I’m seeing the same issue on XAMPP locally running 3.31.
Interestingly, the scanner flags some of its own files as a vulnerability:
Vulnerable 0 cg-tvs-filescanner.php C:\xampplite\htdocs\wordpress/wp-content/plugins/timthumb-vulnerability-scanner/cg-tvs-filescanner.php
Vulnerable 0 class-cg-tvs-filescanner.php C:\xampplite\htdocs\wordpress/wp-content/plugins/timthumb-vulnerability-scanner/class-cg-tvs-filescanner.php