The advisory that names the version you are running.
65% of agencies call plugin and theme updates their biggest security problem, rising to 75% at a hundred sites or more — where 45% still update one site at a time (CloudLinux, 2026).
The problem
Forty sites, and the feed moves every day
New advisories land daily and almost all of them are against third-party plugins. Keeping up means knowing which of your forty sites runs the plugin named in today’s advisory, and at which version — a question about the whole portfolio, asked every week. No single site’s dashboard can answer it, which is why the answer usually arrives as a client phoning you.
How it works
How known plugin vulnerabilities works
- 1
Read the versions off the public pages
Plugin and theme slugs and version numbers from the site’s own asset URLs and its generator tag. No login, no credentials and nothing installed — only what the site already tells every visitor.
- 2
Match against the feed
Wordfence Intelligence advisories, refreshed daily, with the affected version ranges compared properly rather than by string. It is free for commercial use, which is part of why this can be priced per site.
- 3
Report the advisory, not a verdict
A finding says this version is named in this advisory, with the CVE id where there is one, and it is graded on the advisory’s CVSS score. It does not say the site has been, or can be, compromised.
Why it matters
What you get
A daily feed, a weekly crawl
The advisory list refreshes daily and the site is re-read weekly, so a finding is a current advisory against a version seen recently — not a match made once when you added the site.
An unknown version is not a worst case
Where a plugin has advisories but no readable version, we say the version is unknown, at info severity. Grading it by the worst advisory ever filed against that plugin would put a 9.8 on a client’s report for a site that may well be patched.
WordPress is a bonus, not the premise
This is the one check that only applies to WordPress. The other five read any stack, so a portfolio of Shopify, Webflow and hand-built sites is still a portfolio this monitors.
FAQ
Questions, answered
Do you log into the WordPress admin?
No. Versions come from public asset URLs and the generator tag, so there are no credentials to hand over and nothing of ours running on the site. The trade-off is honest: a version read from a URL can be stale, so confirm it in the admin before you act on it.
Does a finding here mean the site is hacked?
No. It means a published advisory names the version we detected. That is a reason to update and a reason to tell the client you are watching; it is not a statement about whether anything happened.
Features
More features
White-label client reports
One PDF per client per month, carrying your logo, your colours and their name. Nothing in it mentions us except the disclaimer.
Learn morePayment-page scripts
Every script on a page that really takes card details, inventoried and hashed, so a change in the set or in a body is something you hear about.
Learn moreCookies before consent
The crawl loads each site cold, as a first-time visitor, and reports the cookies set and the trackers fired before anyone agreed to anything.
Learn moreStart with one page.
Paste a client’s checkout address and see what a crawl reports. No account, no card, and the report has a link you can send to anyone.