Find vulnerable, abandoned and risky WordPress plugins before they become a security problem.
Risk Monitor inventories every plugin, theme and core file version on your site, matches them against published vulnerability data, and ranks what to do first.
Everything installed — not just what is switched on.
Risk Monitor reads the version data WordPress already knows about, so a scan takes seconds and adds no ongoing load to your site.
Plugin vulnerabilities
Installed version against published vulnerability records, with severity, CVE reference and the version that fixes it.
Theme vulnerabilities
Active theme, parent theme and any theme still sitting in wp-content/themes.
WordPress core
Whether your core version has known vulnerabilities or has drifted off the supported security branch.
Abandonment signals
Time since last update, WordPress.org removal, closed listings and unusually long release gaps.
Unsupported software
End-of-life PHP, components that require a newer PHP than you run, and unmaintained dependencies.
Configuration exposure
Debug mode left on, file editing enabled, and other basic settings that make an incident worse.
How a finding becomes a recommendation.
Example Plugin 2.3.1
- Your installed version
- 2.3.1
- Affected versions
- ≤ 2.3.3
- Fixed in version
- 2.3.4
- Component active
- Yes
- CVSS
- 9.8
Known vulnerability, component active, public fix available. This is the only bucket that needs your attention right now.
Abandoned, removed from WordPress.org, or unsupported. No emergency today, but it will not be patched when something is found.
Inactive plugins, leftover themes and configuration flags. Cheap to clean up, and each one removes attack surface.
Every component gets a track record, not just a verdict.
The same data set powers the public plugin profiles on this site, so you can research a plugin before installing it and after.
What leaves your WordPress installation.
Sent
Component slugs and version numbers, your WordPress version and your PHP version. That is what a match needs.
Never sent
No post content, no user data, no email addresses, no database contents, no file contents.
Retention
Free scans are stateless. Pro stores scan results so it can tell you what changed since last time.
Free to scan. Paid to be told.
One site, scanned whenever you want to know where you stand.
- Manual vulnerability scans
- Plugins, themes and WordPress core
- Risk prioritisation (fix / replace / review)
- Abandoned and removed-plugin detection
- Inactive plugin and PHP version checks
- Remediation guidance per finding
GPLv2 or later. No account, no site key.
For site owners who want to hear about a vulnerability the day it is published.
- Everything in Free
- Scheduled automatic scans
- Instant new-vulnerability alerts
- Email and webhook notifications (Slack, Discord)
- Security score history and weekly reports
- Up to 5 monitored sites
For agencies and maintenance plans covering many client installations.
- Everything in Pro
- 25–100 monitored installations
- Central multi-site dashboard
- White-label PDF client reports
- Priority alerting
- “New since last scan” change log
Why another security plugin?
Most WordPress security tools are built around traffic: firewalls, login limits, bot filtering. Risk Monitor is built around inventory. It answers a narrower question — is the software already installed on this site safe to keep running? — and answers it in a form you can act on in ten minutes.
That question matters because the majority of compromised WordPress sites are not broken into through clever new exploits. They are broken into through a plugin that had a published fix available for months.
What a scan actually does
- Reads the installed version of every plugin and theme, plus WordPress core and PHP.
- Matches those versions against published vulnerability records.
- Checks WordPress.org listings for removals, closures and long update gaps.
- Flags inactive components, which still ship code to your server.
- Looks for basic configuration exposure such as
WP_DEBUGleft enabled in production.
No files are uploaded, no content is read, and nothing is executed against your site from outside. A scan is a version comparison, which is why it takes seconds rather than hours.
The output
Every finding lands in one of three buckets, in priority order:
- Fix today — known vulnerability, component active, patch available.
- Replace soon — abandoned, removed from WordPress.org, or unsupported.
- Review — inactive plugins, leftover themes, configuration flags.
If a vulnerability has no patched version, Risk Monitor never tells you to “update”. It tells you to restrict or replace, and says so plainly.
Limits worth knowing
Version matching is imperfect. Forked plugins, white-labelled bundles and hand-edited version strings can produce both false positives and false negatives. Our methodology page explains exactly how matching works, and how to report a bad match.
Questions people ask before installing.
Does Risk Monitor slow my site down?
No. A scan runs when you ask for it (or on a schedule in Pro), reads version metadata WordPress already stores, and writes a single results record. There is no continuous file scanning.
Is this a firewall or a malware scanner?
No. Risk Monitor tells you whether the software you are running is known to be unsafe. It does not block traffic and it does not clean infections. If you need cleanup, see our security services.
What happens when a vulnerability has no patch?
It is reported as unresolved, and the recommendation changes: restrict access to the affected feature, or replace the component. WPDeeply never tells you to update to a version that does not exist.
Can it produce false positives?
Yes, mostly through version-string edge cases and forked or white-labelled plugins. The methodology page explains how matching works and how to report a bad match.
Do I need an account?
Not for the free plugin. Pro and Agency use a licence key for alerting and multi-site monitoring.
Install it, run one scan, see where you stand.
Free, GPL-licensed, and it works on a single site without an account.