
WPScan – WordPress Security Scanner Security & Risk Analysis
wordpress.org/plugins/wpscanWPScan WordPress Security Scanner - Scans your system for security vulnerabilities listed in the WPScan Vulnerability Database.
Is WPScan – WordPress Security Scanner Safe to Use in 2026?
Generally Safe
Score 100/100WPScan – WordPress Security Scanner has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'wpscan' v1.16 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of shortcodes, cron events, and REST API routes contributes to a small and manageable attack surface. Crucially, all identified AJAX entry points are protected by authentication checks, and the absence of any taint analysis findings or known historical CVEs further bolsters this positive assessment.
However, a significant concern arises from the handling of SQL queries. The analysis indicates that 100% of SQL queries do not utilize prepared statements. This is a critical security weakness that could expose the plugin to SQL injection vulnerabilities, especially if the data used in these queries originates from user input. While the plugin demonstrates good practices in output escaping (62% proper escaping is acceptable, though room for improvement exists) and implements nonces and capability checks on its entry points, the lack of prepared statements for all SQL queries represents a substantial risk.
Overall, 'wpscan' v1.16 appears to be a well-secured plugin with a clean vulnerability history, indicating a commitment to security by its developers. The primary weakness lies in its database interaction. Addressing the SQL query preparation is paramount to fully mitigating potential risks and achieving a robust security profile.
Key Concerns
- 100% of SQL queries not using prepared statements
- 62% of output properly escaped, room for improvement
WPScan – WordPress Security Scanner Security Vulnerabilities
WPScan – WordPress Security Scanner Code Analysis
SQL Query Safety
Output Escaping
WPScan – WordPress Security Scanner Attack Surface
AJAX Handlers 4
WordPress Hooks 22
Maintenance & Trust
WPScan – WordPress Security Scanner Maintenance & Trust
Maintenance Signals
Community Trust
WPScan – WordPress Security Scanner Alternatives
Whook Security
whook-security
Our plugin Scans other plugins vulnerabilities listed in the WPScan Database of vulnerabilities.
Gauntlet Security
gauntlet-security
Performs a detailed security analysis of your WordPress installation. Provides specific instructions on how to make your site more secure.
N0WPScan
n0wpscan
Secure your Wordpress of WPScan Prevent hackers using WPScan to find vulnerabilities in your site, disable this plugin when you are security testing o …
Stop User Enumeration
stop-user-enumeration
Helps secure your site against hacking attacks through detecting User Enumeration
Patchstack – WordPress & Plugins Security
patchstack
Patchstack automatically identifies and mitigates security vulnerabilities in WordPress plugins, themes, and core.
WPScan – WordPress Security Scanner Developer Profile
1 plugin · 9K total installs
How We Detect WPScan – WordPress Security Scanner
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpscan/assets/js/security-checks.jswp-content/plugins/wpscan/vendor/autoload.phpwpscan-security-checks.js?ver=HTML / DOM Fingerprints
wpscan-criticalwpscan-highwpscan-mediumwpscan-lowwpscan-vulnerability-severityWPScan WordPress Security Scanner.data-check-iddata-confirmdata-actionwpscan-criticalwpscan-highwpscan-medium+1 morewpscan_check_action