BLACK FRIDAY
Save 59% on PageForge Annual $191/year $485/year
Claim 59% Off →
PreFlight Scanner icon
Actively maintained Tested up to 7.0.6 #3 in conflict

PreFlight Scanner

Scan any plugin ZIP for PHP conflicts, class/function collisions, hook priority conflicts, and malicious code — before installing.

Active installs<10New
Downloads · 30d43▲ +10.3% vs prev. 30d
Rating—0 reviews
Health score55/100Fair
All-time downloads190Since Jun 2026
Support resolved—No recent threads
RequiresWP 5.9PHP 7.4+
Downloads · 7d12▲ +20% week over week
Our verdict

Use with caution

PreFlight Scanner works, but test it on a staging site before relying on it in 2026. Was last updated 2 months ago, and scores 55/100 on our health check.

  • Small user base (<10 active installs)
  • Very few reviews so far

How does it stack up?

Side-by-side on installs, updates, ratings & support

Daily downloads

3710Jul 1Aug 14Sep 28
Yesterday0
Daily average (1y)2
Peak day16Jun 30, 2026
Last 12 months190

Download spikes usually follow a new release — each site that auto-updates counts as a download.

Rankings

Where PreFlight Scanner stands today

WordPress.org search rankings

Live position in the plugin search, top 100
KeywordPositionCompeting pluginsCategory
conflict >100 6,243 Best conflict plugins →
malware >100 410 Best malware plugins →
plugin check >100 10,000 Best plugin check plugins →
scanner >100 1,331 Best scanner plugins →
security >100 10,000 Best security plugins →

About PreFlight Scanner

From the official readme · v1.0.3

Description

PreFlight Scanner lets you upload any plugin .zip and run a comprehensive static safety scan before it ever touches your live WordPress environment. No plugin code is executed during the scan.

One bad plugin can white-screen an entire e-commerce store. PreFlight catches the problems before they happen.

What PreFlight Scanner checks

Version Compatibility

  • PHP version compatibility — reads the plugin header and detects modern syntax your server cannot run (match expressions, nullsafe operators, typed properties, arrow functions, etc.)
  • WordPress version compatibility — validates Requires At Least and Tested Up To headers against the running site

Collision Detection

  • Function name collisions — detects global functions that already exist in the active environment; a guaranteed PHP fatal error
  • Class name collisions — same result, often harder to diagnose
  • Hook priority conflicts — two plugins registering the same add_filter() hook at the same priority silently overwrite each other’s return value; a common source of checkout and pricing bugs on WooCommerce sites

Security — Critical

  • Obfuscated and malicious code patterns (eval/base64, compressed payloads, preg_replace /e modifier, large base64 blobs)
  • Dangerous PHP functions — shell_exec, exec, system, passthru, proc_open, popen, pcntl_exec
  • Suspicious file types inside the ZIP — .exe, .sh, .bat, .cmd, .py, .rb, .pl, .vbs

Warnings & Best Practices

  • Missing PHP namespaces — files that define global functions or classes without a namespace declaration are at elevated collision risk as the site grows
  • Deprecated WordPress functions — code that generates notices or breaks on current and future WordPress versions
  • Suspicious outbound HTTP calls — wp_remote_get/post(), curl_exec(), file_get_contents() with hardcoded external URLs
  • Direct database queries — raw $wpdb->query() and string-concatenated SELECT statements that risk SQL injection
  • Missing nonce and capability checks — files that read $_POST/$_GET without check_admin_referer() or current_user_can()

After the scan

  • ALL CLEAR — one click to install immediately, then activate from the Plugins page.
  • WARNINGS FOUND — advisory issues; review and decide whether to proceed.
  • CRITICAL ISSUES — a confirmation dialog warns you before proceeding; installing is strongly discouraged.

Privacy

PreFlight Scanner performs all analysis locally on your own server. No data is sent anywhere. No external HTTP requests are made.

PreFlight Pro

Upgrade to PreFlight Pro for continuous monitoring of your already-installed plugins:

  • Scheduled background scans — automatically re-scan all active plugins daily or weekly
  • Site risk score — dashboard widget with a 0–100 risk score across all active plugins
  • WooCommerce hook rules — deeper conflict detection for checkout, cart, pricing, and payment hooks
  • Scan history — every scan saved and browsable with full results
  • Email alerts — get notified when a scheduled scan finds critical issues or warnings
  • CSV export — export scan history for client reports

Starter ($49 / 1 site) • Pro ($129 / 5 sites) • Agency ($299 / 25 sites)

Installation

  1. Upload the preflight-scanner folder to the /wp-content/plugins/ directory, or install via the WordPress Plugins screen.
  2. Activate the plugin through the Plugins menu in WordPress.
  3. Navigate to Tools → PreFlight Scanner.
  4. Upload any plugin .zip file and click Run Pre-Flight Scan.

Frequently asked questions

Does this plugin execute the uploaded plugin’s code?

