
Dashboard showing vulnerability summary
OOPVulns is a modern, accessible WordPress plugin that continuously monitors your site for known security vulnerabilities in WordPress core, plugins, and themes.
The plugin checks your installed WordPress core version, plugin versions, and theme versions against the OOPSpam vulnerability database. It also checks WordPress.org plugin maintenance signals like last update date and recent unresolved critical support threads to highlight plugins that may be abandoned before a CVE is published. When a known vulnerability is found, you’ll see it in the dashboard and optionally receive an email notification.
This plugin connects to the OOPSpam API and WordPress.org services to retrieve vulnerability and maintenance information. When a scan runs, the following data is sent:
WordPress.org requests use plugin slugs to retrieve plugin last-updated timestamps and public support forum activity. No personal data, user information, or site content is transmitted.
Vulnerability API checks are disabled by default and only run after an administrator explicitly enables scanning in plugin settings.