.css?ver=wp-spell-check/admin/css/uninstall-page.css?ver=HTML / DOM Fingerprints
[wpsc_settings][wpsc_grammar][wpsc_dictionary][wpsc_ignore]