Skip to content
SitesProof
Known plugin vulnerabilities

The advisory that names the version you are running.

65% of agencies call plugin and theme updates their biggest security problem, rising to 75% at a hundred sites or more — where 45% still update one site at a time (CloudLinux, 2026).

The problem

Forty sites, and the feed moves every day

New advisories land daily and almost all of them are against third-party plugins. Keeping up means knowing which of your forty sites runs the plugin named in today’s advisory, and at which version — a question about the whole portfolio, asked every week. No single site’s dashboard can answer it, which is why the answer usually arrives as a client phoning you.

How it works

How known plugin vulnerabilities works

  1. 1

    Read the versions off the public pages

    Plugin and theme slugs and version numbers from the site’s own asset URLs and its generator tag. No login, no credentials and nothing installed — only what the site already tells every visitor.

  2. 2

    Match against the feed

    Wordfence Intelligence advisories, refreshed daily, with the affected version ranges compared properly rather than by string. It is free for commercial use, which is part of why this can be priced per site.

  3. 3

    Report the advisory, not a verdict

    A finding says this version is named in this advisory, with the CVE id where there is one, and it is graded on the advisory’s CVSS score. It does not say the site has been, or can be, compromised.

Why it matters

What you get

A daily feed, a weekly crawl

The advisory list refreshes daily and the site is re-read weekly, so a finding is a current advisory against a version seen recently — not a match made once when you added the site.

An unknown version is not a worst case

Where a plugin has advisories but no readable version, we say the version is unknown, at info severity. Grading it by the worst advisory ever filed against that plugin would put a 9.8 on a client’s report for a site that may well be patched.

WordPress is a bonus, not the premise

This is the one check that only applies to WordPress. The other five read any stack, so a portfolio of Shopify, Webflow and hand-built sites is still a portfolio this monitors.

FAQ

Questions, answered

Do you log into the WordPress admin?

No. Versions come from public asset URLs and the generator tag, so there are no credentials to hand over and nothing of ours running on the site. The trade-off is honest: a version read from a URL can be stale, so confirm it in the admin before you act on it.

Does a finding here mean the site is hacked?

No. It means a published advisory names the version we detected. That is a reason to update and a reason to tell the client you are watching; it is not a statement about whether anything happened.

Start with one page.

Paste a client’s checkout address and see what a crawl reports. No account, no card, and the report has a link you can send to anyone.

Scan a page free