WPVulnerability
by ROBOTSTXT.es · Security
Also makes 1 other plugin · 13K+ installs across the portfolio →
Get WordPress vulnerability alerts from the WPVulnerability Database API.
97 health vs 64 average across 997 Security plugins
Directory ranking optimization
How it's scored →How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.
Excellent listing optimization
Well tuned across the board
Daily downloads
Since 2022-10-05 · 1,424 days · wp.org + Plugin Pulse archive
30-day downloads
Rolling 30-day volume · peaks are release surges
48.1K
now · peak 73.4K
Directory rank vs rivals
wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you
Update activity
How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.
Release cadence
Actively maintainedHow often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.
11
releases in the last 12 months
2mo ago
latest release · v5.1.1
54
tagged releases on record
Recent releases
What its installed base runs
via wordpress.orgShare of active installs on each version of this plugin · 63% run the current release. Green is the current release; a big slice on older versions is a user base that has stopped updating.
Estimated active installs
The public count shows “10K+”. Our estimate pins where the real number sits.
Refined from the date this plugin crossed into its current band.
Install history · since 2022-06-01 · 1,425 observations
Estimated value
What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.
Est. annual revenue
Est. acquisition value
No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price.
Details
Recent reviews
All reviews on wp.org ↗- ★★★★★ Bubalubs1.6y ago
It is a must have install on every WP project for security and maintaince! 🙂 Backed up by a open API that shares vulnerabilities. Thank you! 😊
Read on wp.org ↗ - ★★★★★ Dan Bamber1.6y ago
Without a doubt, the most important plugin to install on your WordPress instance.
Read on wp.org ↗ - ★★★★★ Lolo Marchal2.3y ago
Resume en un solo plugin todas las vulnerabilidades tu WordPress, Plugins y Themes. Para mi es un “musthave” desde hace más de 1 año. Lo instalo en todas mis auditorías.
Read on wp.org ↗ - ★★★★★ pixluser2.4y ago
Vulnerabilities are listed into your plugins list.You should also being able to receive an automatic email too. It doesn’t work on my system, but email test yes.So awesome plugin anyway!
Read on wp.org ↗ - ★★★★★ Groovyx92.4y ago
Exactly what I was looking for ! On the roadmap, it would be nice if : we can chose if we want to receive an email OR not (I may use it as a vuln reminder on the dashboard, as I have other plugins already keeping me informed) we can chose what will be in the email – php or not for exemple (it seems that it is planned, thanks) only receive an email if one the vuln is considered high risk etc.
Read on wp.org ↗ - ★★★★★ Martin Sauter2.5y ago
This plugin alerts you about known vulnerabilities in your WordPress core, plugins, themes, and even PHP, so you can take action in a timely manner. If you don’t have this plugin on your site already, you absolutely need it!
Read on wp.org ↗ - ★★★★★ Mercadearse2.6y ago
Este plugin es de los primeros que instalo en cada proyecto que ejecuto. Tanto para proyectos desde cero y con mucha más razón para corrección de fallos en proyectos iniciados.
Read on wp.org ↗ - ★★★★★ Chabi Angulo2.6y ago
Sin duda alguna, es el plugin que te ayuda estar informado de vulnerabilidades. Uno de los plugins que instalo por defecto en cuanto empiezo una web.
Read on wp.org ↗
Latest updates
via wp.org changelogRecent releases and news for this plugin
- 2026-08-22 Version 5.1.6 Fixed Saving the “Delete all plugin data on uninstall” preference no longer triggers a fatal error ( add_settings_error() was called before the WordPress admin API was loaded). Notification channels can now be disabled e 5.1.6
- 2026-08-22 Version 5.1.5 Changed The contributor list now leads with the ROBOTSTXT organization account, followed by Javier Casares; the remaining contributors are unchanged. Regenerated languages/wpvulnerability.pot so its source references mat 5.1.5
- 2026-08-22 Version 5.1.4 Highlights The Site Health vulnerability tests work again on every WordPress version: they were silently disabled everywhere by an availability gate that could never pass. Secrets are now masked in the admin forms, and c 5.1.4
- 2026-08-07 Version 5.1.2 Fixed Missing load_plugin_textdomain() call caused a “Translation loading for the wpvulnerability domain was triggered too early” _doing_it_wrong() notice on WordPress 6.7+. The textdomain is now explicitly loaded on the 5.1.2
- 2026-07-09 Version 5.1.1 Fixed Site Health: the memcached, Redis, and SQLite vulnerability tests always returned “Invalid software type” because those components were missing from the software list. They now run correctly. “Send test email” fail 5.1.1
- 2026-07-08 Version 5.1.0 Security wpvulnerability_validate_shell_command() now uses exact in_array() match instead of stripos() substring matching for the shell-command allowlist (defense-in-depth). wpvulnerability_detect_php() , wpvulnerability 5.1.0
Known vulnerabilities
via Wordfence Intelligence1 disclosed vulnerability on record for this plugin, fixed in the current version. Sites on older versions stay exposed until they update.
- Medium · 4.3 WPVulnerability <= 4.2.1 - Missing Authorization ↗
Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.
CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.
Behavioral tests
via WP HiveAutomated install-time checks, tested on PHP 8.1.12 · WP 7.0
Languages
via translate.wordpress.orgTranslated into 16 languages, 1 at 90% or more
Growth timeline
Install-tier crossings we have observed, and how long each tier took to outgrow
- 2024-05-18 9K+ → 10K+ up after 45 days in tier
- 2024-04-03 8K+ → 9K+ up after 110 days in tier
- 2023-12-15 7K+ → 8K+ up after 31 days in tier
- 2023-11-14 6K+ → 7K+ up after 24 days in tier
- 2023-10-21 5K+ → 6K+ up after 24 days in tier
- 2023-09-27 4K+ → 5K+ up after 22 days in tier
- 2023-09-05 3K+ → 4K+ up after 22 days in tier
- 2023-08-14 2K+ → 3K+ up after 88 days in tier
Competes with
The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).
-
Patchstack – WordPress & Plugins Security 50K+ installs · 4.7★ · 2 shared tags A
- L Lockdown WP Admin 10K+ installs · 3.9★ · 2 shared tags D
-
IP Geo Block 8K+ installs · 4.1★ · 2 shared tags D -
WPScan – WordPress Security Scanner 8K+ installs · 3.8★ · 2 shared tags B
-
Security Ninja – WordPress Security & Firewall 7K+ installs · 4.6★ · 2 shared tags A -
Prevent XSS Vulnerability 6K+ installs · 4.3★ · 2 shared tags B
Embed this report card
Drop a live Pulse card for WPVulnerability into a readme, a review or a deck. It updates itself.
<iframe src="https://plugins.wpmayor.com/embed/wpvulnerability" width="480" height="300" style="border:0" loading="lazy" title="WPVulnerability — Plugin Pulse"></iframe> WPVulnerability: 10K+ active installs, 5.0★ (20 reviews). Plugin Pulse (WP Mayor), as of 2026-08-28. https://plugins.wpmayor.com/plugin/wpvulnerability