WordPress Plugin Vulnerability Scanner
Most hacked WordPress sites are broken into through a plugin with a known vulnerability. Enter your website and this free scanner detects the plugins, theme and WordPress version it can see from the outside, then checks each one against the open WPVulnerability database and WordPress.org for known security holes (CVE), missing updates and plugins that were closed.
What the WordPress scanner checks
Plugin vulnerabilities
Each detected plugin is matched with known vulnerabilities for its installed version – SQL injection, XSS, privilege escalation, file upload and more.
WordPress core
The WordPress version your site reveals, compared with the latest release and known core vulnerabilities.
Theme
The active theme and its version, checked for known vulnerabilities and updates.
Outdated software
Plugins and themes with a newer version available on WordPress.org.
Closed plugins
Plugins removed from WordPress.org (often for unfixed security issues) that will never get updates.
Clear priorities
Critical and high issues first, with the version that fixes each problem.
Quick answer
To find vulnerable WordPress plugins, list the plugins and versions your site uses and compare them with a vulnerability database such as WPVulnerability or WPScan. This free scanner detects plugins from your public pages, readme files and REST API, reads their versions and shows known CVEs, outdated plugins and closed plugins in one report.
How to use it
- Enter your WordPress site address and press Check plugins.
- The scanner detects plugins, the theme and the WordPress version from the public website (nothing is installed on your site).
- Update or replace everything marked critical or high first, then the outdated and closed plugins.
Why plugin vulnerabilities matter
WordPress core is well maintained, but a typical site runs 20–40 plugins written by different developers. Security researchers publish new plugin vulnerabilities every week, and automated bots start attacking them within hours. If one plugin on your site has a known hole and is not updated, the whole website – customer data, orders and your Google rankings – is at risk.
Severity levels explained
| Severity | CVSS score | Typical impact |
|---|---|---|
| Critical | 9.0 – 10 | Full site takeover without logging in (remote code execution, arbitrary file upload). |
| High | 7.0 – 8.9 | Database access (SQL injection) or privilege escalation to admin. |
| Medium | 4.0 – 6.9 | Stored XSS, CSRF or information disclosure, often needs a logged-in user. |
| Low | 0.1 – 3.9 | Limited impact; fix during normal updates. |
Limits of an external scan: plugins that load nothing on the public pages (for example backup or admin-only plugins) can’t be seen from outside, and some sites hide version numbers. For a complete list, check Plugins → Installed plugins in your dashboard or ask for a full security audit.
How to fix vulnerable plugins safely
- Take a full backup (files + database) or use a staging copy.
- Update the vulnerable plugin to the “fixed in” version or newer.
- If no fix exists or the plugin is closed, deactivate and replace it with a maintained alternative.
- Delete plugins and themes you don’t use – deactivated code can still be attacked.
- Turn on automatic security updates and a web application firewall.
- Run this scanner again, then check the site with the malware scanner in case it was already exploited.
Need help? I keep client sites patched as part of my WordPress maintenance plans, and the WordPress security guide 2026 explains the full hardening checklist.
Frequently asked questions
How do I check if my WordPress plugins are vulnerable?
Enter your site in this free scanner. It detects your plugins and versions and compares them with the WPVulnerability database and WordPress.org. Inside the dashboard you can also see which plugins have updates under Dashboard → Updates.
Where does the vulnerability data come from?
From the open WPVulnerability database (which aggregates sources like CVE, NVD, Wordfence, Patchstack and WPScan) and from the official WordPress.org API for the latest versions and closed plugins.
Why are some of my plugins missing from the results?
An external scan can only see plugins that load files or API routes on public pages. Admin-only plugins, or sites that hide their asset paths, may not show. The dashboard list is always the complete one.
What does “closed plugin” mean?
WordPress.org closed the plugin, often because of an unfixed security issue or because the author abandoned it. It will not receive updates, so you should replace it.
Is updating plugins enough to secure WordPress?
Updates fix known holes, but you also need strong passwords with 2FA, a firewall, limited login attempts, daily off-site backups and removing unused plugins. See the WordPress security guide on this site for the full checklist.
Want an expert to handle it?
I’m Eslam Abdullah – WordPress developer and web security specialist with 8+ years and 450+ projects. Send me your result on WhatsApp for a free consultation.