DigitalSpace Personal Data Scanner
Finds personal data (PII) in users, comments, posts, WooCommerce and forms. GDPR, HIPAA and CCPA aware. Nothing leaves your server.
Solid choice
DigitalSpace Personal Data Scan… is a solid plugin choice in 2026, with a few things worth checking first. Was last updated 1 week ago, and scores 64/100 on our health check.
- Actively developed — last update 1 week ago
- Tested with the latest WordPress (7.1)
- Small user base (<10 active installs)
- Very few reviews so far
How does it stack up?
Side-by-side on installs, updates, ratings & supportDaily downloads
Download spikes usually follow a new release — each site that auto-updates counts as a download.
Rankings
Where DigitalSpace Personal Data… stands todayWordPress.org search rankings
Live position in the plugin search, top 100| Keyword | Position |
|---|---|
| CCPA | >100 |
| GDPR | >100 |
| HIPAA | #24 |
| PII | #73 |
| woocommerce | >100 |
About DigitalSpace Personal Data Scanner
From the official readme · v0.1.4Description
Most WordPress sites hold far more personal data than their owners know: old form submissions, comment emails and IP addresses, IBANs pasted into order notes, drafts nobody deleted, options a plugin filled years ago. Personal Data Scanner finds it, tells you where it is, and links you straight to the record so you can act.
Run one scan and you have a personal data inventory: how many items, of which kinds, in which places.
Docs, FAQ and Pro: personaldatascanner.com
Built to support the data-mapping step behind GDPR, HIPAA and CCPA work: you cannot protect, minimise or delete personal data (PII) until you know where it is. The scanner shows you where it sits. It does not make a site compliant on its own, and it is not legal advice.
What it scans (free)
- Users and user meta (including WooCommerce billing and shipping fields)
- Comments and comment meta, including spam, trash and WooCommerce order notes
- Posts, pages, custom post types, revisions, drafts and post meta
- WooCommerce orders and customers (HPOS and legacy storage)
- WooCommerce coupon email restrictions
- WooCommerce downloadable-product permissions and the download log (IP addresses)
- Contact Form 7 submissions stored by Flamingo
- WPForms entries (WPForms Pro stores entries; Lite does not)
- Gravity Forms entries
- The options table, including serialized and JSON values
What it detects
- Email addresses
- Phone numbers (international and common national formats)
- IP addresses (v4 and v6)
- IBANs, validated with the ISO 13616 checksum
- Payment card numbers, validated with the Luhn check and issuer ranges
- National ID numbers: German Steuer-ID, UK National Insurance number, US SSN, Georgian personal number, Italian codice fiscale, Spanish DNI/NIE, Dutch BSN
- VAT / tax ID numbers: Germany, France, Italy, each checked with its own real checksum
- Dates of birth in labelled fields or next to a birth keyword
- Names in labelled fields (first name, last name, billing name, comment author)
- Addresses in labelled fields (address, billing/shipping address, street, and common non-English equivalents)
- API keys and secrets: AWS, GitHub, Stripe, OpenAI, Anthropic, Google, Slack, JWTs, and PEM/SSH private keys
- Health keywords and ICD-10 codes for the special-category angle (off by default)
Every finding carries a confidence score so you can focus on the sure things first.
Privacy by design
- The plugin stores masked values only, for example
j***@example.comorDE89**************3000. It never becomes a second copy of your personal data. - Nothing leaves your server. The scan runs entirely inside your WordPress install and the plugin makes no outbound requests. There is no telemetry.
- Every action requires the
manage_optionscapability and a nonce.
Working with findings
- Filter by source, type, confidence and status; search labels and masked values
- Open the record in its own edit screen with one click
- Bulk Ignore, which stays in effect for future scans until you reopen it
- Printable on-screen report with a source-by-type matrix and the records holding the most personal data
- WP-CLI:
wp pdscan scan,wp pdscan status,wp pdscan findings,wp pdscan info
Pro
Delete and anonymize findings (WooCommerce-aware), retention rules, scheduled scans with email summaries, data subject request lookup by email address, custom detectors and custom sources, CSV export. Pro buttons are visible in the free version; clicking one links to the Pro pricing page.
Developers
- Add a data source: implement
PDScan\Scan\SourceInterfaceand hookpdscan/sources - Add a detector: implement
PDScan\Scan\DetectorInterfaceand hookpdscan/detectors - Add a national ID format in
src/Scan/Detectors/national-ids.phpor viapdscan/national_ids - Add a secret/API key format in
src/Scan/Detectors/secret-keys.phpor viapdscan/secret_keys - Add a VAT/tax ID format in
src/Scan/Detectors/vat-ids.phpor viapdscan/vat_ids - Filters:
pdscan/is_pro,pdscan/batch_findings,pdscan/keep_scans,pdscan/health_keywords,pdscan/woocommerce/hpos,pdscan/posts/skip_types,pdscan/options/skip_names - The admin screens are a React app. Source is in
assets/src/, shipped alongside the builtassets/build/index.jsit compiles to. Rebuild withnpm installthennpm run build(useswebpack.config.jsand@wordpress/scripts); nothing outside WordPress core’s own bundled@wordpress/*packages is used.
