Product
Solutions
Compare
Resources
Get early access Talk to us
Security and vulnerabilities

Know which of your WordPress sites are actually exposed

Vulnerability feeds are noisy because most of what they publish does not apply to you. WPCentrify matches every advisory against the exact plugin, theme and core versions running across your portfolio, so an alert always means something you can act on today.

Included on every plan. No add-on pricing.

Updated

app.wpcentrify.com/security
Security postureExample data
Open findings
5
2 critical
Sites affected
3
of 34
Median patch time
4h
last 30 days
Malware
Clean
all sites
!!CVE-2026-2841
Auth bypass, contact plugin, CVSS 9.1
Critical3 sitesPatch ready
!CVE-2026-2790
Stored XSS, slider plugin, CVSS 6.4
Medium1 sitePatch ready
ABAbandoned plugin
No update in 3 years, removed from repo
Advisory2 sitesReplace
HDSecurity headers
CSP missing
Advisory4 sitesGuide

What is a WordPress vulnerability scanner?

A WordPress vulnerability scanner checks the exact versions of WordPress core, plugins and themes a site runs against published security advisories, and tells you which have a known hole and which version fixes it. Plugins are where the risk is: Patchstack counted 11,334 new vulnerabilities in the WordPress ecosystem in 2025, 91 percent of them in plugins, 9 percent in themes and only 6 in WordPress core.

A vulnerability scan finds known holes; to look for an infection that is already there, follow our guide on how to scan a WordPress site for malware.

WPCentrify keeps a record of what every connected site runs and does the matching on its own servers, so nothing heavy runs on the website. When a plugin or theme has a known hole, you get one finding naming the sites affected and the version that fixes every known hole, with an Update now button on it. The checks are part of Sentinel, WPCentrify's security monitoring, which also watches for signs that a site has been hacked.

WPCentrify vulnerability scanning at a glance

  • Installed versions of WordPress core, plugins and themes matched against vulnerability data on WPCentrify's servers.
  • One finding per vulnerable plugin or theme, with the version that fixes every known hole.
  • Update now from the finding, or an automation rule that applies such fixes for you.
  • The finding clears once the site runs a fixed version.
  • Part of Sentinel, which also checks for signs of a hack.
The problem

WordPress website security management starts with your plugin list

Core WordPress is well maintained and rarely the way in. The overwhelming majority of successful WordPress compromises come through a plugin or theme with a known, published, already-patched vulnerability. The exploit is usually automated, indiscriminate and running within days of the disclosure.

Which means the defensive problem is not sophisticated. It is inventory. You need to know, quickly, which of your sites are running the vulnerable version, and get them patched before the scanners find them. Doing that by hand across thirty sites and eight hundred installed plugins is not realistic.

What this looks like without a platform

  • Reading vulnerability news and manually checking whether it affects you
  • Finding out about an exposure from a client's IT department
  • No inventory of what plugin versions run where
  • Sites still running a plugin that was removed from the repository months ago
How it works

How the WordPress vulnerability scanner works

A live inventory of everything installed

WPCentrify maintains a current record of every core, plugin and theme version across every connected site. That inventory is what makes targeted alerting possible rather than generic news.

Advisories matched to your versions

New disclosures are checked against the inventory continuously. If nothing you run is affected, you hear nothing. If three sites are affected, you get one alert naming those three sites with the patched version and a one-click path to apply it. How that matching and ranking works in depth is covered under vulnerability monitoring across the portfolio.

Severity you can triage

Each finding carries a CVSS score, exploit availability, whether it needs authentication, and how exposed the affected site is. A critical unauthenticated remote code execution on a public store outranks a low-severity authenticated issue on a staging site.

Abandoned and removed plugins

Plugins pulled from the WordPress repository, or unmaintained for years, are flagged even without a specific CVE. These are among the highest practical risks in a portfolio and the easiest to miss.

In practice

WordPress security monitoring beyond the vulnerability feed

File integrity monitoring

Core, plugin and theme files are hashed and compared against known-good versions. Unexpected changes are surfaced with a diff so you can tell a legitimate update from an injected backdoor. Watching for those changes as they happen, along with sign-ins and new administrators, is continuous WordPress security monitoring.

Malware and blacklist checks

Regular scanning for known malware signatures and suspicious patterns, plus monitoring of search engine and browser blacklists so you learn about a flag from us, not from a client's traffic collapsing.

Configuration and hardening review

SSL validity and expiry, security headers, directory listing, XML-RPC exposure, file editing permissions, admin username patterns and dormant administrator accounts.

Emergency patch path

Critical findings can bypass the normal update queue entirely, applying the patch immediately with a restore point taken first, rather than waiting for the next scheduled window. Each emergency patch stays attributable afterwards in the change evidence.

At scale

Plugin vulnerability monitoring across your whole portfolio

  • Portfolio risk score with the most exposed sites ranked first
  • See every site affected by a single vulnerable plugin in one view
  • Track mean time to patch across the portfolio as an operational metric
  • Dormant admin account and user role auditing across all sites
  • Security posture included in monthly client reports
  • Weekly vulnerability digest scoped to the plugins you actually run
Answers

Questions about security and vulnerabilities

What people ask before they turn this on.

No. WPCentrify gives you portfolio-wide visibility and patching, which is a different job from blocking traffic in real time. A dedicated firewall and malware scanner remains worthwhile, and WPCentrify works alongside it rather than competing with it.

Feeds are polled continuously and new disclosures are matched against your inventory within minutes. For critical findings with an available patch you can configure emergency application without waiting for a maintenance window.

Premium plugins with published advisories are covered like any other. Genuinely custom code is not in any public feed, so it will not appear. File integrity monitoring still applies to it, and visual regression with automatic rollback still protects you when you update it.

Yes. Group by client and produce a security summary per account, which is included in the monthly report and visible in the client portal if you enable it.

Compare the versions of WordPress, your plugins and your themes with a vulnerability database, then update anything with a known hole. WPCentrify does this for every connected site on its own servers and shows each vulnerable plugin or theme with the version that fixes it.

Yes. Patchstack's State of WordPress Security in 2026 report found that 91 percent of the 11,334 new vulnerabilities in the WordPress ecosystem in 2025 were in plugins, 9 percent were in themes, and only 6 were in WordPress core.

No. A vulnerability scanner looks for known holes in the software a site runs. Finding signs that a site has already been hacked is a different check, which Sentinel, WPCentrify's security monitoring, runs on every connected site.

Early access open

Try security and vulnerabilities on your own sites

Connect a site in under two minutes and see this working against something real. Free during early access.

Free during early access. Keep your data, export any time.