Know what a WordPress plugin can actually do — before you install it.

Plugin Audits is a curated database of already-scanned WordPress plugins. We analyze source code to reveal permissions, external connections, activation behavior, and version changes.

Pre-scanned plugin database

We continuously scan official plugin releases and store results in a public, searchable database.

Permissions & capability insights

See which capabilities are used, where, and how deeply a plugin can access your site.

External access detection

We identify external hosts, third-party services, and outgoing connections.

Version behaviour tracking

Track changes between versions to understand what is new, changed, or introduced.

Recently Audited Plugins

Hello Dolly

Matt Mullenweg

Version
1.7.2
Last Scanned
4 september 2026
Info Technical Risk
View Audit Report →

Akismet Anti-spam: Spam Protection

Automattic

Version
5.7.2
Last Scanned
4 september 2026
Medium Technical Risk
View Audit Report →

WooCommerce

Automattic

Version
11.1.0
Last Scanned
4 september 2026
High Technical Risk
View Audit Report →

WordPress Importer

WordPress.org

Version
0.9.6
Last Scanned
4 september 2026
Info Technical Risk
View Audit Report →

Classic Editor

WordPress.org

Version
1.7.0
Last Scanned
4 september 2026
Info Technical Risk
View Audit Report →

View more plugins in the database →

How Plugin Audits Works

1

We fetch official plugin releases

We obtain plugins directly from the WordPress.org repository.

2

We analyze the source code

Our deterministic scanner analyzes PHP code, never AI-based guessing.

3

We detect permissions & behaviour

We identify capabilities, external hosts, REST routes, and more.

4

You review structured audit reports

Everything is organized into clear, searchable technical reports.

We don't show what the internet thinks about a plugin.
We show you what the code can actually do.

  • ✕ No opinions.
  • ✕ No ratings.
  • ✓ Just technical facts.