Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vuln...
Monitor your WordPress site for security vulnerabilities in core, plugins, and themes.
OOPVulns is a WordPress plugin designed to monitor your site for known security vulnerabilities in the WordPress core, plugins, and themes. It scans for vulnerabilities using the OOPSpam vulnerability database and provides detailed information on any issues found. The plugin requires admin consent to enable scanning and can be configured for automatic scans on a daily or weekly basis.
The plugin features a modern dashboard that displays vulnerability information, severity indicators, and guidance on updates. It also includes a mechanism to monitor the maintenance status of plugins, helping to identify those that may be neglected. This plugin is suitable for site administrators looking to enhance their site's security by keeping track of potential vulnerabilities.
Best for: Site administrators who want to enhance their site's security by monitoring vulnerabilities.
What it does well
Where it falls short
OOPVulns provides a focused approach to vulnerability scanning for WordPress sites. It offers essential features for security monitoring but lacks user feedback on its effectiveness.
OOPSpam Team's own description of OOPVulns: Vulnerability Scanner, lightly tidied.
OOPVulns is a modern, accessible WordPress plugin that continuously monitors your site for known security vulnerabilities in WordPress core, plugins, and themes.
The plugin checks your installed WordPress core version, plugin versions, and theme versions against the OOPSpam vulnerability database. It also checks WordPress.org plugin maintenance signals like last update date and recent unresolved critical support threads to highlight plugins that may be abandoned before a CVE is published. When a known vulnerability is found, you’ll see it in the dashboard and optionally receive an email notification.
This plugin connects to the OOPSpam API and WordPress.org services to retrieve vulnerability and maintenance information. When a scan runs, the following data is sent:
WordPress.org requests use plugin slugs to retrieve plugin last-updated timestamps and public support forum activity. No personal data, user information, or site content is transmitted.
Vulnerability API checks are disabled by default and only run after an administrator explicitly enables scanning in plugin settings.
Other plugins for securing a site.
Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vuln...
Firewall, Malware Scanner, Two Factor Auth, and Comprehensive Security Features, powered by our 24-hour team....
The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam sol...
Loginizer is a WordPress security plugin which helps you fight against bruteforce attacks.
Enable SVG uploads and sanitize them to stop XML/SVG vulnerabilities in your WordPress website.
Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plu...