About WPDeeply
What WPDeeply is today, and how its historical research is handled.
What WPDeeply is
WPDeeply is a WordPress security project with three parts: a free plugin that finds vulnerable, abandoned and unnecessary software on your site; a public database of plugin security histories; and an archive of WordPress vulnerability research.
The historical research
WPDeeply published WordPress plugin vulnerability research in 2020 and 2021 — most notably the Loginizer SQL injection (CVE-2020-27615) that led WordPress to push a forced update to over a million sites. That work was researched and published by Slavco Mihajloski (mslavco).
The site’s current operators did not discover those vulnerabilities. We maintain the archive, keep the original URLs alive, preserve the researcher’s credit, and add current remediation information. Where a historical post has been updated, the update is marked as such.
Resources
What we are building now
The useful gap in WordPress security is not another vulnerability database — several good ones exist, and WPDeeply uses them. The gap is prioritisation: turning a list of CVEs into three short answers, fix today, replace soon, review. That is what Risk Monitor does, and what the plugin profiles are for.
Independence
WPDeeply sells its own plugin and its own services, and links to hosting and security products as an affiliate where relevant. Those relationships never decide a risk rating. Ratings come from the rules on the methodology page, and those rules are public so you can disagree with them.
Contact
Editorial, partnerships and services: triumphoid@proton.me. Legal and privacy: legal@wpdeeply.com.