WPDeeply
Download free plugin

Know what is putting your WordPress site at risk.

WPDeeply scans your plugins, themes and WordPress installation, then tells you what actually needs fixing.

Scan summary example-store.com
24 components inspected
Critical Example Plugin 2.1.3, patch available 1
Abandoned Old Slider, no update in 3 years 1
Review Inactive plugins still shipping code 3
Secure Core 6.8.2 current, PHP 8.2 supported 19
Last scan 4 minutes ago How scanning works
Free and GPLv2 or later No account required Reads your site only

Six checks that cover how WordPress sites actually get broken into.

Most compromises start with software that was already installed: outdated, abandoned or simply forgotten. WPDeeply looks at every component on the site, not just the ones you remember.

01

Known plugin vulnerabilities

Match every installed plugin version against known security issues, with severity and the version that fixes it.

02

Theme vulnerabilities

Identify security problems affecting your active theme, parent themes and any theme left installed.

03

WordPress core

Check whether the installed WordPress version contains known vulnerabilities or has fallen off the security-release branch.

04

Abandoned plugins

Flag software that looks unmaintained: long gaps between updates, or removal from the WordPress.org directory.

05

Unsupported software

Spot old PHP versions, components requiring newer PHP than you run, and end-of-life dependencies.

06

Unnecessary attack surface

List inactive plugins, leftover themes and exposed configuration signals such as debug mode left enabled.

One dashboard. Every component. Plain language.

A status line for everything installed, and a short explanation for anything that needs your attention.

Plugin risk report 6 of 24 shown
Elementor 3.31.2 No known issues
Example Plugin 2.1.3 Critical
Old Slider 1.4.0 Abandoned
Loginizer 1.9.2 Patched
PHP 8.2 Supported
WordPress core 6.8.2 Current
Critical

Example Plugin 2.1.3

CVE-2026-XXXXX, authenticated stored XSS
Your installed version
2.1.3
Affected versions
≤ 2.1.3
Patched in
2.1.5
Plugin state
Active
Public fix available
Yes
Update immediately
Move to 2.1.5. Nothing else on this site depends on the affected version.

Not a CVE list. A to-do list.

A CVSS score does not tell you whether the plugin is even switched on. WPDeeply combines severity, whether the component is active, and whether a fix exists, then sorts everything into three buckets.

Fix today

Plugin X 2.1.0

Known vulnerability, plugin is active, and a public fix is already released.

Update to 2.1.4
Replace soon

Plugin Y 3.0.2

No known vulnerability today, but it was removed from WordPress.org and has had no update in four years.

Find an alternative
Review

Plugin Z 1.2.8

Installed but inactive. It still ships code to your server and still needs patching.

Delete if you no longer use it

Is this WordPress plugin safe?

Check a plugin’s security history before it ever reaches your site: current version, maintenance status, open vulnerabilities and WordPress.org standing.

The checker reads public plugin data and published vulnerability records. It never touches your website.

Security history for the plugins everyone installs.

Current version, maintenance frequency, open vulnerabilities, WordPress.org status and a WPDeeply risk rating, on one page per plugin.

Browse plugin security profiles

Scanning is free. Monitoring is the paid part.

The free plugin tells you where you stand today. Pro watches for the vulnerability that gets published next week.

Free
€0 forever

One site, scanned whenever you want to know where you stand.

Manual vulnerability scans
Plugins, themes and WordPress core
Risk prioritisation, fix / replace / review
Abandoned and removed-plugin detection
Remediation guidance per finding
Download free plugin

GPLv2 or later. No account, no site key.

Pro
€49 per year

For site owners who want to hear about a vulnerability the day it is published.

Everything in Free
Scheduled automatic scans
Instant new-vulnerability alerts
Email and webhook notifications
Security score history and weekly reports
Up to 5 monitored sites
Get Pro
Agency
€129 per year

For agencies and maintenance plans covering many client installations.

