Plugin Pulse
← Pulse

WPVulnerability

by ROBOTSTXT.es · Security

Also makes 1 other plugin · 13K+ installs across the portfolio →

Get WordPress vulnerability alerts from the WPVulnerability Database API.

How scoring works →
97 Health · A
Maintenance 100/100
Rating quality 91/100
Support 100/100

97 health vs 64 average across 997 Security plugins

Directory ranking optimization

How it's scored →

How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.

93 / 100

Excellent listing optimization

Well tuned across the board

Update recency 100/100
WP compatibility 100/100
Rating quality 80/100
Listing tuning 84/100
Support resolution 100/100

Daily downloads

Since 2022-10-05 · 1,424 days · wp.org + Plugin Pulse archive

+64% vs prior 30d
573Downloads · Aug 26

30-day downloads

Rolling 30-day volume · peaks are release surges

48.1K

now · peak 73.4K

47.9K30d downloads · Aug 26

Directory rank vs rivals

wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you

WPVulnerability · #1572 you Patchstack · #703 Lockdown WP Admin · #1839 IP Geo Block · #2417

Update activity

How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.

4.8Kper 1k installs · Aug 26

Release cadence

Actively maintained
from wp.org release tags

How often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.

11

releases in the last 12 months

2mo ago

latest release · v5.1.1

54

tagged releases on record

Recent releases

5.1.1 · 2mo ago5.0.1 · 3mo ago5.0.0 · 3mo ago4.3.2 · 3mo ago4.3.1 · 7mo ago4.3.0 · 7mo ago4.2.1.1 · 7mo ago4.2.1 · 8mo ago4.2.0 · 10mo ago4.1.1 · 11mo ago4.1.0 · 12mo ago4.0.4 · 1.4y ago4.0.3 · 1.8y ago4.0.2 · 1.8y ago

What its installed base runs

via wordpress.org

Share of active installs on each version of this plugin · 63% run the current release. Green is the current release; a big slice on older versions is a user base that has stopped updating.

v5.1 63%
v5.0 11%
v4.3 8.7%
v4.0 6.7%
Older / other versions 11%

Estimated active installs

The public count shows “10K+”. Our estimate pins where the real number sits.

tracked estimate
10K–20K ≈19K

Refined from the date this plugin crossed into its current band.

Install history · since 2022-06-01 · 1,425 observations

10KInstalls · Aug 26

Estimated value

What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.

Est. annual revenue

N/A

Est. acquisition value

N/A

No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price.

Details

Version
5.1.6
Last updated
5d ago
Added
2022-05-06 · 4 yrs old
Requires WP
4.7
Tested up to
7.1
Requires PHP
7.0

Recent reviews

All reviews on wp.org ↗
  1. Bubalubs
    1.6y ago

    It is a must have install on every WP project for security and maintaince! 🙂 Backed up by a open API that shares vulnerabilities. Thank you! 😊

    Read on wp.org ↗
  2. Dan Bamber
    1.6y ago

    Without a doubt, the most important plugin to install on your WordPress instance.

    Read on wp.org ↗
  3. Lolo Marchal
    2.3y ago

    Resume en un solo plugin todas las vulnerabilidades tu WordPress, Plugins y Themes. Para mi es un “musthave” desde hace más de 1 año. Lo instalo en todas mis auditorías.

    Read on wp.org ↗
  4. pixluser
    2.4y ago

    Vulnerabilities are listed into your plugins list.You should also being able to receive an automatic email too. It doesn’t work on my system, but email test yes.So awesome plugin anyway!

    Read on wp.org ↗
  5. Groovyx9
    2.4y ago

    Exactly what I was looking for ! On the roadmap, it would be nice if : we can chose if we want to receive an email OR not (I may use it as a vuln reminder on the dashboard, as I have other plugins already keeping me informed) we can chose what will be in the email – php or not for exemple (it seems that it is planned, thanks) only receive an email if one the vuln is considered high risk etc.

    Read on wp.org ↗
  6. Martin Sauter
    2.5y ago

    This plugin alerts you about known vulnerabilities in your WordPress core, plugins, themes, and even PHP, so you can take action in a timely manner. If you don’t have this plugin on your site already, you absolutely need it!

    Read on wp.org ↗
  7. Mercadearse
    2.6y ago

    Este plugin es de los primeros que instalo en cada proyecto que ejecuto. Tanto para proyectos desde cero y con mucha más razón para corrección de fallos en proyectos iniciados.

