WPDeeply

Data Sources

The vulnerability intelligence and directory data WPDeeply relies on.

WPDeeply does not pretend to have discovered the WordPress vulnerability landscape on its own. Most of what Risk Monitor matches against was published by other people. This page says who.

Currently in use

  • WordPress.org plugin and theme directory — version, last-updated date, active installation ranges, tested-up-to values, and listing status including closures and removals.
  • WPDeeply research archive — the 2020–2021 disclosures published on this site, credited to their original researcher.
  • Public CVE records — identifiers, affected ranges, patched versions and CVSS vectors as published.

Under evaluation

Dedicated WordPress vulnerability feeds — including WPVulnerability, Wordfence Intelligence and WPScan — publish the most complete plugin data in the ecosystem. Each has its own commercial and API licensing terms, and we will name one here as a source only once an integration is live and correctly licensed. Listing a partner we have not integrated would be marketing, not attribution.

Attribution

Where a finding originates with a named researcher, that name stays attached to it. Where a record originates with a vendor database, the record is linked rather than copied.

Corrections

If you maintain a data source and believe WPDeeply is using it incorrectly or outside its licence, write to legal@wpdeeply.com and it will be addressed promptly.