WPVulnerability icon

WPVulnerability

by ROBOTSTXT.es

View on WordPress.org
80 Quality Score
Active Installs
18/30

10,000 active installs is a modest niche footprint, far below the millions held by category leaders like Wordfence, which limits raw reach signals.

Update Freshness
25/25

Updated in July 2026 against WordPress 7.1 with a PHP 7.0 minimum, showing clear, recent maintenance activity and forward compatibility testing.

User Rating
15/15

A perfect 100 from 20 raters is encouraging but the small sample size means the rating carries less statistical weight than it appears.

Support Health
8/15

Only 1 support thread exists, and while it was resolved, the near-empty queue suggests either an issue-free plugin or low user engagement; hard to tell which.

WP Compatibility
15/15

Tested up to WordPress 7.1 with broad PHP support from 7.0 onward, signalling strong compatibility across older and current environments.

Scores higher than 81% of indexed plugins

About

Get WordPress vulnerability alerts from the WPVulnerability Database API.

Active Installs 10k+
Rating ★★★★★ 5/5
Last Updated 2026-08-23 7:02am GMT
Requires WordPress 4.7+
Tested Up To 7.1
Requires PHP 7.0+

Security History

1 known vulnerability, all patched
1 Medium

Most recent: March 18, 2026

View details ▸

Powered by Wordfence Intelligence

What It Does

WPVulnerability connects your WordPress site to the WPVulnerability Database API and delivers alerts about known vulnerabilities affecting your core installation, plugins, themes, and PHP version. It surfaces risks inside the WordPress dashboard through the Site Health area and email notifications, so administrators can act on known issues without manually checking databases. It does not fix, patch, or block anything; it only informs.

Who It's For

This plugin is best for site owners, freelancers, and small agencies who manage multiple WordPress installs and want a lightweight, passive heads-up system about disclosed vulnerabilities. It works well for users who already handle patching manually but want a centralized alert feed pulling from a curated database. Sites with strict compliance or audit requirements will appreciate the documented vulnerability trail it provides.

Who Should Skip It

If you already run a full security suite like Wordfence, Solid Security, or Patchstack that includes its own vulnerability database and remediation features, this plugin is largely redundant. Users wanting active firewall, malware scanning, or auto-patching should look at a more complete security tool rather than a notification layer.

The Bottom Line

WPVulnerability scores a solid 80.41/100 and does one job, vulnerability awareness, in a clean, well-maintained way. Its small install base and tiny support footprint give pause, but the recent update, broad compatibility, and perfect ratings suggest a focused, dependable tool. Treat it as a useful complement to active security, not a replacement for one.

Tags

security site health vulnerability