Is Scan WP - WordPress Theme and Plugin Detector safe?
Medium risk
Scan WP sends the active tab URL to scanwp.net and renders the raw HTML response without sanitization.
Each time a user opens the extension popup, it reads the current tab's URL and transmits it to scanwp.net/extension/ via an XMLHttpRequest. The server response is injected directly into the popup's innerHTML with no sanitization, meaning any HTML or script content returned by scanwp.net is executed in the extension popup context.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
45Risk
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Data recipients
scanwp.net