SiteCare – Vulnerability Scanner
SiteCare – Vulnerability Scanner

SiteCare – Vulnerability Scanner

5/5 (2 ratings) 20 active installs Updated Jul 22, 2026
A vulnerable plugin caught: severity badges, CVE links, "fixed in" versions and the security score reacting instantly.

A vulnerable plugin caught: severity badges, CVE links, "fixed in" versions and the security score reacting instantly.

Most compromised WordPress sites aren’t hit by some clever, brand-new exploit – they’re breached through a known vulnerability in an outdated plugin or theme that nobody noticed in time. The fix is almost always as simple as running an update. The hard part is knowing there’s a problem at all.

SiteCare Vulnerability Scanner watches that blind spot for you. It checks your installed plugins, themes, and WordPress core against a continuously updated database of publicly known vulnerabilities, then tells you in plain language – right in your dashboard – what is affected and what to do about it.

  • Automatic daily monitoring in the background – plus an instant re-scan whenever you install, update or activate a plugin or theme.
  • Email alerts the moment a new vulnerability appears, so you find out without having to be logged in.
  • Clear severity ratings (CVSS) and CVE references, with the most urgent components listed first.
  • One-click updates right from the results whenever a fix is available.
  • Security score A-F (0-100) that grades your whole site at a glance, with a trend against your previous scan.
  • Abandoned & removed plugin detection – warns you when an installed plugin has been closed on WordPress.org or has had no update for years.
  • Slack / Discord alerts via webhook, and a WP-CLI command (wp vulnerability scan) with a CI-friendly exit code.
  • Shown where you already look – a dashboard widget and a WordPress Site Health check.

Your site’s data never leaves your server. The plugin only reads public vulnerability information through the WP Vulnerability API – no account, no external tracking, and no noticeable impact on performance.

Key Features

  • Accurate version-range detection against a continuously updated vulnerability database
  • Automatic background scans (daily, configurable) with instant re-checks after site changes
  • Email alerts for newly discovered vulnerabilities – only new ones, never repeated
  • Severity ratings (CVSS), CVE references and “fixed in” versions
  • One-click updates for affected plugins, themes and WordPress core
  • Dashboard widget and WordPress Site Health integration
  • Security score (A-F / 0-100) with a trend against the previous scan
  • Detection of abandoned and removed (closed) plugins via the WordPress.org API
  • Slack and Discord notifications through a webhook URL
  • WP-CLI command (wp vulnerability scan / status) with a CI-friendly exit code
  • Ships fully translated into five world languages – German, Spanish, French, Portuguese and Russian – plus Czech.
  • Read-only: only component slugs and versions are sent; no data leaves your site
  • Support development via Buy Me a Coffee

License

This plugin is distributed under the GNU General Public License v2.0 or later. See the license.txt file for details.