Is this WordPress plugin safe?
Look up a plugin’s security history before you install it — current version, maintenance status, open vulnerabilities and WordPress.org standing.
Wordfence
- WordPress.org status
- Active
- Open unresolved vulnerabilities
- 0
- Known vulnerabilities
- Few, historically
- Last vulnerability disclosed
- None current
- Maintenance status
- Active — frequent releases and its own threat-intelligence programme
- PHP compatibility
- PHP 7.4+ supported
Four signals that tell you most of what you need to know.
Time since last update
A plugin that has not shipped anything in two years is unlikely to ship a security fix quickly.
Open unresolved issues
Historical vulnerabilities are normal. Vulnerabilities with no patched version are not.
WordPress.org standing
A closed or removed listing is the single strongest signal to replace a plugin.
What the checker tells you
Enter a plugin name, slug or WordPress.org URL and you get its security track record: current maintenance status, historical vulnerability count, anything still unresolved, and where it stands in the official directory.
It reads public data only. It never connects to your website, and you do not need to install anything to use it.
When to use it
- Before installing something you found in a tutorial or a Facebook group.
- When you inherit a site and want to know what the previous owner left behind.
- When a plugin has not updated in a while and you are deciding whether to migrate.
To check every plugin on a site at once — including the ones you have forgotten about — use WPDeeply Risk Monitor instead.