WPVulnerability
View on WordPress.orgScores higher than 81% of indexed plugins
About
Get WordPress vulnerability alerts from the WPVulnerability Database API.
Security History
What It Does
WPVulnerability connects your WordPress site to the WPVulnerability Database API and delivers alerts about known vulnerabilities affecting your core installation, plugins, themes, and PHP version. It surfaces risks inside the WordPress dashboard through the Site Health area and email notifications, so administrators can act on known issues without manually checking databases. It does not fix, patch, or block anything; it only informs.
Who It's For
This plugin is best for site owners, freelancers, and small agencies who manage multiple WordPress installs and want a lightweight, passive heads-up system about disclosed vulnerabilities. It works well for users who already handle patching manually but want a centralized alert feed pulling from a curated database. Sites with strict compliance or audit requirements will appreciate the documented vulnerability trail it provides.
Who Should Skip It
If you already run a full security suite like Wordfence, Solid Security, or Patchstack that includes its own vulnerability database and remediation features, this plugin is largely redundant. Users wanting active firewall, malware scanning, or auto-patching should look at a more complete security tool rather than a notification layer.
The Bottom Line
WPVulnerability scores a solid 80.41/100 and does one job, vulnerability awareness, in a clean, well-maintained way. Its small install base and tiny support footprint give pause, but the recent update, broad compatibility, and perfect ratings suggest a focused, dependable tool. Treat it as a useful complement to active security, not a replacement for one.
Related Plugins
Pick this when you want HTTPS enforcement, vulnerability headers, and mixed-content fixes bundled into one package rather than a pure alert tool.
Pick this when you need an endpoint firewall, malware scanner, and live traffic rules on top of vulnerability data.
Pick this when you want a multi-purpose suite that pairs security alerts with backups, spam filtering, and performance tools.
Pick this when you want free, on-site hardening features like login lockdown, firewall rules, and database security, not just reporting.
Pick this for a narrow use case when your real gap is sanitising SVG uploads, not general vulnerability monitoring.