Know what’s putting your WordPress site at risk.
WPDeeply scans your plugins, themes and WordPress installation for known vulnerabilities, abandoned software and security risks — then tells you what actually needs fixing.
Six checks that cover how WordPress sites actually get broken into.
Most compromises start with software that was already installed — outdated, abandoned or simply forgotten. WPDeeply looks at every component on the site, not just the ones you remember.
Known plugin vulnerabilities
Match every installed plugin version against known security issues, with severity and the version that fixes it.
Theme vulnerabilities
Identify security problems affecting your active theme, parent themes and any theme left installed.
WordPress core
Check whether the installed WordPress version contains known vulnerabilities or has fallen off the security-release branch.
Abandoned plugins
Flag software that looks unmaintained — long gaps between updates, or removal from the WordPress.org directory.
Unsupported software
Spot old PHP versions, components requiring newer PHP than you run, and end-of-life dependencies.
Unnecessary attack surface
List inactive plugins, leftover themes and exposed configuration signals such as debug mode left enabled.
One dashboard. Every component. Plain language.
This is the whole product: a status line for everything installed, and a short explanation for anything that needs your attention.
Example Plugin 2.1.3
- Your installed version
- 2.1.3
- Affected versions
- ≤ 2.1.3
- Patched in
- 2.1.5
- Plugin state
- Active
- Public fix available
- Yes
Not a CVE list. A to-do list.
A CVSS score does not tell you whether the plugin is even switched on. WPDeeply combines severity, whether the component is active, and whether a fix exists — then sorts everything into three buckets.
Plugin X 2.1.0
Known vulnerability, plugin is active, and a public fix is already released.
Plugin Y 3.0.2
No known vulnerability today, but it was removed from WordPress.org and has had no update in four years.
Plugin Z 1.2.8
Installed but inactive. It still ships code to your server and still needs patching.
Is this WordPress plugin safe?
Check a plugin’s security history before it ever reaches your site — current version, maintenance status, open vulnerabilities and WordPress.org standing.
The checker reads public plugin data and published vulnerability records. It never touches your website.
WPDeeply Security Research
WPDeeply has a history of documenting WordPress plugin vulnerabilities and security issues. The research archive preserves those historical disclosures while adding updated remediation and vulnerability information.
Loginizer SQL Injection
Unauthenticated SQL injection in the failed-login handling of Loginizer before 1.6.4, force-pushed to millions of sites.
Read the disclosure Fixed in 3.4.27.1Ninja Forms CSRF to RCE
A missing nonce check on the form-import routine let a single crafted link escalate into remote code execution.
Read the disclosure Fixed in 5.8.3WooCommerce Abandoned Cart SQL Injection
Unsanitised cart parameters exposed the full customer table to unauthenticated extraction.
Read the disclosureSecurity history for the plugins everyone installs.
Current version, maintenance frequency, open vulnerabilities, WordPress.org status and a WPDeeply risk rating — on one page per plugin.
Scanning is free. Monitoring is the paid part.
The free plugin tells you where you stand today. Pro watches for the vulnerability that gets published next week.
One site, scanned whenever you want to know where you stand.
- Manual vulnerability scans
- Plugins, themes and WordPress core
- Risk prioritisation (fix / replace / review)
- Abandoned and removed-plugin detection
- Inactive plugin and PHP version checks
- Remediation guidance per finding
GPLv2 or later. No account, no site key.
For site owners who want to hear about a vulnerability the day it is published.
- Everything in Free
- Scheduled automatic scans
- Instant new-vulnerability alerts
- Email and webhook notifications (Slack, Discord)
- Security score history and weekly reports
- Up to 5 monitored sites
For agencies and maintenance plans covering many client installations.
- Everything in Pro
- 25–100 monitored installations
- Central multi-site dashboard
- White-label PDF client reports
- Priority alerting
- “New since last scan” change log
WordPress security guides and vulnerability news.
Find risky WordPress software before attackers do.
Install WPDeeply Risk Monitor, run one scan, and get a ranked list of what to fix, what to replace and what to delete.