Installation
- Upload the plugin folder to
/wp-content/plugins/or install it from the Plugins screen. - Activate it.
- Open the new Personal Data menu in the WordPress admin and click Scan now.
- Or run
wp pdscan scanwith WP-CLI.
Scans run in batches and resume where they left off, so large sites with tens of thousands of comments and orders are fine.
Frequently asked questions
Does any data leave my server?
No. Scanning runs entirely on your server and the plugin makes no outbound requests of any kind.
Does it store the personal data it finds?
No. It stores a masked version of each value plus a link to the record it was found in. Uninstalling the plugin drops its tables.
Why does it report my own admin email?
Because it is personal data sitting in the options table. Findings on reserved domains like example.com get a low confidence. Use Ignore for anything you have reviewed.
Does it detect names in free text?
No. Name detection in prose is noisy and slow. The scanner reports names only in fields whose name says it is a name (first_name, billing_last_name, comment author, and so on).
Does it work with WooCommerce High-Performance Order Storage?
Yes. Both HPOS tables and legacy post-based orders are supported, and the mode is detected automatically.
Can I add my own country’s ID format?
Yes. Formats live in one config file with a pattern, an optional checksum validator and a confidence. Pull requests welcome.
Is this legal advice?
No. The scanner shows you where personal data sits. What you must do with it depends on your jurisdiction and your lawful basis for processing.
Why does Plugin Check report direct database call warnings?
By design. A personal data scanner has to read raw tables in batches to find data other tools don’t know to look for, which is exactly what the object cache and WP_Query are not built for. Every query is still safely prepared with $wpdb->prepare(); the warnings that remain are false positives from table names built with $wpdb->prefix, which Plugin Check cannot statically tell apart from user input. No warning involves unescaped user-supplied data.
Changelog
Metadata only, no functional changes.
0.1.4
- Plugin header now links to the author site. Readme keywords updated (HIPAA, CCPA).
0.1.3
- New detector: VAT/tax ID numbers (Germany, France, Italy, checksum-validated).
- New sources: WooCommerce coupon email restrictions, WooCommerce download permissions and log, Gravity Forms entries.
0.1.2
- Pro upsell now links to personaldatascanner.com/pricing instead of a “notify me” email signup – Pro is available for purchase now.
0.1.1
- Two new detectors: addresses in labelled fields, and API keys/secrets (AWS, GitHub, Stripe, OpenAI, Anthropic, Google, Slack, JWTs, PEM/SSH private keys).
0.1.0
- Initial release: eight data sources, nine detectors, admin dashboard, findings, report and settings screens, WP-CLI commands, persistent ignore list.
For developers
Is this your plugin? Show off the numbers.
Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.
Best DigitalSpace Personal Data Sc… alternatives
All CCPA plugins →FAQ
DigitalSpace Personal Data Scanner: quick answers
Straight answers, pulled from live WordPress.org data.
Live data from WordPress.org · checked Oct 5, 2026
Is DigitalSpace Personal Data Scan… free?
Yes. DigitalSpace Personal Data Scan… is free to download and use from the official WordPress.org plugin directory.
Is DigitalSpace Personal Data Scan… safe to use in 2026?
DigitalSpace Personal Data Scan… is a solid plugin choice in 2026, with a few things worth checking first. Was last updated 1 week ago, and scores 64/100 on our health check.
How many websites use DigitalSpace Personal Data Scan…?
DigitalSpace Personal Data Scan… is active on <10 WordPress websites and has been downloaded 233 times since it launched in September 2026. It was downloaded 233 times in the last 30 days.
Does DigitalSpace Personal Data Scan… work with WordPress 7.1?
Yes. The developer has tested DigitalSpace Personal Data Scan… up to WordPress 7.1.2, the latest release. It requires WordPress 6.0 or newer.
What PHP version does DigitalSpace Personal Data Scan… need?
DigitalSpace Personal Data Scan… requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.
When was DigitalSpace Personal Data Scan… last updated?
The latest version, 0.1.4, was released on September 24, 2026 (1 week ago).
Who makes DigitalSpace Personal Data Scan…?
DigitalSpace Personal Data Scan… is developed and maintained by Digital Space LLC.
What are the best alternatives to DigitalSpace Personal Data Scan…?
The most popular alternatives to DigitalSpace Personal Data Scan… are CookieYes (1M+ installs), Complianz GDPR/CCPA Cookie… (1M+ installs) and Cookie Compliance for WordP… (800K+ installs).
Powered by PageForge
Want thousands of pages that rank like these? Build them in an afternoon.
This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.
- CSV, Google Sheets & API data sources
- AI content, schema & internal links per page
- Works with Elementor, Gutenberg, Yoast & Rank Math
- Free on WordPress.org — no credit card



