The vulnerability scanner is included in both Free and Pro. It compares your installed plugins, themes, and WordPress version against a regularly updated list of known vulnerabilities and alerts you when something needs an update or replacement.
How detection works
- The plugin downloads a vulnerability list from our API (sourced from open databases such as the National Vulnerability Database (NVD)).
- Checks run locally on your server. Your installed software is compared to that list on the site itself.
- If a match is found, you see an alert with guidance (update, replace, or note if a plugin is discontinued).
No details about your site’s vulnerabilities are sent back to our servers. Only the vulnerability list is downloaded.
What is a vulnerability?
A vulnerability is a known weakness in software that attackers can exploit. It can affect plugins, themes, or WordPress core. We aggregate public vulnerability data so you can act before an issue is exploited on your site.
What to do when something is flagged
- Check for an available update and apply it when safe (ideally after a backup).
- If there is no update, look for a maintained alternative or follow the recommendation shown in the plugin.
- Enable email alerts if you do not log in every day.
