Plugin Pulse
← Pulse
E

Exploit Scanner

by Donncha O Caoimh (a11n) · Security

Also makes 9 other plugins · 21.4K+ installs across the portfolio →

Search the files and database of your WordPress install for signs that may indicate that it has fallen victim to malicious hackers.

⚠ Stale⚠ Likely abandoned
How scoring works →
39 Health · F
Maintenance 3/100
Rating quality 59/100
Support 70/100

39 health vs 64 average across 997 Security plugins

High removal-risk signals

63/100

Maintenance and integrity signals that tend to precede a WordPress.org removal. Not an official status, a heads-up to act.

  • Long abandoned. No update in 8+ years — the top precursor to removal once a vulnerability is found.
  • Compatibility drift. Tested only up to WordPress 4.7.35, well behind 6.8.

Directory ranking optimization

How it's scored →

How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.

43 / 100

Under-optimized

Biggest win: Update recency

Update recency 0/100
WP compatibility 8/100
Rating quality 74/100
Listing tuning 100/100

To rank higher: Last updated 3196 days ago — ship an update; wp.org decays a listing's search weight after ~180 days.

Get the full rank-higher report →

Daily downloads

Since 2022-10-05 · 1,425 days · wp.org + Plugin Pulse archive

+29% vs prior 30d
11Downloads · Aug 26

30-day downloads

Rolling 30-day volume · peaks are release surges

288

now · peak 1.0K

28530d downloads · Aug 26

Directory rank vs rivals

wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you

Exploit Scanner · #2415 you Wordfence Security · #11 Sucuri Security · #105 Anti-Malware Securit · #303

Rating trend

Star average over time · dips mark rough releases

3.2Stars · Aug 26

Update activity

How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.

36per 1k installs · Aug 26

Release cadence

No release in a year
from wp.org release tags

How often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.

0

releases in the last 12 months

9.2y ago

latest release · v1.5.2

51

tagged releases on record

Recent releases

1.5.2 · 9.2y ago1.5.1 · 9.7y ago1.5 · 10.2y ago1.4.12 · 10.3y ago1.4.11 · 10.3y ago1.4.10 · 10.6y ago1.4.9 · 10.7y ago1.4.8 · 11.0y ago1.4.7 · 11.0y ago1.4.6 · 11.1y ago1.4.5 · 11.3y ago1.4.4 · 11.3y ago1.4.3 · 11.4y ago1.4.2 · 11.4y ago

What its installed base runs

via wordpress.org

Share of active installs on each version of this plugin · 87% run the current release. Green is the current release; a big slice on older versions is a user base that has stopped updating.

v1.5 87%
v1.3 7%
v1.4 5.7%
Older / other versions 0.7%

Estimated active installs

The public count shows “8K+”. Our estimate pins where the real number sits.

tracked estimate
8K–9K ≈8.4K

Refined from the date this plugin crossed into its current band.

Install history · since 2015-03-16 · 1,500 observations

8KInstalls · Aug 26

Estimated value

What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.

Est. annual revenue

N/A

Est. acquisition value

N/A

No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price. A small install base leaves thin data to model from.

Details

Version
1.5.2
Last updated
8.8y ago
Added
2008-06-26 · 18 yrs old
Requires WP
3.3
Tested up to
4.7.35
Requires PHP

Recent reviews

All reviews on wp.org ↗
  1. Antonio Augusto
    5.4y ago

    Apparently abandoned or confuse. This topic was modified 5 years, 3 months ago by Antonio Augusto.

    Read on wp.org ↗
  2. C77
    7.2y ago

    Doesn´t work at all… it always shows an error, try later.

    Read on wp.org ↗
  3. scorpiotiger
    8.2y ago

    Just gives an error: {“status”:”error”,”message”:”$this->files was not an array”,”data”:{“start”:250,”files”:”b:0;”}} Others have posted in the support section and not had responses and the plugin has not been updated for a long time, so it looks to be an abandoned project.

    Read on wp.org ↗
  4. carolzeroum
    8.5y ago

    Exploit Scanner is a useless plugin. I mean, it does nothing. It just lists hundreds of files of your server. Says nothing about them. And does nothing either. In the end, it says you are a PARANOID. If you have any further worries. I think I will create a WordPress plugin too.

    Read on wp.org ↗
  5. Eduard Doloc
    8.8y ago

    Great plugin, but it’s not well documented. Anyways, it works on version 4.8.3 and theoretically any version as long as you generate (if you don’t have) the hashes for your wordpress version; in my case I had to generate for 4.8.3 and it did a good job 🙂

    Read on wp.org ↗
  6. enacta2
    9.2y ago

    Works really well. I have it installed next to TAC and VIP Scanner on my localhost test site. The trick is you need to use current hashes, and none are available for WordPress 4.8 and higher on the Internets. So, here are hashes for WordPress 4.8. And easy to follow directions to create new hashes for newer versions of WordPress: https://wordpress.org/support/topic/here-you-go-hashes-4-8-php/ This topic was modified 9 years ago by enacta2. Reason: Phrasing

    Read on wp.org ↗
  7. Ovidiu Zeicu
    9.2y ago

    A LOT of WP core files on fresh install are included on the Level Severe results section, most of them having “Unknown file found” in the description. If the plugin doesn’t even know which files are core files, how should I trust it with other files? Working with MD5 hashes is not for everyone, so it’s definitely not for beginners.

    Read on wp.org ↗
  8. mark200789
    9.5y ago

    I’m pretty tech savvy, but creating a hash file for my site is beyond my abilities. That’s what this scanner needs or it will mark every single files and unknown and corrupted. And it won’t tell you until after you’ve finished scanning. It’s nowhere in the online instructions. Waste of time unless you are a command line guru.

    Read on wp.org ↗

Latest updates

via wp.org changelog

Recent releases and news for this plugin

  1. Version 1.5.2 Added hashes for WordPress 4.7.5 1.5.2
  2. Version 1.5.1 WordPress 4.6 hashes WordPress 4.6.1 hashes WordPress 4.7 hashes 1.5.1
  3. Version 1.5 WordPress 4.5.3 hashes Move to follow WP versioning system 1.5
  4. Version 1.4.12 WordPress 4.5.2 hashes 1.4.12
  5. Version 1.4.11 WordPress 4.5 hashes WordPress 4.5.1 hashes 1.4.11
  6. Version 1.4.10 WordPress 4.4.1 hashes 1.4.10

Known vulnerabilities

via Wordfence Intelligence

1 disclosed vulnerability on record for this plugin, fixed in the current version. Sites on older versions stay exposed until they update.

  1. 2013-05-29 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 1.3.3 Patched in 1.3.4

Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.

Growth timeline

Install-tier crossings we have observed, and how long each tier took to outgrow

  1. 2026-06-07 9K+ → 8K+ down after 153 days in tier
  2. 2026-01-05 10K+ → 9K+ down after 1138 days in tier
  3. 2022-11-24 20K+ → 10K+ down

Competes with

The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).

Compare head to head →

Embed this report card

Drop a live Pulse card for Exploit Scanner into a readme, a review or a deck. It updates itself.

<iframe src="https://plugins.wpmayor.com/embed/exploit-scanner" width="480" height="300" style="border:0" loading="lazy" title="Exploit Scanner — Plugin Pulse"></iframe>
Preview card ↗

Exploit Scanner: 8K+ active installs, 3.2★ (40 reviews). Plugin Pulse (WP Mayor), as of 2026-08-29. https://plugins.wpmayor.com/plugin/exploit-scanner