Everything in Pro
25 to 100 monitored installations
Central multi-site dashboard
White-label PDF client reports
Priority alerting
See Agency plans

Latest from the guides

All guides
ProfilePress < 4.17.2 - Unauthenticated Arbitrary Plugin Installation RCE CVE-2026-66047 affects ProfilePress before 4.17.2. A weak 32-bit connect token in the unauthenticated ppress_connect_process AJAX handler can allow arbitrary plugin installation and PHP code execution. Update to 4.17.2… Plugin Security 1 Sep 2026, 3 min WPMU DEV Dashboard <= 5.0.1 - Authentication Bypass to Administrator via Hub SSO HMAC Confusion CVE-2026-76581 is a critical WPMU DEV Dashboard authentication bypass affecting sites with Hub SSO enabled and mapped to an administrator. Update to 5.0.2 or disable Hub SSO immediately. Plugin Security 29 Aug 2026, 3 min GiveWP <= 4.16.7.1 - Unauthenticated PHP Object Injection to Remote Code Execution Patchstack disclosed CVSS 10.0 unauthenticated PHP Object Injection to RCE in GiveWP. Sites with affected donation flows should update to 4.16.7.2 immediately and review sessions, users, and recent… Plugin Security 29 Aug 2026, 3 min WoodMart Theme Security Audit: Known CVEs, Vulnerabilities and Risk Profile WoodMart is a powerful WooCommerce theme, and powerful themes carry a larger attack surface. Your risk depends on the version, bundled plugins, site configuration, and whether updates are… Plugin Security 27 Aug 2026, 2 min Ultimate Member 2.6.7 – 2.12.1 – Unauthenticated Privilege Escalation via Profile Form Role Field WPScan published a new high-severity Ultimate Member vulnerability on August 26, 2026. Versions 2.6.7 through 2.12.1 are affected by unauthenticated privilege escalation through the profile form role field.… Plugin Security 27 Aug 2026, 3 min TranslatePress <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure CVE-2026-19632 is a critical TranslatePress vulnerability that can expose administrator password reset links from secondary-language dictionary tables. Update to 3.3.2 or newer immediately; WordPress.org currently lists 3.3.4. Plugin Security 26 Aug 2026, 3 min Avada <= 7.16 and Fusion Builder <= 3.16 - Unauthenticated Remote Code Execution CVE-2026-18431 is a critical unauthenticated RCE chain affecting Avada Plugin Security 26 Aug 2026, 3 min Events Manager <= 7.4.0.1 - Multiple Vulnerabilities Disclosed in WordPress Plugin Four Events Manager vulnerabilities were published on August 24, 2026, including Contributor+ SQL injection, unauthenticated information disclosure, reflected XSS, and administrator-level local file inclusion. Update to 7.4.1 or… Plugin Security 25 Aug 2026, 3 min PPWP Password Protect Pages <= 1.9.18 - Contributor+ PHP Object Injection CVE-2026-0551 affects PPWP Password Protect Pages up to 1.9.18. Contributor-level users can inject a PHP object through post_protection_roles; real-world impact depends on whether another plugin or theme exposes… Plugin Security 23 Aug 2026, 3 min Security Hardener <= 2.4.4 - Subscriber+ Privilege Escalation via REST Users Permission Callback CVE-2026-16149 is a high-severity Security Hardener flaw where user-enumeration protection can overwrite WordPress REST user endpoint capability checks, allowing Subscriber-level users to perform privileged user actions. Update to… Hardening 23 Aug 2026, 3 min Pods <= 3.3.9 - Unauthenticated Privilege Escalation via pods_admin AJAX Router CVE-2026-19598 is a critical Pods authorization bypass that can let unauthenticated attackers reach administrator methods, overwrite user passwords, or obtain administrator privileges. Update to 3.3.9.1 or a backported… Plugin Security 22 Aug 2026, 3 min miniOrange SAML Single Sign On – Unauthenticated Authentication Bypass Across Seven Editions Two miniOrange SAML Single Sign On flaws can let unauthenticated attackers sign in as existing WordPress users, including administrators. Paid editions need manual version checks because the normal… Plugin Security 22 Aug 2026, 3 min