Paste any WordPress URL. Get a full plugin security report with CVE details and risk scores in seconds.
Discovers installed plugins from HTML source, script tags, stylesheets, and readme files.
Extracts exact versions from query strings, readme files, and asset URLs.
Cross-references each version against WPScan, NVD, and public vulnerability records.
Published methodology. Every deduction explained. No black boxes.
Any public WordPress site. No login, no install, no API key needed.
See every step in real-time as we detect plugins, check versions, and match vulnerabilities.
Get a full report with CVE details, severity scores, and which version fixes each issue.
No black-box algorithms. Every deduction in your risk score maps to a specific CVE, a specific plugin version, and a specific severity rating. Read the full methodology — it's public.
CVSS base scores weighted by exploitability and plugin popularity
Database syncs every 2 hours from NVD and WPScan feeds
Each detection tagged as confirmed, likely, or suspected
Managing WordPress sites for clients means staying ahead of vulnerabilities — not finding out after a breach.
Start free. Upgrade when you need continuous monitoring.
Full plugin security report in 15 seconds. No signup, no install.
We'll notify you when new CVEs are published for these plugins.
No thanks