Title: JAZ-X Code Inspection
Author: jazxinnovation
Published: <strong>Ọwẹ́wẹ̀  27, 2026</strong>
Last modified: Ọwẹ́wẹ̀  27, 2026

---

Ṣàwárí àwọn plugin

![](https://ps.w.org/jaz-x-code-inspection/assets/icon-256x256.jpg?rev=3715107)

# JAZ-X Code Inspection

 Láti ọwọ́ [jazxinnovation](https://profiles.wordpress.org/jazxinnovation/)

[Ṣe ìgbàsílẹ̀](https://downloads.wordpress.org/plugin/jaz-x-code-inspection.0.7.1.zip)

 * [Àwọn àlàyé](https://yor.wordpress.org/plugins/jaz-x-code-inspection/#description)
 * [Àwọn àgbéyẹ̀wò](https://yor.wordpress.org/plugins/jaz-x-code-inspection/#reviews)
 *  [Ìgbéwọlẹ̀](https://yor.wordpress.org/plugins/jaz-x-code-inspection/#installation)
 * [Ìdàgbàsókè](https://yor.wordpress.org/plugins/jaz-x-code-inspection/#developers)

 [Ìrànlọ́wọ́](https://wordpress.org/support/plugin/jaz-x-code-inspection/)

## Àpèjúwe

JAZ-X Code Inspection is a read-only static inspection tool. It highlights code 
capabilities that deserve review, including dynamic code execution, obfuscation,
filesystem writes, direct database changes, outbound requests, REST routes, scheduled
tasks, and user privilege changes.

It also lists literal external domains referenced by the scanned code.

Important: a finding is not proof of malware, and a clean report is not a guarantee
of safety. Legitimate plugins often need powerful WordPress capabilities. JAZ-X 
Code Inspection helps administrators ask better questions before trusting code.

JAZ-X Code Inspection does not send scan data to an external service and does not
retain uploaded ZIP files.

#### JAZ-X Code Inspection Pro

The free edition is fully usable for on-demand static inspection. If you need continuous
monitoring, baselines, scan history, change alerts, and other advanced workflow 
features, an optional Pro edition is available from JAZ-X Innovation:
 https://store.
jazx.online/product/code-x-ray-pro-wordpress-plugin-security-scanner/

## Ìgbéwọlẹ̀

 1. Upload the plugin folder to `/wp-content/plugins/` or install the ZIP in WordPress.
 2. Activate JAZ-X Code Inspection.
 3. Open Tools > JAZ-X Code Inspection.
 4. Select an installed plugin or upload a plugin ZIP for inspection.

## FAQ

### Does a high score mean a plugin is malicious?

No. The score measures potentially powerful capabilities detected by static signatures.
Review the identified code and the pluginÌtumọ̀ Yorùbá: ’s documentation before 
making a trust decision.

### Does a low score guarantee safety?

No. Static analysis has limitations, including code assembled at runtime or behavior
supplied by remote services.

### Is uploaded code executed?

No. JAZ-X Code Inspection reads supported source files as text and removes extracted
temporary files after the scan.

### Is there a Pro edition?

Yes. JAZ-X Code Inspection Pro is an optional commercial edition for users who need
continuous monitoring, baselines, scan history, change alerts, and additional advanced
workflows. The free edition remains fully usable for its listed on-demand scanning
features.

Learn more: https://store.jazx.online/product/code-x-ray-pro-wordpress-plugin-security-
scanner/

## Àwọn àgbéyẹ̀wò

Kò sí àwọn àgbéyẹ̀wò fún plugin yìí.

## Àwọn Olùkópa & Olùgbéejáde

“JAZ-X Code Inspection” jẹ́ ètò ìṣàmúlò orísun ṣíṣí sílẹ̀. Àwọn ènìyàn wọ̀nyí ti
ṣe ìkópa sí plugin yìí.

Àwọn Olùkópa

 *   [ jazxinnovation ](https://profiles.wordpress.org/jazxinnovation/)

[Túmọ̀ “JAZ-X Code Inspection” sí èdè rẹ.](https://translate.wordpress.org/projects/wp-plugins/jaz-x-code-inspection)

### Ṣe o nífẹ̀ẹ́ sí ìdàgbàsókè?

[Ṣàwárí koodu](https://plugins.trac.wordpress.org/browser/jaz-x-code-inspection/),
ṣàyẹ̀wò [ibi ìpamọ́ SVN](https://plugins.svn.wordpress.org/jaz-x-code-inspection/),
tàbí ṣe àgbékalẹ̀ sí [àkọsílẹ̀ ìdàgbàsókè](https://plugins.trac.wordpress.org/log/jaz-x-code-inspection/)
nípasẹ̀ [RSS](https://plugins.trac.wordpress.org/log/jaz-x-code-inspection/?limit=100&mode=stop_on_copy&format=rss).

## Àkọsílẹ̀ àwọn àyípadà

#### 0.7.1

 * Add a restrained, optional JAZ-X Code Inspection Pro information link on the 
   plugin screen.
 * Document the optional Pro edition in the readme and FAQ.

