About WPDeeply

Most WordPress sites are broken into
through software they already had.

WPDeeply is a WordPress security project: a free plugin that finds vulnerable, abandoned and unnecessary software on your site, a public database of plugin security histories, and an archive of WordPress vulnerability research.

What WPDeeply does

Vulnerability intelligence that ends in a decision, not a score.

Prioritisation over noise

A CVSS number does not tell you whether the plugin is even active. Every WPDeeply finding ends in one of three answers: fix today, replace soon, or review.

Preserved research

WPDeeply’s historical vulnerability disclosures stay online at their original URLs, credited to the researchers who found them, with updated remediation notes added.

Transparent method

How vulnerabilities are sourced, how versions are matched and where the limits are is written down publicly, including the cases where WPDeeply can get it wrong.

The team

Small on purpose. Vulnerability triage, writing and services in one pair of hands.

LZ
Liz
Founder & Editor

Runs WPDeeply today: the Risk Monitor plugin, the plugin security database and the editorial side of the site. Handles vulnerability triage, remediation guidance and the security services WPDeeply offers directly.

What WPDeeply is

WPDeeply is a WordPress security project with three parts: a free plugin that finds vulnerable, abandoned and unnecessary software on your site; a public database of plugin security histories; and an archive of WordPress vulnerability research.

The historical research

WPDeeply published WordPress plugin vulnerability research in 2020 and 2021 — most notably the Loginizer SQL injection (CVE-2020-27615) that led WordPress to push a forced update to over a million sites. That work was researched and published by Slavco Mihajloski (mslavco).

The site’s current operators did not discover those vulnerabilities. We maintain the archive, keep the original URLs alive, preserve the researcher’s credit, and add current remediation information. Where a historical post has been updated, the update is marked as such.

What we are building now

The useful gap in WordPress security is not another vulnerability database — several good ones exist, and WPDeeply uses them. The gap is prioritisation: turning a list of CVEs into three short answers, fix today, replace soon, review. That is what Risk Monitor does, and what the plugin profiles are for.

Independence

WPDeeply sells its own plugin and its own services, and links to hosting and security products as an affiliate where relevant. Those relationships never decide a risk rating. Ratings come from the rules on the methodology page, and those rules are public so you can disagree with them.

Contact

Editorial, partnerships and services: triumphoid@proton.me. Legal and privacy: legal@wpdeeply.com.

Find out what is actually installed on your site.

WPDeeply Risk Monitor scans your plugins, themes and WordPress core, then ranks what needs fixing.

Download the free plugin