WPDeeply
Download free plugin

Plugin Security

How to judge, replace and remove WordPress plugins.

22
Guides
InspectWP vs. WPDeeply: Which WordPress Security Analysis Tool Wins in 2026? InspectWP is useful for seeing surface-level technology signals. WPDeeply is built for the next question: are the exact plugins and themes on your site tied to known CVEs,… Plugin Security 19 Aug 2026, 2 min Forminator Forms <= 1.56.1 - Unauthenticated Arbitrary File Upload Forminator Forms versions up to 1.56.1 contain a critical unauthenticated arbitrary file upload vulnerability. Update to 1.56.2 or later and review public forms that combine Select and File… Plugin Security 18 Aug 2026, 4 min How Long Is Too Long Without a Plugin Update? What update gaps actually predict, and the thresholds WPDeeply uses. Plugin Security 11 Jun 2026, 2 min How to Replace an Abandoned WordPress Plugin A migration order that avoids losing data or breaking a live site. Plugin Security 29 May 2026, 2 min Should You Delete Inactive WordPress Plugins? Deactivated is not the same as gone. What an inactive plugin can and cannot do. Plugin Security 17 Apr 2026, 2 min How to Check If a WordPress Plugin Is Safe Five checks, in order of usefulness, before you install a WordPress plugin. Plugin Security 4 Mar 2026, 2 min A Plugin Was Removed From WordPress.org. What Does That Mean? Closed, removed, or just gone — how to read a missing plugin listing, and what to do. Plugin Security 20 Feb 2026, 2 min WP Job Manager Permission Escalation to RCE: Risk Profile and Response Permission escalation is dangerous because it changes who can perform sensitive actions. On a WordPress site, that can quickly become plugin installation, file writes, or code execution. Plugin Security 25 Nov 2020, 2 min WordPress Protected Meta Exposure via WP Job Manager: What Site Owners Should Know Protected meta is only protected if every plugin respects the boundary. Job, listing, and directory plugins often attach sensitive operational data to posts, so permission checks matter. Plugin Security 11 Aug 2020, 2 min LearnPress SQL Injection to RCE: Lessons for WordPress LMS Sites LMS plugins hold users, progress, payments, certificates, and admin workflows. A SQL injection in that environment can become more than a data leak if chained with privileged actions. Plugin Security 20 Jul 2020, 2 min