Know the instant a plugin, theme or WordPress core has a known security hole - with a security score and clear fixes. Patch before attackers do.
Most compromised WordPress sites aren’t hit by some clever, brand-new exploit – they’re breached through a known vulnerability in an outdated plugin or theme that nobody noticed in time. The fix is almost always as simple as running an update. The hard part is knowing there’s a problem at all.
SiteCare Vulnerability Scanner watches that blind spot for you. It checks your installed plugins, themes, and WordPress core against a continuously updated database of publicly known vulnerabilities, then tells you in plain language – right in your dashboard – what is affected and what to do about it.
- Automatic daily monitoring in the background – plus an instant re-scan whenever you install, update or activate a plugin or theme.
- Email alerts the moment a new vulnerability appears, so you find out without having to be logged in.
- Clear severity ratings (CVSS) and CVE references, with the most urgent components listed first.
- One-click updates right from the results whenever a fix is available.
- Security score A-F (0-100) that grades your whole site at a glance, with a trend against your previous scan.
- Abandoned & removed plugin detection – warns you when an installed plugin has been closed on WordPress.org or has had no update for years.
- Slack / Discord alerts via webhook, and a WP-CLI command (
wp vulnerability scan) with a CI-friendly exit code. - Shown where you already look – a dashboard widget and a WordPress Site Health check.
Your site’s data never leaves your server. The plugin only reads public vulnerability information through the WP Vulnerability API – no account, no external tracking, and no noticeable impact on performance.
Key Features
- Accurate version-range detection against a continuously updated vulnerability database
- Automatic background scans (daily, configurable) with instant re-checks after site changes
- Email alerts for newly discovered vulnerabilities – only new ones, never repeated
- Severity ratings (CVSS), CVE references and “fixed in” versions
- One-click updates for affected plugins, themes and WordPress core
- Dashboard widget and WordPress Site Health integration
- Security score (A-F / 0-100) with a trend against the previous scan
- Detection of abandoned and removed (closed) plugins via the WordPress.org API
- Slack and Discord notifications through a webhook URL
- WP-CLI command (
wp vulnerability scan/status) with a CI-friendly exit code - Ships fully translated into five world languages – German, Spanish, French, Portuguese and Russian – plus Czech.
- Read-only: only component slugs and versions are sent; no data leaves your site
- Support development via Buy Me a Coffee
License
This plugin is distributed under the GNU General Public License v2.0 or later. See the license.txt file for details.