Product
Solutions
Compare
Resources
Get early access Talk to us
Security and vulnerabilities

Know which of your WordPress sites are actually exposed

Vulnerability feeds are noisy because most of what they publish does not apply to you. WPCentrify matches every advisory against the exact plugin, theme and core versions running across your portfolio, so an alert always means something you can act on today.

Included on every plan. No add-on pricing.

app.wpcentrify.com/security
Security postureLive
Open findings
5
2 critical
Sites affected
3
of 34
Median patch time
4h
last 30 days
Malware
Clean
all sites
!!CVE-2026-2841
Auth bypass, contact plugin, CVSS 9.1
Critical3 sitesPatch ready
!CVE-2026-2790
Stored XSS, slider plugin, CVSS 6.4
Medium1 sitePatch ready
ABAbandoned plugin
No update in 3 years, removed from repo
Advisory2 sitesReplace
HDSecurity headers
CSP missing
Advisory4 sitesGuide
The problem

WordPress website security management starts with your plugin list

Core WordPress is well maintained and rarely the way in. The overwhelming majority of successful WordPress compromises come through a plugin or theme with a known, published, already-patched vulnerability. The exploit is usually automated, indiscriminate and running within days of the disclosure.

Which means the defensive problem is not sophisticated. It is inventory. You need to know, quickly, which of your sites are running the vulnerable version, and get them patched before the scanners find them. Doing that by hand across thirty sites and eight hundred installed plugins is not realistic.

What this looks like without a platform

  • Reading vulnerability news and manually checking whether it affects you
  • Finding out about an exposure from a client's IT department
  • No inventory of what plugin versions run where
  • Sites still running a plugin that was removed from the repository months ago
How it works

How the WordPress vulnerability scanner works

A live inventory of everything installed

WPCentrify maintains a current record of every core, plugin and theme version across every connected site. That inventory is what makes targeted alerting possible rather than generic news.

Advisories matched to your versions

New disclosures are checked against the inventory continuously. If nothing you run is affected, you hear nothing. If three sites are affected, you get one alert naming those three sites with the patched version and a one-click path to apply it.

Severity you can triage

Each finding carries a CVSS score, exploit availability, whether it needs authentication, and how exposed the affected site is. A critical unauthenticated remote code execution on a public store outranks a low-severity authenticated issue on a staging site.

Abandoned and removed plugins

Plugins pulled from the WordPress repository, or unmaintained for years, are flagged even without a specific CVE. These are among the highest practical risks in a portfolio and the easiest to miss.

In practice

WordPress security monitoring beyond the vulnerability feed

File integrity monitoring

Core, plugin and theme files are hashed and compared against known-good versions. Unexpected changes are surfaced with a diff so you can tell a legitimate update from an injected backdoor.

Malware and blacklist checks

Regular scanning for known malware signatures and suspicious patterns, plus monitoring of search engine and browser blacklists so you learn about a flag from us, not from a client's traffic collapsing.

Configuration and hardening review

SSL validity and expiry, security headers, directory listing, XML-RPC exposure, file editing permissions, admin username patterns and dormant administrator accounts.

Emergency patch path

Critical findings can bypass the normal update queue entirely, applying the patch immediately with a restore point taken first, rather than waiting for the next scheduled window.

At scale

Plugin vulnerability monitoring across your whole portfolio

  • Portfolio risk score with the most exposed sites ranked first
  • See every site affected by a single vulnerable plugin in one view
  • Track mean time to patch across the portfolio as an operational metric
  • Dormant admin account and user role auditing across all sites
  • Security posture included in monthly client reports
  • Weekly vulnerability digest scoped to the plugins you actually run
Answers

Questions about security and vulnerabilities

What people ask before they turn this on.

No. WPCentrify gives you portfolio-wide visibility and patching, which is a different job from blocking traffic in real time. A dedicated firewall and malware scanner remains worthwhile, and WPCentrify works alongside it rather than competing with it.

Feeds are polled continuously and new disclosures are matched against your inventory within minutes. For critical findings with an available patch you can configure emergency application without waiting for a maintenance window.

Premium plugins with published advisories are covered like any other. Genuinely custom code is not in any public feed, so it will not appear. File integrity monitoring still applies to it, and staging plus visual regression still protects you when you update it.

Yes. Group by client and produce a security summary per account, which is included in the monthly report and visible in the client portal if you enable it.

Early access open

Try security and vulnerabilities on your own sites

Connect a site in under two minutes and see this working against something real. Free during early access.

Free during early access. Keep your data, export any time.