{"id":372268,"date":"2026-09-27T07:37:48","date_gmt":"2026-09-27T07:37:48","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/code-x-ray\/"},"modified":"2026-09-27T07:37:12","modified_gmt":"2026-09-27T07:37:12","slug":"jaz-x-code-inspection","status":"publish","type":"plugin","link":"https:\/\/yor.wordpress.org\/plugins\/jaz-x-code-inspection\/","author":23558679,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"0.7.1","stable_tag":"0.7.1","tested":"7.1.2","requires":"6.5","requires_php":"7.4","requires_plugins":null,"header_name":"JAZ-X Code Inspection","header_author":"JAZ-X Innovation","header_description":"Inspect installed plugins and plugin ZIP files for potentially risky capabilities before you trust them.","assets_banners_color":"","last_updated":"2026-09-27 07:37:12","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"https:\/\/www.jazx.online\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":48,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"0.7.1":{"tag":"0.7.1","author":"jazxinnovation","date":"2026-09-27 07:37:12","revision":3715109}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3715107,"resolution":"128x128","location":"assets","locale":"","width":125,"height":125},"icon-256x256.jpg":{"filename":"icon-256x256.jpg","revision":3715107,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":[],"assets_blueprints":{},"all_blocks":[],"tagged_versions":["0.7.1"],"block_files":[],"assets_screenshots":[],"screenshots":[]},"plugin_section":[],"plugin_tags":[4932,282900,396,6464,600],"plugin_category":[54],"plugin_contributors":[279727],"plugin_business_model":[],"class_list":["post-372268","plugin","type-plugin","status-publish","hentry","plugin_tags-developer-tools","plugin_tags-plugin-inspection","plugin_tags-privacy","plugin_tags-scanner","plugin_tags-security","plugin_category-security-and-spam-protection","plugin_contributors-jazxinnovation","plugin_committers-jazxinnovation"],"banners":[],"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/jaz-x-code-inspection\/assets\/icon-128x128.png?rev=3715107","icon_2x":"https:\/\/ps.w.org\/jaz-x-code-inspection\/assets\/icon-256x256.jpg?rev=3715107","generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>JAZ-X Code Inspection is a read-only static inspection tool. It highlights code capabilities that deserve review, including dynamic code execution, obfuscation, filesystem writes, direct database changes, outbound requests, REST routes, scheduled tasks, and user privilege changes.<\/p>\n\n<p>It also lists literal external domains referenced by the scanned code.<\/p>\n\n<p>Important: a finding is not proof of malware, and a clean report is not a guarantee of safety. Legitimate plugins often need powerful WordPress capabilities. JAZ-X Code Inspection helps administrators ask better questions before trusting code.<\/p>\n\n<p>JAZ-X Code Inspection does not send scan data to an external service and does not retain uploaded ZIP files.<\/p>\n\n<h4>JAZ-X Code Inspection Pro<\/h4>\n\n<p>The free edition is fully usable for on-demand static inspection. If you need continuous monitoring, baselines, scan history, change alerts, and other advanced workflow features, an optional Pro edition is available from JAZ-X Innovation:\nhttps:\/\/store.jazx.online\/product\/code-x-ray-pro-wordpress-plugin-security-scanner\/<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin folder to <code>\/wp-content\/plugins\/<\/code> or install the ZIP in WordPress.<\/li>\n<li>Activate JAZ-X Code Inspection.<\/li>\n<li>Open Tools &gt; JAZ-X Code Inspection.<\/li>\n<li>Select an installed plugin or upload a plugin ZIP for inspection.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20a%20high%20score%20mean%20a%20plugin%20is%20malicious%3F\"><h3>Does a high score mean a plugin is malicious?<\/h3><\/dt>\n<dd><p>No. The score measures potentially powerful capabilities detected by static signatures. Review the identified code and the plugin's documentation before making a trust decision.<\/p><\/dd>\n<dt id=\"does%20a%20low%20score%20guarantee%20safety%3F\"><h3>Does a low score guarantee safety?<\/h3><\/dt>\n<dd><p>No. Static analysis has limitations, including code assembled at runtime or behavior supplied by remote services.<\/p><\/dd>\n<dt id=\"is%20uploaded%20code%20executed%3F\"><h3>Is uploaded code executed?<\/h3><\/dt>\n<dd><p>No. JAZ-X Code Inspection reads supported source files as text and removes extracted temporary files after the scan.<\/p><\/dd>\n<dt id=\"is%20there%20a%20pro%20edition%3F\"><h3>Is there a Pro edition?<\/h3><\/dt>\n<dd><p>Yes. JAZ-X Code Inspection Pro is an optional commercial edition for users who need continuous monitoring, baselines, scan history, change alerts, and additional advanced workflows. The free edition remains fully usable for its listed on-demand scanning features.<\/p>\n\n<p>Learn more: https:\/\/store.jazx.online\/product\/code-x-ray-pro-wordpress-plugin-security-scanner\/<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>0.7.1<\/h4>\n\n<ul>\n<li>Add a restrained, optional JAZ-X Code Inspection Pro information link on the plugin screen.<\/li>\n<li>Document the optional Pro edition in the readme and FAQ.<\/li>\n<\/ul>\n\n<h4>0.7.0<\/h4>\n\n<ul>\n<li>Add live report search across capabilities, files, evidence, and review guidance.<\/li>\n<li>Add type, severity, and status filters with one-click reset.