No. PreFlight Scanner performs static analysis only — it reads and parses PHP files as plain text without executing them. The ZIP is opened entirely in memory using PHP’s ZipArchive. No files are extracted to disk.

Can I install a plugin that has warnings?

Yes. Warnings are advisory — the plugin may still work correctly on your site. The scan results give you the information to make an informed decision.

Can I install a plugin that has critical (DANGER) issues?

You can, but a confirmation dialog warns you strongly against it. Critical issues typically mean a PHP fatal error is guaranteed on activation.

Does it scan plugins already installed on my site?

No. PreFlight Scanner is a pre-installation tool. To audit an already-installed plugin, deactivate it, download its ZIP, and upload that ZIP for scanning.

How long are scan results stored?

Scan results and the temporary staging directory are automatically deleted after 5 minutes. If you close the browser mid-scan, leftover data is cleaned up on the next page load.

Is PreFlight Scanner safe to use on production sites?

Yes. The scanner is fully read-only. It never modifies any plugin files, settings, or database values outside of its own short-lived transients.

What user role is required?

The Tools → PreFlight Scanner page requires the install_plugins capability, which is reserved for Administrators by default.

Why are some common hooks like “init” not flagged even when active plugins use them?

Hooks that every WordPress install registers many callbacks on (init, wp_head, admin_init, etc.) are excluded from hook-conflict reporting to avoid noise. The conflict check focuses on non-core hooks — plugin-specific filters, WooCommerce hooks, and other hooks where a collision is genuinely surprising.

What happens to the uploaded ZIP after scanning?

The ZIP is read entirely in memory and never written to disk. PHP’s standard file upload handling manages the temporary file and deletes it automatically at the end of the request.

Changelog

1.0.3

  • ZIP is now read entirely in memory via ZipArchive — no files are extracted to disk, eliminating staging directory and .htaccess requirements.
  • Added PreFlight Pro upsell in the admin UI.

1.0.1

  • Use wp_handle_upload() for file uploads instead of move_uploaded_file().
  • Use Plugin_Upgrader (WordPress standard API) for plugin installation instead of direct filesystem copy.
  • Use wp_upload_dir() for staging directory path to respect custom upload locations.
  • Remove load_plugin_textdomain() call — handled automatically by WordPress since 4.6.
  • Installation no longer auto-activates the plugin; user activates from the Plugins page.

1.0.0

  • Initial release.
  • 13 checks across version compatibility, collision detection, security, and best practices.
  • Pre-install ZIP upload pipeline with static analysis and one-click installation.
  • Hook priority conflict detection against the live active-plugin environment.
  • PHP namespace check for global function and class declarations.

Full changelog on WordPress.org →

For developers

Is this your plugin? Show off the numbers.

Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.

Active installs badge Rating badge Health score badge

Best PreFlight Scanner alternatives

All conflict plugins →

FAQ

PreFlight Scanner: quick answers

Straight answers, pulled from live WordPress.org data.

Live data from WordPress.org · checked Sep 29, 2026

Is PreFlight Scanner free?

Yes. PreFlight Scanner is free to download and use from the official WordPress.org plugin directory.

Is PreFlight Scanner safe to use in 2026?

PreFlight Scanner works, but test it on a staging site before relying on it in 2026. Was last updated 2 months ago, and scores 55/100 on our health check.

How many websites use PreFlight Scanner?

PreFlight Scanner is active on <10 WordPress websites and has been downloaded 190 times since it launched in June 2026. It was downloaded 43 times in the last 30 days.

Does PreFlight Scanner work with WordPress 7.1?

PreFlight Scanner is officially tested up to WordPress 7.0.6, while the latest release is 7.1.2. It may still work, but try it on a staging site first.

What PHP version does PreFlight Scanner need?

PreFlight Scanner requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.

When was PreFlight Scanner last updated?

The latest version, 1.0.3, was released on July 17, 2026 (2 months ago).

Who makes PreFlight Scanner?

PreFlight Scanner is developed and maintained by Tim Boulley.

What are the best alternatives to PreFlight Scanner?

The most popular alternatives to PreFlight Scanner are Block editor assets filter (10+ installs), Conflict Guard (<10 installs) and Tahhan Conflict Detective (<10 installs).

Powered by PageForge

Want thousands of pages that rank like these? Build them in an afternoon.

This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.

  • CSV, Google Sheets & API data sources
  • AI content, schema & internal links per page
  • Works with Elementor, Gutenberg, Yoast & Rank Math
  • Free on WordPress.org — no credit card
Sarah is here to help!
Hi there! 👋 Need help finding what you're looking for?
Sarah
Sarah
Online & Ready to Help
Hi there! 👋 Need help finding what you're looking for?

We'll use this to continue our conversation

Just now ✓ Verified

Join 500+ SEO Pros Scaling Their Strategy

Get exclusive programmatic SEO tactics, AI content workflows, and the latest PageForge updates delivered straight to your inbox. Stay ahead of the algorithm.

We care about your data in our privacy policy.