WPThumbs
Themes Plugins By purpose By industry Best-of lists Fix it guides
Free Plugin by ROBOTSTXT.es v5.1.6

WPVulnerability

Get WordPress vulnerability alerts from the WPVulnerability Database API.

WPVulnerability

The facts

Rating
5★ from 20
Active installs
10k+
Price
Free
Last updated
23 Aug 2026
Added
May 2022
Requires WP
4.7
Tested up to
WP 7.1
Requires PHP
7.0
Downloads
696,365

Our analysis

AI-assisted

WPVulnerability is a WordPress plugin that integrates with the WPVulnerability API to provide real-time assessments of vulnerabilities in your WordPress core, plugins, themes, and various server components. It delivers detailed reports directly within your WordPress dashboard and allows for configuration of periodic notifications about your site's security status.

This plugin is designed for ease of use and does not store or retrieve personal data. It is suitable for users looking to enhance their site's security through proactive measures and detailed reporting.

Best for: This plugin suits WordPress site owners who want to proactively manage their site's security.

What it does well

  • Integrates with WPVulnerability API for real-time assessments
  • Delivers detailed reports within the WordPress dashboard
  • Configurable notifications for security status
  • Supports various server components including PHP and MySQL
  • Does not store or retrieve personal data

Where it falls short

  • No information on specific vulnerabilities or data sources
  • Data reliability disclaimer provided by the author

Verdict

WPVulnerability offers a straightforward solution for monitoring security risks in WordPress sites. Its ease of use and comprehensive reporting make it a valuable tool for site owners focused on security.

From the developer

ROBOTSTXT.es's own description of WPVulnerability, lightly tidied.

This plugin integrates with the WPVulnerability API to provide real-time vulnerability assessments for your WordPress core, plugins, themes, PHP version, Apache HTTPD, nginx, MariaDB, MySQL, ImageMagick, curl, memcached, Redis, and SQLite.

It delivers detailed reports directly within your WordPress dashboard, helping you stay aware of potential security risks. Configure the plugin to send periodic notifications about your site’s security status, ensuring you remain informed without being overwhelmed. Designed for ease of use, it supports proactive security measures without storing or retrieving any personal data from your site.

Data reliability

The information provided by the information database comes from different sources that have been reviewed by third parties. There is no liability of any kind for the information. Act at your own risk.

Using the plugin

Wp-cli

You can use the following WP-CLI commands to manage and check vulnerabilities:

  • Core: wp wpvulnerability core
  • Plugins: wp wpvulnerability plugins
  • Themes: wp wpvulnerability themes
  • PHP: wp wpvulnerability php
  • Apache HTTPD: wp wpvulnerability apache
  • nginx: wp wpvulnerability nginx
  • MariaDB: wp wpvulnerability mariadb
  • MySQL: wp wpvulnerability mysql
  • ImageMagick: wp wpvulnerability imagemagick
  • curl: wp wpvulnerability curl
  • memcached: wp wpvulnerability memcached
  • Redis: wp wpvulnerability redis
  • SQLite: wp wpvulnerability sqlite

To configure the plugin you can use:

  • Hide component: wp wpvulnerability config hide <component> [on|off]
  • Notification email: wp wpvulnerability config email <emails> (comma separatted)
  • Notification period: wp wpvulnerability config period <never|daily|weekly>
  • Log retention: wp wpvulnerability config log-retention <0|1|7|14|28> (in days)
  • Cache duration: wp wpvulnerability config cache <1|6|12|24> (in hours)

All commands support the --format option to specify the output format:

  • --format=table: Displays the results in a table format (default).
  • --format=json: Displays the results in JSON format.

Need help?

  • wp wpvulnerability --help: Displays help information for WPVulnerability commands.
  • wp wpvulnerability [command] --help: Displays help information for a WPVulnerability command.

Rest API

The WPVulnerability plugin provides several REST API endpoints to fetch vulnerability information for different components of your WordPress site.

Read the full description on the official page →

Tagged as

Alternatives

Other plugins for securing a site.

Really Simple Security

Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vuln...

Free 3M+ installs 4.9★ (8,862)
Wordfence Security

Firewall, Malware Scanner, Two Factor Auth, and Comprehensive Security Features, powered by our 24-hour team....

Free 5M+ installs 4.7★ (4,983)
Akismet Anti-spam: Spam Protection

The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam sol...

Free 5M+ installs 4.7★ (1,186)
Loginizer

Loginizer is a WordPress security plugin which helps you fight against bruteforce attacks.

Free 1M+ installs 4.8★ (1,030)
Safe SVG

Enable SVG uploads and sanitize them to stop XML/SVG vulnerabilities in your WordPress website.

Free 1M+ installs 4.9★ (79)
All-In-One Security

Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plu...

Free 1M+ installs 4.7★ (1,715)