WPVulnerability is a WordPress plugin that delivers vulnerability assessments inside the WordPress dashboard. It uses the free and unlimited WPVulnerability API and is described as a tool for website administrators, developers, and anyone maintaining a secure WordPress environment.
Its checks cover WordPress core, plugins, themes, and several server software components, including PHP, Apache HTTPD, nginx, MariaDB, MySQL, ImageMagick, curl, Memcached, Redis, and SQLite. The plugin supports WP-CLI commands for each of those areas, along with configuration commands to hide specific components, set notification email addresses, choose a notification period, control log retention, and adjust cache duration. Output can be formatted as a table or as JSON. It also provides REST API endpoints for the same components, and those endpoints use WordPress Application Passwords for authentication.
The plugin stores recent API responses in a log tab, and its cache duration defaults to 12 hours. Configuration can also be controlled through constants in wp-config.php, including a custom sender email, forced hiding of component checks, cache duration, and log retention. For server software detection, it uses a hybrid approach that checks PHP extensions first and then falls back to shell commands. The page also lists compatibility with WordPress 4.7 through 6.9, PHP 5.6 through 8.5, and WP-CLI 2.3.0 through 2.11.0. No pricing or license details are stated beyond the API being free and unlimited.
WPVulnerability sits in PulseGate's Security & compliance platforms category. It focuses on alerting WordPress site owners to vulnerabilities in core, plugins, and infrastructure in real time. It is built as a B2B product for wordPress administrators and security professionals. WPVulnerability costs nothing to use. WPVulnerability is available on the web and API.
Javier Casares builds and maintains WPVulnerability, and it first shipped in 2011. Development happens publicly on GitHub with 2.8k stars and 37 commits in the last 90 days. Among its 5 catalogued features are vulnerability alerts, API integration, and dashboard reports. The interface is available in Catalan and English. It exposes integrations via a public API.
Summary written by a language model from the project’s public pages.
What PulseGate has recorded for this listing
Closest matches by what these projects do