WordPress 7.1.2: critical core security fix. Update now, then check inactive themes and comments.

Details

Vulnerabilities

Vulnerability database files

Where Security Ninja stores local vulnerability list files under uploads, and why they are not kept in the database.

Security Ninja downloads a public vulnerability list and stores it locally so comparisons can run on your server.

Files live under:

/wp-content/uploads/security-ninja/vulns/

Typical names:

  • plugins_vulns.jsonl.gz
  • themes_vulns.jsonl.gz
  • wordpress_vulns.jsonl.gz

Nothing about which plugins you run is uploaded back with those list files. When a check runs, the plugin loads the local list and compares it to what is installed right now.

The lists are not stored in the WordPress database. A few compressed files keep memory and database size down compared with storing thousands of reference rows in MySQL.

Older documentation mentioned an outdated.dat file used for a separate “outdated plugins” list. That list is no longer part of the product. The current scanner uses the vulnerability database files above.

Having trouble writing or reading these files? See Problems with the vulnerability scanner.

Still stuck? Get help or contact us.

Larger screenshot

Enlarged image