Free for everyone

WP Security Ninja

Know which plugins, themes, and WordPress core put you at risk

Security Ninja’s free WordPress vulnerability scanner checks your installed software against known CVEs and security issues, included on every free and Pro install.

  • ✓ Plugins, themes & core
  • ✓ CVE / known issues
  • ✓ Free for everyone
Know which plugins, themes, and WordPress core put you at risk

YouTube channel

Watch the walkthrough

See how Security Ninja finds known plugin and theme vulnerabilities before attackers do.

Vulnerable WordPress Plugin? Catch It Before It Becomes a Problem

See known risks before bots do

Outdated plugins are one of the most common WordPress attack paths. The scanner matches your installed versions against a regularly updated database of known vulnerabilities so you can update, replace, or remove risky components.

  • ✓ Scan plugins, themes, and WordPress core
  • ✓ Clear warnings tied to known issues and CVE IDs
  • ✓ Included free on every Security Ninja install
How the scanner works

When a vulnerability is found, act

A match means your site is running software with a publicly known flaw. Prefer updating first. If no patch exists, replace or remove the plugin or theme. Deactivated plugins can still be a risk if they remain on the server. For the July 2026 WordPress core wp2shell advisory, affected versions, fixed releases, and post-update checks, use our permanent security note.

  • ✓ Update when a fixed version is available
  • ✓ Replace or remove abandoned and closed plugins
  • ✓ Treat findings seriously even if the plugin is deactivated
Read the wp2shell advisory

Add Pro when you want alerts and deeper cover

Finding known vulnerabilities is step one. Pro adds email alerts, a faster vulnerability database refresh, plus Cloud Firewall, malware scanning, login protection, and 2FA while you patch.

  • ✓ Email alerts when vulnerabilities are detected
  • ✓ Daily vulnerability database updates (weekly on Free)
  • ✓ Firewall, malware scanning, and 2FA while you fix issues
See all features

Free vs Pro

Vulnerability scanning is free. Pro adds alerts and faster updates.

Every site can check plugins, themes, and core for known issues. Upgrade when you want email warnings and the rest of the protection stack.

Forever free

Free

A WordPress vulnerability scanner for every site - no license required.

  • Scan plugins, themes, and WordPress core
  • Dashboard results for known CVEs and issues
  • Weekly vulnerability database refresh
  • Works with the free Security Ninja plugin
Download Free

Recommended

Pro

Same scanner, plus alerts and the tools that protect you while you patch.

  • Everything in Free
  • Email alerts for detected vulnerabilities
  • Daily vulnerability database refresh
  • Cloud Firewall, malware scanning, login & 2FA
See Pro pricing

Built for the risks WordPress sites actually face

Most WordPress compromises start with outdated or abandoned plugins. The free scanner turns that into a clear checklist.

Known plugin and theme CVEs

When a vulnerability is published and catalogued (often with a CVE ID from sources like the National Vulnerability Database), the scanner can flag matching versions on your site.

Outdated and abandoned plugins

Software that never gets updates stays vulnerable forever. Security Ninja highlights known issues so you can update, replace, or remove before automated attacks find them.

WordPress core vulnerabilities

Core gets security releases too. The scanner checks your WordPress version against known core issues so you are not relying on memory alone.

Vulnerability docs

Customer reviews

4.9 / 5 from 254 reviews

Leave a review

★★★★★

“Great plugin! Allowed me to save a lot of time”

Dezio

★★★★★

“Hi, I bought Security Ninja and Login Ninja. I must say they’re great and my website is much more secure now. I had quite a lot of security issues on my website, but they’re all fixed now thanks to the plugin.”

wdlb

★★★★★

“Exceptionally awesome.”

Pippin Williamson

Frequently asked questions

What is a CVE?+

CVE stands for Common Vulnerabilities and Exposures. It is a public ID (for example CVE-2024-1234) that names a specific security flaw so researchers, tools, and site owners can talk about the same issue. Many WordPress plugin and theme vulnerabilities are assigned CVE IDs and listed in databases such as the National Vulnerability Database (NVD).

What is a WordPress vulnerability?+

A WordPress vulnerability is a known weakness in WordPress core, a plugin, or a theme that attackers can exploit, for example to inject scripts, escalate privileges, or take over a site. Most documented WordPress vulnerabilities live in plugins. Updating or removing the affected software is the usual fix.

Is the vulnerability scanner free?+

Yes. The WordPress vulnerability scanner is included in the free Security Ninja plugin for everyone, free and Pro installs. You can scan plugins, themes, and core without a paid license.

How does the WordPress vulnerability scanner work?+

Security Ninja compares the versions of your installed plugins, themes, and WordPress core against a regularly updated database of known vulnerabilities. When your version matches a published issue, you see a clear warning in the dashboard so you can update, replace, or remove the software.

Does it check plugins, themes, and WordPress core?+

Yes. The scanner reviews installed plugins, themes, and WordPress core for known security issues and CVE matches.

What should I do if a vulnerability is found?+

Update to a fixed version when one is available. If there is no patch, replace the plugin or theme with a maintained alternative, or remove it. Do not ignore findings on deactivated plugins, unused files on the server can still be exploited.

Does the scanner replace updating plugins?+

No. It tells you which installed software has known issues so you can update, replace, or remove it promptly. Keeping WordPress, plugins, and themes updated remains essential.

What is the difference between a vulnerability scanner and a malware scanner?+

A vulnerability scanner looks for known flaws in the software you already installed (CVEs and similar public advisories). A malware scanner looks for malicious or unexpected code in your files. Security Ninja includes vulnerability scanning for free; malware scanning is a Pro feature, and Core Scanner (also free) checks whether WordPress core files still match official originals.

Can it find zero-day exploits?+

No. Like other known-issue scanners, it only flags vulnerabilities after they are publicly documented and present in the vulnerability database. It cannot detect undisclosed zero-day flaws. Once an issue is published, a scan can alert you if your site is still running an affected version.

Are email alerts for vulnerabilities free?+

Scanning and dashboard results are free. Email alerts when vulnerabilities are detected are a Pro option. Free refreshes the vulnerability database weekly; Pro refreshes it daily.

Scan for known vulnerabilities free

Download Security Ninja for free CVE checks on plugins, themes, and core, or go Pro for email alerts, Cloud Firewall, malware scanning, and 2FA.

Get the free plugin