WPThumbs
Themes Plugins By purpose By industry Best-of lists Fix it guides
Free Plugin by OOPSpam Team v1.1.4

OOPVulns: Vulnerability Scanner

Monitor your WordPress site for security vulnerabilities in core, plugins, and themes.

OOPVulns: Vulnerability Scanner

The facts

Active installs
100+
Price
Free
Last updated
24 Jul 2026
Added
Mar 2026
Requires WP
5.8
Tested up to
WP 7.0.4
Requires PHP
7.4
Downloads
1,277

Our analysis

AI-assisted

OOPVulns is a WordPress plugin designed to monitor your site for known security vulnerabilities in the WordPress core, plugins, and themes. It scans for vulnerabilities using the OOPSpam vulnerability database and provides detailed information on any issues found. The plugin requires admin consent to enable scanning and can be configured for automatic scans on a daily or weekly basis.

The plugin features a modern dashboard that displays vulnerability information, severity indicators, and guidance on updates. It also includes a mechanism to monitor the maintenance status of plugins, helping to identify those that may be neglected. This plugin is suitable for site administrators looking to enhance their site's security by keeping track of potential vulnerabilities.

Best for: Site administrators who want to enhance their site's security by monitoring vulnerabilities.

What it does well

  • Continuously monitors for known vulnerabilities
  • Configurable automatic scanning options
  • Email notifications for detected vulnerabilities
  • Modern and accessible admin interface
  • Abandonment risk monitoring for plugins

Where it falls short

  • No published rating available
  • Limited information on user experience or support

Verdict

OOPVulns provides a focused approach to vulnerability scanning for WordPress sites. It offers essential features for security monitoring but lacks user feedback on its effectiveness.

From the developer

OOPSpam Team's own description of OOPVulns: Vulnerability Scanner, lightly tidied.

OOPVulns is a modern, accessible WordPress plugin that continuously monitors your site for known security vulnerabilities in WordPress core, plugins, and themes.

Features

  • Comprehensive Scanning Scans WordPress core, all plugins, and all themes for known vulnerabilities
  • Explicit Opt-In Vulnerability scanning is disabled by default and only runs after admin consent
  • Automatic Scans Configurable daily or weekly automatic scanning
  • Email Notifications Get notified when vulnerabilities are detected
  • Modern Dashboard Clean, accessible admin interface with detailed vulnerability information
  • Severity Indicators Color-coded severity levels (Critical, High, Medium, Low)
  • Update Guidance See which vulnerabilities have fixes available
  • Abandonment Risk Monitoring Detect neglected plugins with a WordPress.org-powered neglect score and maintenance badge

How It Works

The plugin checks your installed WordPress core version, plugin versions, and theme versions against the OOPSpam vulnerability database. It also checks WordPress.org plugin maintenance signals like last update date and recent unresolved critical support threads to highlight plugins that may be abandoned before a CVE is published. When a known vulnerability is found, you’ll see it in the dashboard and optionally receive an email notification.

External Service

This plugin connects to the OOPSpam API and WordPress.org services to retrieve vulnerability and maintenance information. When a scan runs, the following data is sent:

  • WordPress core version
  • Plugin slugs and versions
  • Theme slugs and versions

WordPress.org requests use plugin slugs to retrieve plugin last-updated timestamps and public support forum activity. No personal data, user information, or site content is transmitted.
Vulnerability API checks are disabled by default and only run after an administrator explicitly enables scanning in plugin settings.

Read the full description on the official page →

Tagged as

Alternatives

Other plugins for securing a site.

Really Simple Security

Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vuln...

Free 3M+ installs 4.9★ (8,862)
Wordfence Security

Firewall, Malware Scanner, Two Factor Auth, and Comprehensive Security Features, powered by our 24-hour team....

Free 5M+ installs 4.7★ (4,983)
Akismet Anti-spam: Spam Protection

The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam sol...

Free 5M+ installs 4.7★ (1,186)
Loginizer

Loginizer is a WordPress security plugin which helps you fight against bruteforce attacks.

Free 1M+ installs 4.8★ (1,030)
Safe SVG

Enable SVG uploads and sanitize them to stop XML/SVG vulnerabilities in your WordPress website.

Free 1M+ installs 4.9★ (79)
All-In-One Security

Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plu...

Free 1M+ installs 4.7★ (1,715)