Security Ninja downloads a public vulnerability list and stores it locally so comparisons can run on your server.
Files live under:
/wp-content/uploads/security-ninja/vulns/
Typical names:
plugins_vulns.jsonl.gzthemes_vulns.jsonl.gzwordpress_vulns.jsonl.gz
Nothing about which plugins you run is uploaded back with those list files. When a check runs, the plugin loads the local list and compares it to what is installed right now.
The lists are not stored in the WordPress database. A few compressed files keep memory and database size down compared with storing thousands of reference rows in MySQL.
Older documentation mentioned an outdated.dat file used for a separate “outdated plugins” list. That list is no longer part of the product. The current scanner uses the vulnerability database files above.
Having trouble writing or reading these files? See Problems with the vulnerability scanner.