    Read on wp.org ↗
  8. Chabi Angulo
    2.6y ago

    Sin duda alguna, es el plugin que te ayuda estar informado de vulnerabilidades. Uno de los plugins que instalo por defecto en cuanto empiezo una web.

    Read on wp.org ↗

Latest updates

via wp.org changelog

Recent releases and news for this plugin

  1. 2026-08-22 Version 5.1.6 Fixed Saving the “Delete all plugin data on uninstall” preference no longer triggers a fatal error ( add_settings_error() was called before the WordPress admin API was loaded). Notification channels can now be disabled e 5.1.6
  2. 2026-08-22 Version 5.1.5 Changed The contributor list now leads with the ROBOTSTXT organization account, followed by Javier Casares; the remaining contributors are unchanged. Regenerated languages/wpvulnerability.pot so its source references mat 5.1.5
  3. 2026-08-22 Version 5.1.4 Highlights The Site Health vulnerability tests work again on every WordPress version: they were silently disabled everywhere by an availability gate that could never pass. Secrets are now masked in the admin forms, and c 5.1.4
  4. 2026-08-07 Version 5.1.2 Fixed Missing load_plugin_textdomain() call caused a “Translation loading for the wpvulnerability domain was triggered too early” _doing_it_wrong() notice on WordPress 6.7+. The textdomain is now explicitly loaded on the 5.1.2
  5. 2026-07-09 Version 5.1.1 Fixed Site Health: the memcached, Redis, and SQLite vulnerability tests always returned “Invalid software type” because those components were missing from the software list. They now run correctly. “Send test email” fail 5.1.1
  6. 2026-07-08 Version 5.1.0 Security wpvulnerability_validate_shell_command() now uses exact in_array() match instead of stripos() substring matching for the shell-command allowlist (defense-in-depth). wpvulnerability_detect_php() , wpvulnerability 5.1.0

Known vulnerabilities

via Wordfence Intelligence

1 disclosed vulnerability on record for this plugin, fixed in the current version. Sites on older versions stay exposed until they update.

  1. 2026-03-18 CVE-2026-24376 Missing Authorization Affects <= 4.2.1 Patched in 4.2.1.1

Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.

CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.

Behavioral tests

via WP Hive

Automated install-time checks, tested on PHP 8.1.12 · WP 7.0

Low memory footprint
Low page-speed impact
Runs on latest PHP + WP
No PHP errors
No JS errors
Activates cleanly
No resource errors
No external HTTP errors
Optimized database use
Frequently updated

Languages

via translate.wordpress.org

Translated into 16 languages, 1 at 90% or more

Spanish (Spain) 90%
Catalan 89%
Japanese 89%
Russian 89%
Spanish (Chile) 89%
Dutch 70%
Dutch (Belgium) 64%
Romanian 62%
French (France) 31%
Chinese (Taiwan) 30%
Dutch (Formal) 23%
Galician 16%
Basque 9%
Catalan (Valencian) 5%
German 4%
Italian 1%

Growth timeline

Install-tier crossings we have observed, and how long each tier took to outgrow

  1. 2024-05-18 9K+ → 10K+ up after 45 days in tier
  2. 2024-04-03 8K+ → 9K+ up after 110 days in tier
  3. 2023-12-15 7K+ → 8K+ up after 31 days in tier
  4. 2023-11-14 6K+ → 7K+ up after 24 days in tier
  5. 2023-10-21 5K+ → 6K+ up after 24 days in tier
  6. 2023-09-27 4K+ → 5K+ up after 22 days in tier
  7. 2023-09-05 3K+ → 4K+ up after 22 days in tier
  8. 2023-08-14 2K+ → 3K+ up after 88 days in tier

Competes with

The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).

Compare head to head →

Embed this report card

Drop a live Pulse card for WPVulnerability into a readme, a review or a deck. It updates itself.

<iframe src="https://plugins.wpmayor.com/embed/wpvulnerability" width="480" height="300" style="border:0" loading="lazy" title="WPVulnerability — Plugin Pulse"></iframe>
Preview card ↗

WPVulnerability: 10K+ active installs, 5.0★ (20 reviews). Plugin Pulse (WP Mayor), as of 2026-08-28. https://plugins.wpmayor.com/plugin/wpvulnerability