Plugin · Theme · WordPress core vulnerability monitoring

Know what’s putting your WordPress site at risk.

WPDeeply scans your plugins, themes and WordPress installation for known vulnerabilities, abandoned software and security risks — then tells you what actually needs fixing.

Free & GPL No account required Reads your site only
Your Plugin Risk Report
example-store.com · 24 components
82/100
Example Plugin 2.1.3 · active · patch available Critical
Old Slider No update in 3 years · removed from WordPress.org Abandoned
3 inactive plugins Installed but not in use — extra attack surface Review
WordPress core 6.8.2 Current · PHP 8.2 supported Secure
Last scan: 4 minutes ago How scanning works →
What it checks

Six checks that cover how WordPress sites actually get broken into.

Most compromises start with software that was already installed — outdated, abandoned or simply forgotten. WPDeeply looks at every component on the site, not just the ones you remember.

Known plugin vulnerabilities

Match every installed plugin version against known security issues, with severity and the version that fixes it.

Theme vulnerabilities

Identify security problems affecting your active theme, parent themes and any theme left installed.

WordPress core

Check whether the installed WordPress version contains known vulnerabilities or has fallen off the security-release branch.

Abandoned plugins

Flag software that looks unmaintained — long gaps between updates, or removal from the WordPress.org directory.

Unsupported software

Spot old PHP versions, components requiring newer PHP than you run, and end-of-life dependencies.

Unnecessary attack surface

List inactive plugins, leftover themes and exposed configuration signals such as debug mode left enabled.

Example report

One dashboard. Every component. Plain language.

This is the whole product: a status line for everything installed, and a short explanation for anything that needs your attention.

Your Plugin Risk Report 6 of 24 shown
Elementor3.31.2 No known vulnerabilities
Example Plugin2.1.3 Critical vulnerability
Old Slider1.4.0 Abandoned — no update in 3 years
Loginizer1.9.2 Current version patched
PHP8.2 Supported
WordPress core6.8.2 Current

Example Plugin 2.1.3

CVE-2026-XXXXX · Authenticated stored XSS
Critical
Your installed version
2.1.3
Affected versions
≤ 2.1.3
Patched in
2.1.5
Plugin state
Active
Public fix available
Yes
Update immediatelyMove to 2.1.5. Nothing else on this site depends on the affected version.
Prioritisation

Not a CVE list. A to-do list.

A CVSS score does not tell you whether the plugin is even switched on. WPDeeply combines severity, whether the component is active, and whether a fix exists — then sorts everything into three buckets.

Fix today

Plugin X 2.1.0

Known vulnerability, plugin is active, and a public fix is already released.

Update to 2.1.4
Replace soon

Plugin Y 3.0.2

No known vulnerability today, but it was removed from WordPress.org and has had no update in four years.

Find an alternative
Review

Plugin Z 1.2.8

Installed but inactive. It still ships code to your server and still needs patching.

Delete if you no longer use it
Before you install

Is this WordPress plugin safe?

Check a plugin’s security history before it ever reaches your site — current version, maintenance status, open vulnerabilities and WordPress.org standing.

The checker reads public plugin data and published vulnerability records. It never touches your website.

Plugin security profiles

Security history for the plugins everyone installs.

Current version, maintenance frequency, open vulnerabilities, WordPress.org status and a WPDeeply risk rating — on one page per plugin.

Pricing

Scanning is free. Monitoring is the paid part.

The free plugin tells you where you stand today. Pro watches for the vulnerability that gets published next week.

Free
€0forever

One site, scanned whenever you want to know where you stand.

  • Manual vulnerability scans
  • Plugins, themes and WordPress core
  • Risk prioritisation (fix / replace / review)
  • Abandoned and removed-plugin detection
  • Inactive plugin and PHP version checks
  • Remediation guidance per finding
Download free plugin

GPLv2 or later. No account, no site key.

Most popular
Pro
€49per year

For site owners who want to hear about a vulnerability the day it is published.

  • Everything in Free
  • Scheduled automatic scans
  • Instant new-vulnerability alerts
  • Email and webhook notifications (Slack, Discord)
  • Security score history and weekly reports
  • Up to 5 monitored sites
Get Pro
Agency
€129per year

For agencies and maintenance plans covering many client installations.

  • Everything in Pro
  • 25–100 monitored installations
  • Central multi-site dashboard
  • White-label PDF client reports
  • Priority alerting
  • “New since last scan” change log
See Agency plans

Find risky WordPress software before attackers do.

Install WPDeeply Risk Monitor, run one scan, and get a ranked list of what to fix, what to replace and what to delete.

Free · GPLv2 or later · WordPress 6.2+ · PHP 7.4+