@gsuberland Unless you're worried about plugins dynamically creating bad permissions, scanning at plugin install time, before installing, would make a lot more sense. Catch the vuln before it's deployed rather than after you've been popped. And no resource thrashing.