A live inventory of everything installed
WPCentrify maintains a current record of every core, plugin and theme version across every connected site. That inventory is what makes targeted alerting possible rather than generic news.
Vulnerability feeds are noisy because most of what they publish does not apply to you. WPCentrify matches every advisory against the exact plugin, theme and core versions running across your portfolio, so an alert always means something you can act on today.
Included on every plan. No add-on pricing.
Updated
A WordPress vulnerability scanner checks the exact versions of WordPress core, plugins and themes a site runs against published security advisories, and tells you which have a known hole and which version fixes it. Plugins are where the risk is: Patchstack counted 11,334 new vulnerabilities in the WordPress ecosystem in 2025, 91 percent of them in plugins, 9 percent in themes and only 6 in WordPress core.
A vulnerability scan finds known holes; to look for an infection that is already there, follow our guide on how to scan a WordPress site for malware.
WPCentrify keeps a record of what every connected site runs and does the matching on its own servers, so nothing heavy runs on the website. When a plugin or theme has a known hole, you get one finding naming the sites affected and the version that fixes every known hole, with an Update now button on it. The checks are part of Sentinel, WPCentrify's security monitoring, which also watches for signs that a site has been hacked.
Core WordPress is well maintained and rarely the way in. The overwhelming majority of successful WordPress compromises come through a plugin or theme with a known, published, already-patched vulnerability. The exploit is usually automated, indiscriminate and running within days of the disclosure.
Which means the defensive problem is not sophisticated. It is inventory. You need to know, quickly, which of your sites are running the vulnerable version, and get them patched before the scanners find them. Doing that by hand across thirty sites and eight hundred installed plugins is not realistic.
WPCentrify maintains a current record of every core, plugin and theme version across every connected site. That inventory is what makes targeted alerting possible rather than generic news.
New disclosures are checked against the inventory continuously. If nothing you run is affected, you hear nothing. If three sites are affected, you get one alert naming those three sites with the patched version and a one-click path to apply it. How that matching and ranking works in depth is covered under vulnerability monitoring across the portfolio.
Each finding carries a CVSS score, exploit availability, whether it needs authentication, and how exposed the affected site is. A critical unauthenticated remote code execution on a public store outranks a low-severity authenticated issue on a staging site.
Plugins pulled from the WordPress repository, or unmaintained for years, are flagged even without a specific CVE. These are among the highest practical risks in a portfolio and the easiest to miss.
Core, plugin and theme files are hashed and compared against known-good versions. Unexpected changes are surfaced with a diff so you can tell a legitimate update from an injected backdoor. Watching for those changes as they happen, along with sign-ins and new administrators, is continuous WordPress security monitoring.
Regular scanning for known malware signatures and suspicious patterns, plus monitoring of search engine and browser blacklists so you learn about a flag from us, not from a client's traffic collapsing.
SSL validity and expiry, security headers, directory listing, XML-RPC exposure, file editing permissions, admin username patterns and dormant administrator accounts.
Critical findings can bypass the normal update queue entirely, applying the patch immediately with a restore point taken first, rather than waiting for the next scheduled window. Each emergency patch stays attributable afterwards in the change evidence.
What people ask before they turn this on.
No. WPCentrify gives you portfolio-wide visibility and patching, which is a different job from blocking traffic in real time. A dedicated firewall and malware scanner remains worthwhile, and WPCentrify works alongside it rather than competing with it.
Feeds are polled continuously and new disclosures are matched against your inventory within minutes. For critical findings with an available patch you can configure emergency application without waiting for a maintenance window.
Premium plugins with published advisories are covered like any other. Genuinely custom code is not in any public feed, so it will not appear. File integrity monitoring still applies to it, and visual regression with automatic rollback still protects you when you update it.
Yes. Group by client and produce a security summary per account, which is included in the monthly report and visible in the client portal if you enable it.
Compare the versions of WordPress, your plugins and your themes with a vulnerability database, then update anything with a known hole. WPCentrify does this for every connected site on its own servers and shows each vulnerable plugin or theme with the version that fixes it.
Yes. Patchstack's State of WordPress Security in 2026 report found that 91 percent of the 11,334 new vulnerabilities in the WordPress ecosystem in 2025 were in plugins, 9 percent were in themes, and only 6 were in WordPress core.
No. A vulnerability scanner looks for known holes in the software a site runs. Finding signs that a site has already been hacked is a different check, which Sentinel, WPCentrify's security monitoring, runs on every connected site.
Connect a site in under two minutes and see this working against something real. Free during early access.
Free during early access. Keep your data, export any time.