<\/li>\n<li>Add sorting by severity, capability, location, status, or original report order.<\/li>\n<li>Add total, security, access, dependency, and informational finding counters.<\/li>\n<\/ul>\n\n<h4>0.6.1<\/h4>\n\n<ul>\n<li>Limit nearby controls to those relevant to each finding type.<\/li>\n<li>Tighten the context window to reduce controls leaking across unrelated functions.<\/li>\n<li>Add URL and uploaded-file validation context.<\/li>\n<li>Clear older report data when the context schema changes.<\/li>\n<\/ul>\n\n<h4>0.6.0<\/h4>\n\n<ul>\n<li>Add short redacted evidence excerpts to each finding.<\/li>\n<li>Detect nearby nonce, capability, sanitization, prepared SQL, safe redirect, and REST permission controls.<\/li>\n<li>Add a review status to every finding.<\/li>\n<li>Include status, detected controls, and evidence in JSON and CSV exports.<\/li>\n<\/ul>\n\n<h4>0.5.1<\/h4>\n\n<ul>\n<li>Require a remote source as well as hidden styling before reporting hidden iframe markup.<\/li>\n<li>Suppress direct redirect findings when nearby executable code verifies a nonce or checks authorization.<\/li>\n<li>Add visible separators between referenced external domains.<\/li>\n<\/ul>\n\n<h4>0.5.0<\/h4>\n\n<ul>\n<li>Detect user input flowing directly into code loading or execution.<\/li>\n<li>Detect unsafe deserialization of request data.<\/li>\n<li>Detect remote-response-to-file write chains for manual review.<\/li>\n<li>Detect direct upload handling, privileged account creation, user-controlled redirects, and hidden iframe markup.<\/li>\n<li>Preserve comment filtering while allowing selected compound checks to inspect ordinary string literals without matching scanner-rule regex definitions.<\/li>\n<\/ul>\n\n<h4>0.4.2<\/h4>\n\n<ul>\n<li>Stop treating PHP assert calls as dynamic code execution signals.<\/li>\n<li>Recognize bundled code under lib\/packages as third-party dependency context.<\/li>\n<\/ul>\n\n<h4>0.4.1<\/h4>\n\n<ul>\n<li>Increase scan capacity to 5,000 source files and 50 MB of inspected code.<\/li>\n<li>Correctly mark a report as partial when the next eligible file exceeds a scan limit.<\/li>\n<\/ul>\n\n<h4>0.4.0<\/h4>\n\n<ul>\n<li>Add an automatic, plain-language scan verdict.<\/li>\n<li>Add grouped capability summaries and collapse repeated technical evidence.<\/li>\n<li>Add downloadable JSON and CSV scan reports.<\/li>\n<\/ul>\n\n<h4>0.3.0<\/h4>\n\n<ul>\n<li>Rename the plugin to JAZ-X Code Inspection for WordPress.org naming compliance.<\/li>\n<li>Use the WordPress Filesystem API for temporary directory cleanup.<\/li>\n<li>Improve nonce verification placement and translation comments for Plugin Check.<\/li>\n<li>Remove obsolete manual translation loading and the unused language path header.<\/li>\n<\/ul>\n\n<h4>0.2.1<\/h4>\n\n<ul>\n<li>Add JAZ-X Innovation author branding and website link.<\/li>\n<\/ul>\n\n<h4>0.2.0<\/h4>\n\n<ul>\n<li>Separate suspicious security signals from legitimate access exposure.<\/li>\n<li>Make dangerous PHP signatures language-aware so JavaScript assertions are not reported as PHP execution.<\/li>\n<li>Require suspicious decoding\/execution chains before reporting possible obfuscation.<\/li>\n<li>Separate first-party, dependency, and capability scoring.<\/li>\n<\/ul>\n\n<h4>0.1.2<\/h4>\n\n<ul>\n<li>Split first-party plugin risk from bundled dependency risk.<\/li>\n<li>Collapse dependency and low-confidence test\/tooling evidence by default.<\/li>\n<li>Limit the domain inventory to runtime-relevant source files with outbound calls.<\/li>\n<\/ul>\n\n<h4>0.1.1<\/h4>\n\n<ul>\n<li>Reduce false positives by excluding PHP comments and string literals from capability matching.<\/li>\n<li>Count each capability once in the risk score instead of once per matching file.<\/li>\n<li>Add confidence and source-context labels for first-party, vendor, and test\/tooling findings.<\/li>\n<\/ul>\n\n<h4>0.1.0<\/h4>\n\n<ul>\n<li>Initial MVP.<\/li>\n<li>Scan installed plugins and uploaded ZIP files.<\/li>\n<li>Risk scoring, capability findings, file locations, and referenced domains.<\/li>\n<\/ul>","raw_excerpt":"Inspect installed plugins and plugin ZIP files for potentially risky capabilities without executing their code.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/yor.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/372268","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/yor.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/yor.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/yor.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=372268"}],"author":[{"embeddable":true,"href":"https:\/\/yor.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/jazxinnovation"}],"wp:attachment":[{"href":"https:\/\/yor.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=372268"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/yor.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=372268"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/yor.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=372268"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/yor.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=372268"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/yor.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=372268"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/yor.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=372268"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}