The Sucuri WordPress Security plugin is a security toolset for security integrity monitoring, malware detection and security hardening.
Prioritized issue groups from the latest Plugin Check scan
Maintainability
56
7 issue groups
Security
5
3 issue groups
Repo Compliance
1
1 issue group
Sample message
PHP file should prevent direct access. Add a check like: if ( ! defined( 'ABSPATH' ) ) exit;
Sample message
Function "get_password_reset_key()" requires WordPress 4.4.0, but your plugin minimum supported version is WordPress 3.6.0.
Sample message
Detected usage of a non-sanitized input variable: $_GET['twofactor_search']
Sample message
$_GET['twofactor_search'] not unslashed before sanitization. Use wp_unslash() or similar
Sample message
Detected usage of meta_key, possible slow query.
Sample message
Classes declared by a theme/plugin should start with the theme/plugin prefix. Found: "SucuriWordPressRecommendations".
Sample message
Processing form data without nonce verification.
Sample message
Plugin name "Sucuri Security - Auditing, Malware Scanner and Security Hardening" is different from the name declared in plugin header "Sucuri Security - Auditing, Malware Scanner and Hardening".
Sample message
One or more tags were ignored. Please limit your plugin to 5 tags.
Sample message
Unexpected markdown file "CLAUDE.md" detected in plugin root. Only specific markdown files are expected in production plugins.
Sample message
The upgrade notice for "1.8.37" exceeds the limit of 300 characters.
Potential connections found in static code analysis.
Outbound calls
276
External assets
0
Incoming endpoints
3
No external asset domains detected.
No public endpoints detected.
wp_ajax
wp_ajax
wp_ajax
2 score snapshots
v2.7.4
82
Latest
v2.7.3
94
Score
| Scan | Score | Findings | Errors | Warnings | Plugin | Check |
|---|---|---|---|---|---|---|
| Latest | 82 | 62 | 51 | 11 | v2.7.4 | 2.0.0 |
| 94 | 57 | 52 | 5 | v2.7.3 | 2.0.0 |
Author, categories, issues, domains, and nearby plugins.