WPDeeply Risk Monitor · free WordPress plugin

Find vulnerable, abandoned and risky WordPress plugins before they become a security problem.

Risk Monitor inventories every plugin, theme and core file version on your site, matches them against published vulnerability data, and ranks what to do first.

WordPress 6.2+ PHP 7.4+ GPLv2 or later
Risk Monitor dashboard
Scan completed in 3.1s · 24 components
82/100
1 critical vulnerability Active plugin, patch releasedFix today
2 outdated plugins Behind current releaseReplace soon
3 inactive plugins Unnecessary attack surfaceReview
WordPress core secure 6.8.2 · PHP 8.2 supportedOK
Next scheduled scan: Pro feature Methodology →
What it scans

Everything installed — not just what is switched on.

Risk Monitor reads the version data WordPress already knows about, so a scan takes seconds and adds no ongoing load to your site.

Plugin vulnerabilities

Installed version against published vulnerability records, with severity, CVE reference and the version that fixes it.

Theme vulnerabilities

Active theme, parent theme and any theme still sitting in wp-content/themes.

WordPress core

Whether your core version has known vulnerabilities or has drifted off the supported security branch.

Abandonment signals

Time since last update, WordPress.org removal, closed listings and unusually long release gaps.

Unsupported software

End-of-life PHP, components that require a newer PHP than you run, and unmaintained dependencies.

Configuration exposure

Debug mode left on, file editing enabled, and other basic settings that make an incident worse.

Matching

How a finding becomes a recommendation.

Example Plugin 2.3.1

CVE-2026-XXXXX
Critical
Your installed version
2.3.1
Affected versions
≤ 2.3.3
Fixed in version
2.3.4
Component active
Yes
CVSS
9.8
Recommended action: update immediatelyYour installed version 2.3.1 is affected. Fixed in version 2.3.4.
Fix today

Known vulnerability, component active, public fix available. This is the only bucket that needs your attention right now.

Replace soon

Abandoned, removed from WordPress.org, or unsupported. No emergency today, but it will not be patched when something is found.

Review

Inactive plugins, leftover themes and configuration flags. Cheap to clean up, and each one removes attack surface.

Plugin security history

Every component gets a track record, not just a verdict.

The same data set powers the public plugin profiles on this site, so you can research a plugin before installing it and after.

Current version
1.9.2
Last updated
3 weeks ago
Active installations
1M+
Known vulnerabilities
7 historical
Open unresolved
0
WPDeeply risk rating
LOW
Privacy and data handling

What leaves your WordPress installation.

Sent

Component slugs and version numbers, your WordPress version and your PHP version. That is what a match needs.

Never sent

No post content, no user data, no email addresses, no database contents, no file contents.

Retention

Free scans are stateless. Pro stores scan results so it can tell you what changed since last time.

Plans

Free to scan. Paid to be told.

Free
€0forever

One site, scanned whenever you want to know where you stand.

  • Manual vulnerability scans
  • Plugins, themes and WordPress core
  • Risk prioritisation (fix / replace / review)
  • Abandoned and removed-plugin detection
  • Inactive plugin and PHP version checks
  • Remediation guidance per finding
Download free plugin

GPLv2 or later. No account, no site key.

Most popular
Pro
€49per year

For site owners who want to hear about a vulnerability the day it is published.

  • Everything in Free
  • Scheduled automatic scans
  • Instant new-vulnerability alerts
  • Email and webhook notifications (Slack, Discord)
  • Security score history and weekly reports
  • Up to 5 monitored sites
Get Pro
Agency
€129per year

For agencies and maintenance plans covering many client installations.

  • Everything in Pro
  • 25–100 monitored installations
  • Central multi-site dashboard
  • White-label PDF client reports
  • Priority alerting
  • “New since last scan” change log
See Agency plans

Why another security plugin?

Most WordPress security tools are built around traffic: firewalls, login limits, bot filtering. Risk Monitor is built around inventory. It answers a narrower question — is the software already installed on this site safe to keep running? — and answers it in a form you can act on in ten minutes.

That question matters because the majority of compromised WordPress sites are not broken into through clever new exploits. They are broken into through a plugin that had a published fix available for months.

What a scan actually does

  • Reads the installed version of every plugin and theme, plus WordPress core and PHP.
  • Matches those versions against published vulnerability records.
  • Checks WordPress.org listings for removals, closures and long update gaps.
  • Flags inactive components, which still ship code to your server.
  • Looks for basic configuration exposure such as WP_DEBUG left enabled in production.

No files are uploaded, no content is read, and nothing is executed against your site from outside. A scan is a version comparison, which is why it takes seconds rather than hours.

The output

Every finding lands in one of three buckets, in priority order:

  • Fix today — known vulnerability, component active, patch available.
  • Replace soon — abandoned, removed from WordPress.org, or unsupported.
  • Review — inactive plugins, leftover themes, configuration flags.

If a vulnerability has no patched version, Risk Monitor never tells you to “update”. It tells you to restrict or replace, and says so plainly.

Limits worth knowing

Version matching is imperfect. Forked plugins, white-labelled bundles and hand-edited version strings can produce both false positives and false negatives. Our methodology page explains exactly how matching works, and how to report a bad match.

FAQ

Questions people ask before installing.

Does Risk Monitor slow my site down?

No. A scan runs when you ask for it (or on a schedule in Pro), reads version metadata WordPress already stores, and writes a single results record. There is no continuous file scanning.

Is this a firewall or a malware scanner?

No. Risk Monitor tells you whether the software you are running is known to be unsafe. It does not block traffic and it does not clean infections. If you need cleanup, see our security services.

What happens when a vulnerability has no patch?

It is reported as unresolved, and the recommendation changes: restrict access to the affected feature, or replace the component. WPDeeply never tells you to update to a version that does not exist.

Can it produce false positives?

Yes, mostly through version-string edge cases and forked or white-labelled plugins. The methodology page explains how matching works and how to report a bad match.

Do I need an account?

Not for the free plugin. Pro and Agency use a licence key for alerting and multi-site monitoring.

Install it, run one scan, see where you stand.

Free, GPL-licensed, and it works on a single site without an account.

Version 16.9 · GPLv2 or later