Run a scan

AllScanTool — The rule-based code scanner

Built for developers performing rule-based security audits across PHP and WordPress platforms.

Scan Free → Review Results → Download Report

Catch security flaws in your code before your clients do

Scan your code. Get a list of findings. Pick what to fix.

Scan Free → Review Results → Download Report

app.allscantool.com/scan
Paste source code or drop a file…
0
Lines Scanned
0ms
Processing Time
4
Platform Engines
12
Issues Found
File Issue Severity Status
welcome-widget.php Unescaped SQL query Critical FIXED
theme.liquid Hardcoded API key Critical PENDING
embed-tiktok.js No GDPR consent gate Warning PENDING
youtube-iframe.js Visitor IP sent to Google Warning PENDING
fb-pixel.js Fires before consent Warning FIXED
footer.php Unsafe input handler Info PENDING

Export Report

Active Scan Engines

WordPress
Shopify
TikTok
YouTube
File Issue Severity Status
header.php eval() in template Critical FIXED
custom-script.js XSS handler without sanitization Warning PENDING
theme-settings.liquid Missing integrity hash Info FIXED
🔒

Rule-Based

Run scans directly through the scanning interface with clear, rule-based results.

🚫

Clear Process

Review findings, choose what to keep, and export a report.

⏱️

Clear Results

Results are organized so issues can be reviewed and understood.

🌐

Exportable Reports

Export findings as PDF or TXT reports.

How It Works

Three steps. Paste, scan, and review.

1

Paste Your Source Code

Drop in PHP, JavaScript, HTML, CSS, Liquid, or any plain-text source from a WordPress plugin, Shopify theme, TikTok embed, or YouTube integration.

2

The Engine Scans Your Code

The Delivery-Layer Engine applies scanning rules and returns findings you can review. Results appear in seconds.

3

Review Findings and Download Report

Review findings by severity. Export a PDF or TXT report. Choose what to address.

What AllScanTool Detects

Targeted rules for the platforms freelancers deliver code on.

WordPress

  • [Critical] eval() in theme or plugin code
  • [High] Direct DB queries without escaping
  • [Medium] Unsanitized echo of user input
  • [Low] AJAX handler without nonce check

Shopify

  • [Critical] Unescaped customer object in Liquid
  • [High] Hardcoded API key in theme.js
  • [Medium] Insecure external script in theme
  • [Low] Missing integrity hash on CDN asset

TikTok

  • [High] Embed fires without GDPR consent
  • [Medium] Visitor data sent on page load
  • [Low] Missing click-to-load wrapper

YouTube

  • [High] Visitor IP sent to Google on load
  • [Medium] No consent wrapper for embed
  • [Low] Autoplay without user gesture

Trust & Security

AllScanTool presents scanning features and results in a clear, structured workflow.

🔒

Controlled Scanning

The scanner performs defined checks and presents the findings for review.

📡

Report Tools

Review findings and use the available report tools after scanning.

👁️

Clear Findings

Findings are organized so issues can be reviewed and understood.

Transparent Process

The scanning process is presented in clear steps so users can understand what the tool does.