Security advisorywp2shell: WordPress core vulnerability. Confirm every site is on 6.8.6, 6.9.5, 7.0.2, or newer.

Read the advisory

More

Non-sensitive diagnostic data

What optional diagnostic data Security Ninja collects, what it never collects, and how Freemius and GDPR fit in.

We do not collect usage data from wordpress.org installs by default. That makes it harder to see how the free plugin is used in the wild, so we may ask you to opt in to non-sensitive diagnostic tracking.

What is collected when you opt in

  • Name and email of the WordPress user installing the plugin
  • Site URL
  • WordPress version
  • PHP version
  • Plugin status (activation, deactivation, uninstall)
  • Plugin version

We never receive security-related information about your website. We do not see security test results, firewall settings, or which vulnerabilities are present on your site.

You can say no

If you decline, we get no information about you or your site. The free plugin works the same either way.

On Pro, the plugin must contact the Freemius license servers for license checks and updates. That licensing traffic is separate from optional analytics opt-in on the free plugin.

We use Freemius

Freemius for WordPress

We use Freemius for licensing, payments, updates, and related business tooling so we can focus on product work.

Questions about tracking: use the help page.

GDPR

Freemius is GDPR-oriented for this flow. To request deletion of account records when you stop using the plugin, use our GDPR removal form.

Still stuck? Get help or contact us.