Skip to main content
Agency Program Get 2× more leads and save 50% on hosting. Built for agencies ready to grow. Book a call
WPVulnerability icon

WPVulnerability

v4.0.3
by Javier Casares · 5.0 (20 reviews)

Receive information about possible vulnerabilities in your WordPress from WordPress Vulnerability Database API.

10K+ active installs Updated Oct 28, 2024 Tested to 6.7.2 Requires PHP 5.6
Try Demo Download
Pre-installed Ready in ~10s No card
WPVulnerability

About WPVulnerability

This plugin integrates with the WPVulnerability API to provide real-time vulnerability assessments for your WordPress site. It delivers detailed reports within your WordPress dashboard and can send notifications about your site's security status. The plugin is designed for ease of use and does not store or retrieve any personal data from your site.

Screenshots

WPVulnerability screenshot
WPVulnerability screenshot
WPVulnerability screenshot

Frequently asked questions

What is WPVulnerability?
WPVulnerability is a WordPress plugin that integrates with the WPVulnerability API to provide real-time vulnerability assessments for your WordPress core, plugins, themes, and various server components. It helps you stay aware of potential security risks by delivering detailed reports directly within your WordPress dashboard.
How does WPVulnerability help with security?
The plugin provides real-time vulnerability assessments for WordPress core, plugins, themes, PHP, Apache HTTPD, nginx, MariaDB, MySQL, ImageMagick, curl, memcached, Redis, and SQLite. It can be configured to send periodic notifications about your site's security status, ensuring you remain informed without being overwhelmed.
Does WPVulnerability store personal data?
No, WPVulnerability does not store or retrieve any personal data from your site. It is designed for ease of use and supports proactive security measures while respecting user privacy.
How can I use WP-CLI with WPVulnerability?
WPVulnerability supports WP-CLI commands for managing and checking vulnerabilities across various components like core, plugins, themes, PHP, and databases. You can use commands like 'wp wpvulnerability core' or 'wp wpvulnerability plugins' and specify output formats like table or JSON.
What kind of information does the plugin provide?
The plugin provides information about possible vulnerabilities in your WordPress site, including its core, plugins, themes, and server environment. This data comes from the WPVulnerability Database API, which is reviewed by third parties.

Changelog

[4.0.3] – 2024-10-28

  • Recreation of the 4.0.2 version. Something did not created the 4.0.2 version.

[4.0.2] – 2024-10-25

Fixed

  • ImageMagick: it crashes in some cases where the hosting does not have ImageMagick.

Compatibility

  • WordPress: 4.1 – 6.7
  • PHP: 5.6 – 8.4
  • WP-CLI: 2.3.0 – 2.11.0

Tests

  • PHP Coding Standards: 3.10.3
  • WordPress Coding Standards: 3.1.0
  • Plugin Check (PCP): 1.1.0
  • SonarCloud Code Review

[4.0.1] – 2024-10-04

Fixed

  • API endpoints: some API endpoints were failing.
  • CLI endpoints: some CLI endpoints were failing.

Compatibility

  • WordPress: 4.1 – 6.7
  • PHP: 5.6 – 8.4
  • WP-CLI: 2.3.0 – 2.11.0

Tests

  • PHP Coding Standards: 3.10.3
  • WordPress Coding Standards: 3.1.0
  • Plugin Check (PCP): 1.1.0
  • SonarCloud Code Review

[4.0.0] – 2024-10-01

Added

  • ImageMagic vulnerabilities (Site Health + WP-CLI + API + mail).
  • curl vulnerabilities (Site Health + WP-CLI + API + mail).
  • memcached vulnerabilities (Site Health + WP-CLI + API + mail).
  • Redis vulnerabilities (Site Health + WP-CLI + API + mail).
  • SQLite vulnerabilities (Site Health + WP-CLI + API + mail).

Fixed

  • Test email without email.
  • Improved MariaDB 11.x detection.
  • Improved versions detection (major-minor.patch-build).
  • WordPress < 5.3: use of wp_date().
  • WordPress < 5.0: locale detection.
  • Dashboard widget only for users with capabilities.
  • WordPress < 5.2: link to Site Health

Changed

  • Big refactory.
  • Less files, less size, improved code quality.

Compatibility

  • WordPress: 4.1 – 6.7
  • PHP: 5.6 – 8.4
  • WP-CLI: 2.3.0 – 2.11.0

Tests

  • Manual Testing:
    • WordPress 6.7 / PHP 8.4
    • WordPress 6.6 / PHP 8.3
    • WordPress 6.4 / PHP 8.2
    • WordPress 6.1 / PHP 8.1
    • WordPress 5.8 / PHP 8.0
    • WordPress 5.5 / PHP 7.4
    • WordPress 5.3 / PHP 7.3
    • WordPress 4.9 / PHP 7.2
    • WordPress 4.8 / PHP 7.1
    • WordPress 4.6 / PHP 7.0
    • WordPress 4.1 / PHP 5.6
  • PHP Coding Standards: 3.10.3
  • WordPress Coding Standards: 3.1.0
  • Plugin Check (PCP): 1.1.0
  • SonarCloud Code Review

Previous versions

If you want to see the full changelog, visit the changelog.txt file.

Try other plugins