17 Comments


  1. Just for the record, WPThemeDetector also detects plugins, even if the name isn’t the best hint. Not sure if the results are more accurate with the new service, but just saying.

    Reply

  2. This is a VERY BAD idea. If there are any security vulnerabilites in any plugins then this will allow people to scan for them.

    Reply

  3. The tool only looks to see whether you have any of the 65 plugins from their two lists (15 of their own and 50 common plugins) installed – it reported that your site had 5 of those so is that correct ? In our own test it didnt give a number of installed plugins at all although we do have some from their list. So overall, a less than useful tool : only checks 65 plugins and doesnt report those correctly !

    Reply

  4. @Dom Atreides – this one and the one from WPThemeDetector are not doing anything special – it is information that is relatively easy to find out and neither of these are very accurate anyway.

    Reply
  5. PD

    I use a browser plugin called SpyBar that does what you describe and a little more (links in/whois) and consider it an educational tool.

    Reply

  6. @Havenswift Hosting – Thank you for pointing this out. Indeed, they are only checking to see if the website has any of the 65 plugins installed. 15 that they created and the 50 most popular plugins. It doesn’t list or show any plugins outside of those 65.

    This had me confused and I’ve corrected the post to more accurately reflect how the checker works. After figuring that out, now the tool is even less useful than I thought.

    Reply

  7. @Jeffro – No problem and for the record WPThemeDetector only detected 3 installed plugins. Can’t see the point of these when the success rate is so poor other than a novelty factor and that VERY quickly wore off !

    Reply

  8. @Havenswift Hosting – Yeah. I hear ya. The next best thing is being able to browse the plugins directory if they don’t have it blocked with a blank index.html or php file. Last resort is looking at the Page Source for information on CSS files and which plugins are using them.

    Reply

  9. @Dom Atreides: I don´t think our WPThemeDetector plugin detection feature is any “bad idea” at all (for obvious reasons). For instance, many people use our tool to find out which particular plugin a site is using for a particular functionality, once they´ve seen it working on that site to their satisfaction, so our tool may help them choose the right plugin for that job. Plus, if anyone wanted to search plugins for malicious purposes, they would do it anyway without the help of our tool.

    @Havenswift Hosting: When you say that our tool is not very accurate, is it because it showed you any false positive or just because it didn´t detect all the plugins you use? Please bear in mind that not all the plugins are detectable (for example, plugins used for the admin area or for backups won´t show up), and also that not all the detectable plugins will be detected on every page of the analysed site, so the number of detected plugins will depend on the url being checked (for example, a plugin dealing with comments won´t be detected on the homepage of many sites).

    In general, our tool is intended to help people choose the right theme or plugin once they´ve seen them working on real sites, not for just snooping around other people´s sites.

    Maybe that´s the point Havenswift Hosting is missing.

    Reply

  10. At WPBeginner we have a page ‘WPBeginner’s Blueprint’ which has all the plugins and tools we use on the site. I like to read about plugins and tools people use on their sites particularly in their about page. This is how I found out Moveable Type and then later WordPress.

    Reply

  11. @Luis Alejandre: Not missing that point at all !

    Your tool didnt give false positives, just didnt report many of the plugins that are being used and of course we are aware that not all plugins are detectable for a variety of reasons – that is the exact point !

    Some sites like WPBeginner, as they have said, publish a list of plugins they use and others will respond to polite enquiries asking what are used. Do tools like this do any harm, no of course not, but their limited usability, due to very good reasons, should simply be understood

    Reply

  12. Cool tool. It would be nice if it would rip through and check a few thousand, but I guess that would hammer their server a bit too much :/

    Reply

  13. @Ryan Hellyer – You were right, but most of those five plugins are not being used by your homepage. Like I said in a previous reply:

    the number of detected plugins will depend on the url being checked (for example, a plugin dealing with comments won´t be detected on the homepage of many sites)

    And, as I also tried to make clear before, our plugin detection feature is intended for finding out what particular plugin is being used for a certain functionality once you´ve seen it working and you liked the way it works, not for getting to know what plugins are installed in a WP site just for the heck of it.

    The reason I said you “were” right is because your site was a bit tricky and our tool missed a couple of active plugins. But it gets continuously improved, so if you check it again you´ll realize that now it detects two more plugins on your home url (not detected by the other tool since none of them are in that 65 plugins list).

    Reply

Leave a Reply