Cannot create folder or write vulnerability files
You may see PHP warnings in debug.log when Security Ninja cannot create directories or write files under uploads, for example:
Warning: mkdir(): No such file or directory in .../plugins/security-ninja/modules/vulnerabilities/...
Warning: file_put_contents(.../uploads/security-ninja/vulns/...): failed to open stream: No such file or directory
The vulnerability scanner needs to store compressed list files under:
/wp-content/uploads/security-ninja/vulns/
See Vulnerability database files.
Common causes
- Custom permissions on
/wp-content/uploads/that block the web user from creating folders or files - Hardening rules (including
.htaccessor host “protect uploads” features) that block writes or downloads into uploads - Disk full, or a host that quarantines new files under uploads
What to try
- Confirm
/wp-content/uploads/is writable by WordPress. - Temporarily relax extra upload protection while you activate Security Ninja or force a vulnerability list refresh, then turn protection back on.
- Check that
security-ninja/vulns/exists after a refresh and that the.jsonl.gzfiles appear. - If a host malware scanner deletes those files because they contain CVE descriptions, allowlist the
security-ninja/vulns/path. The lists are reference data, not an infection on your site.
Still stuck? Contact support with the exact warning lines from debug.log.