#### 0.7.0

 * Add live report search across capabilities, files, evidence, and review guidance.
 * Add type, severity, and status filters with one-click reset.
 * Add sorting by severity, capability, location, status, or original report order.
 * Add total, security, access, dependency, and informational finding counters.

#### 0.6.1

 * Limit nearby controls to those relevant to each finding type.
 * Tighten the context window to reduce controls leaking across unrelated functions.
 * Add URL and uploaded-file validation context.
 * Clear older report data when the context schema changes.

#### 0.6.0

 * Add short redacted evidence excerpts to each finding.
 * Detect nearby nonce, capability, sanitization, prepared SQL, safe redirect, and
   REST permission controls.
 * Add a review status to every finding.
 * Include status, detected controls, and evidence in JSON and CSV exports.

#### 0.5.1

 * Require a remote source as well as hidden styling before reporting hidden iframe
   markup.
 * Suppress direct redirect findings when nearby executable code verifies a nonce
   or checks authorization.
 * Add visible separators between referenced external domains.

#### 0.5.0

 * Detect user input flowing directly into code loading or execution.
 * Detect unsafe deserialization of request data.
 * Detect remote-response-to-file write chains for manual review.
 * Detect direct upload handling, privileged account creation, user-controlled redirects,
   and hidden iframe markup.
 * Preserve comment filtering while allowing selected compound checks to inspect
   ordinary string literals without matching scanner-rule regex definitions.

#### 0.4.2

 * Stop treating PHP assert calls as dynamic code execution signals.
 * Recognize bundled code under lib/packages as third-party dependency context.

#### 0.4.1

 * Increase scan capacity to 5,000 source files and 50 MB of inspected code.
 * Correctly mark a report as partial when the next eligible file exceeds a scan
   limit.

#### 0.4.0

 * Add an automatic, plain-language scan verdict.
 * Add grouped capability summaries and collapse repeated technical evidence.
 * Add downloadable JSON and CSV scan reports.

#### 0.3.0

 * Rename the plugin to JAZ-X Code Inspection for WordPress.org naming compliance.
 * Use the WordPress Filesystem API for temporary directory cleanup.
 * Improve nonce verification placement and translation comments for Plugin Check.
 * Remove obsolete manual translation loading and the unused language path header.

#### 0.2.1

 * Add JAZ-X Innovation author branding and website link.

#### 0.2.0

 * Separate suspicious security signals from legitimate access exposure.
 * Make dangerous PHP signatures language-aware so JavaScript assertions are not
   reported as PHP execution.
 * Require suspicious decoding/execution chains before reporting possible obfuscation.
 * Separate first-party, dependency, and capability scoring.

#### 0.1.2

 * Split first-party plugin risk from bundled dependency risk.
 * Collapse dependency and low-confidence test/tooling evidence by default.
 * Limit the domain inventory to runtime-relevant source files with outbound calls.

#### 0.1.1

 * Reduce false positives by excluding PHP comments and string literals from capability
   matching.
 * Count each capability once in the risk score instead of once per matching file.
 * Add confidence and source-context labels for first-party, vendor, and test/tooling
   findings.

#### 0.1.0

 * Initial MVP.
 * Scan installed plugins and uploaded ZIP files.
 * Risk scoring, capability findings, file locations, and referenced domains.

## Àkójọpọ̀ Meta

 *  Ẹ̀yà **0.7.1**
 *  Ìgbàgbọ́hùn tó kẹ́yìn **ọjọ́ 2 sẹ́yìn**
 *  Àwọn ìgbéwọlẹ̀ tó ṣiṣẹ́ **Tó kéré sí 10**
 *  Ẹ̀yà WordPress ** 6.5 tàbí ju bẹ́ẹ̀ lọ **
 *  Dánwò dé **7.1.2**
 *  Ẹ̀yà PHP ** 7.4 tàbí ju bẹ́ẹ̀ lọ **
 *  Èdè
 * [English (US)](https://wordpress.org/plugins/jaz-x-code-inspection/)
 * Àwọn àmì
 * [developer-tools](https://yor.wordpress.org/plugins/tags/developer-tools/)[privacy](https://yor.wordpress.org/plugins/tags/privacy/)
   [scanner](https://yor.wordpress.org/plugins/tags/scanner/)[security](https://yor.wordpress.org/plugins/tags/security/)
 *  [Ìwòye Tó Péye](https://yor.wordpress.org/plugins/jaz-x-code-inspection/advanced/)

## Àwọn ìbò

Kò sí ìwádìí tí a tíì fi ránṣẹ́.

[Your review](https://wordpress.org/support/plugin/jaz-x-code-inspection/reviews/#new-post)

[Wo gbogbo àwọn àgbéyẹ̀wò](https://wordpress.org/support/plugin/jaz-x-code-inspection/reviews/)

## Àwọn Olùkópa

 *   [ jazxinnovation ](https://profiles.wordpress.org/jazxinnovation/)

## Ìrànlọ́wọ́

Nǹkan wà tí o fẹ́ sọ? Ṣé o nílò ìrànlọ́wọ́?

 [Wo àpéjọ ìrànlọ́wọ́](https://wordpress.org/support/plugin/jaz-x-code-inspection/)