Vulnerability intelligence

Know which installed plugins and themes have disclosed vulnerabilities -- before they're exploited.

A file-integrity scan only catches code that's already been tampered with. WPFixAgent separately checks every installed plugin and theme's current version against publicly disclosed vulnerabilities, so you can see and fix an outdated, at-risk component before it's actually used against you.

Every

Installed plugin

Every

Installed theme

Severity

Ranked

One-click

Update

wpfixagent.com/wordpress-vulnerability-scanner

How matching works

InventoryThe connector reports every installed plugin and theme with its exact current version on each sync.
MatchInstalled versions are checked against known, publicly disclosed vulnerability records.
RankMatches are shown with severity so the most urgent issues are obvious first.
RemediateUpdate directly where a patched version exists, or review manually when it doesn't.
RescanSoftware falls off the list automatically once it's updated past the affected version range.

Repair playbook

1

Inventory

The connector reports every installed plugin and theme with its exact current version on each sync.

2

Match

Installed versions are checked against known, publicly disclosed vulnerability records.

3

Rank

Matches are shown with severity so the most urgent issues are obvious first.

4

Remediate

Update directly where a patched version exists, or review manually when it doesn't.

5

Rescan

Software falls off the list automatically once it's updated past the affected version range.

Full software inventory checked

Every plugin and theme currently installed on a connected website is checked against its exact installed version -- not just the ones that happen to be active.

Severity and remediation, not just a warning

Each match shows the CVE identifier, severity, affected version range, and what actually fixes it -- usually the patched version to update to.

Clean is shown explicitly

Software with no known issues is marked Clean, not just left blank -- so you know the check actually ran, not that it was skipped.

Feeds the same Issue Center as everything else

A critical vulnerability match becomes a ranked issue like any other finding, and can trigger a notification depending on severity -- it isn't a separate report you have to remember to check.

One-click update where a patch exists

Updating from a vulnerability finding uses the same protected update workflow as the Plugins & Themes tab -- a component snapshot first, automatic restore if the update fails.

What vulnerability matching does and doesn't do

Checks disclosed, publicly known vulnerabilities -- not a live exploit test

Severity comes from the disclosure, not an internal guess

A patched-version update doesn't require leaving the dashboard

Zero-day issues with no public disclosure yet won't appear here

Practical guidance

Go deeper before changing a live site.

Open documentation

Critical errors

How to Fix a WordPress Critical Error Without Making It Worse

Recover from the WordPress critical error screen with a controlled process that protects evidence, creates a restore point, isolates the cause, and verifies the result.

Read guide

Auto repair

WordPress Auto Repair: What Should Be Automated and What Needs Review?

Automation should resolve known, reversible WordPress conditions while risky database, malware, and hosting failures remain review-driven.

Read guide

Backups

Local vs Off-Site WordPress Backups: What a Recovery Plan Needs

Local restore points make repairs fast, while off-site copies protect against hosting and disk failure. A serious recovery plan needs clear roles for both.

Read guide

FAQ

Common questions

Does this scan inactive plugins and themes too?

Yes -- every installed plugin and theme is checked, whether or not it's currently active, since a dormant vulnerable component is still real risk.

What happens if there's no patched version yet?

The finding still shows with remediation guidance where available -- in that case, review or temporarily deactivate the affected component instead of updating.

Is this the same thing as the malware scanner?

No. The malware scanner looks for code that's already been tampered with; this checks whether legitimate, untouched code has a known disclosed vulnerability.

Does a vulnerability finding trigger an email?

Critical vulnerability findings are one of the small set of events eligible to email -- see the Notifications page for the full policy.

Free 14-day trial · no card required

Give every WordPress site a safer path from incident to verified recovery.

Install the connector, pair with a one-time token, and start monitoring in minutes -- upgrade whenever you're ready.

Start Free Trial