BLACK FRIDAY
Save 59% on PageForge Annual $191/year $485/year
Claim 59% Off →
CodeMedic SupplyScope icon
Actively maintained Tested up to 7.0.6 #13 in composer

CodeMedic SupplyScope

Scans WordPress plugins for vulnerable Composer dependencies and reports CVEs before they become breaches.

Active installs<10New
Downloads · 30d55▲ +31% vs prev. 30d
Rating—0 reviews
Health score55/100Fair
All-time downloads177Since Jul 2026
Support resolved—No recent threads
RequiresWP 5.8PHP 7.4+
Downloads · 7d17▲ +6.3% week over week
Our verdict

Use with caution

CodeMedic SupplyScope works, but test it on a staging site before relying on it in 2026. Was last updated 2 months ago, and scores 55/100 on our health check.

  • Small user base (<10 active installs)
  • Very few reviews so far

How does it stack up?

Side-by-side on installs, updates, ratings & support

Daily downloads

61218Jul 24Aug 28Oct 3
Yesterday1
Daily average (1y)2
Peak day24Jul 25, 2026
Last 12 months177

Download spikes usually follow a new release — each site that auto-updates counts as a download.

Rankings

Where CodeMedic SupplyScope stands today

WordPress.org search rankings

Live position in the plugin search, top 100
KeywordPositionCompeting pluginsCategory
composer >100 1,922 Best composer plugins →
cve #46 899 Best cve plugins →
dependencies >100 6,042 Best dependencies plugins →
security >100 10,000 Best security plugins →
vulnerabilities >100 3,740 Best vulnerabilities plugins →

About CodeMedic SupplyScope

From the official readme · v1.0.0

Description

CodeMedic SupplyScope detects vulnerable Composer packages bundled within your WordPress plugins. Every hour, it scans your active plugins against a continuously updated CVE intelligence feed and displays the results in a clear admin dashboard.

Stop guessing which plugins have unpatched vulnerabilities. Get visibility into the hidden dependency chain of every plugin on your site.

How It Works

  1. Discovery — Every hour, the plugin scans all active WordPress plugins for bundled Composer dependencies and checks them against our cloud CVE API.
  2. Review — Detected vulnerabilities are listed in the admin screen with CVE details, severity, and affected library information.
  3. Act — The plugin reports what’s vulnerable so you can take action — whether that means updating the plugin, replacing it, or applying patches manually.

Why Dependency Scanning?

WordPress plugins often bundle Composer dependencies (Guzzle, Monolog, PHPUnit, etc.) directly in their vendor directory. Plugin authors may not update these dependencies promptly after a CVE is disclosed. Without a scanner, you have no visibility into these hidden risks.

Patchstack and Wordfence block exploit attempts at the perimeter. This plugin tells you what’s vulnerable so you can take action — whether that means updating the plugin, replacing it, or applying patches manually.

External Services

This plugin queries several third-party vulnerability databases to detect known CVEs in Composer dependencies bundled by your WordPress plugins. No personally identifiable information is transmitted. Each service is described below.

OSV.dev

What it is: OSV.dev is an open-source vulnerability database maintained by Google. It is used to look up known vulnerabilities in Composer (Packagist) packages.

Data sent: Composer package names and version numbers are sent as JSON in a batch query.

When: On every scheduled scan and when a manual scan is triggered from the admin dashboard.

Terms of Service: https://google.github.io/osv.dev/
Privacy Policy: https://policies.google.com/privacy

National Vulnerability Database (NVD)

What it is: The NVD is a public vulnerability database maintained by NIST (U.S. National Institute of Standards and Technology). It is used to search for CVEs related to WordPress plugins by keyword.

Data sent: The WordPress plugin name is sent as a keyword search query parameter. No personal data is transmitted.

When: On every scheduled scan and when a manual scan is triggered from the admin dashboard.

Terms of Service: https://nvd.nist.gov/developers/terms-of-use
Privacy Policy: https://www.nist.gov/privacy-policy

Note: This product uses data from the NVD API but is not endorsed or certified by the NVD.

WPVulnerability.net

What it is: WPVulnerability.net is an open-source WordPress vulnerability database. It provides aggregated vulnerability data for WordPress core, plugins, and themes.

Data sent: The WordPress plugin slug is sent as part of the API URL path. No personal data is transmitted.

When: On every scheduled scan and when a manual scan is triggered from the admin dashboard.

Terms of Service: https://www.wpvulnerability.com/license/
Privacy Policy: https://www.wpvulnerability.com/privacy/

WordPress.org Plugin API

What it is: The official WordPress.org plugin information API. It is used to retrieve plugin metadata (such as the current stable version and last updated date) to calculate patch velocity metrics.

Data sent: The WordPress plugin slug is sent as a query parameter. No personal data is transmitted.

When: On every scheduled scan and when a manual scan is triggered from the admin dashboard.

Terms of Service: https://wordpress.org/about/privacy/
Privacy Policy: https://wordpress.org/about/privacy/

Installation

  1. Upload the codemedic-supplyscope folder to the /wp-content/plugins/ directory.
  2. Activate the plugin through the ‘Plugins’ menu in WordPress.
  3. The plugin begins scanning hourly for vulnerable dependencies. Review findings from Tools > Dep Scanner.

Frequently asked questions

Does this plugin modify my files?

No. The free version is read-only — it scans and reports vulnerabilities but never modifies any files.

How do I fix the vulnerabilities this plugin finds?

Update the affected plugin if a newer version is available, replace it with an alternative, or use the patch history to manually apply fixes.

Can I use this alongside other security plugins?

Yes. This plugin is complementary to firewalls and WAFs. It focuses on visibility into bundled Composer dependencies that other tools don’t inspect.

Changelog

1.0.0

  • Initial release.
  • Hourly scanning of active plugins for bundled Composer dependencies.
  • Cloud-based CVE intelligence feed.
  • Read-only vulnerability dashboard with CVE details and severity.
  • Patch history log.
  • Patch history log for audit and manual remediation.

Full changelog on WordPress.org →

Screenshots

The admin screen showing detected vulnerabilities with CVE details.
The admin screen showing detected vulnerabilities with CVE details.

For developers

Is this your plugin? Show off the numbers.

Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.

Active installs badge Rating badge Health score badge

Best CodeMedic SupplyScope alternatives

All composer plugins →
Alternatives
Rank Plugin Active installs Rating Updated Health
1 Falang for YOOtheme Lite Falang for YOOtheme Lite Simplify YOOtheme translations by translating content directly in each element of the… by sbouey 200+ ★★★★★★★★★★ 5 (15) 1 month ago 72
2 Advanced Composer Blocks for Newsletter Advanced Composer Blocks for Newsletter A set of enhanced composer blocks and additional settings to extend The Newsletter Plugin. by mdburnette 100+ ★★★★★★★★★★ No reviews 9 months ago 40
3 WP Composer WP Composer Adding Composer dependency management to WP CLI. by Sean Fisher 70+ ★★★★★★★★★★ 5 (2) 13 years ago 32
4 Falang for WPBakery Lite Falang for WPBakery Lite The Falang for WPBakery plugin makes your WPBakery page translation simpler. by sbouey 60+ ★★★★★★★★★★ 5 (3) 1 year ago 35
5 RSS Block for Newsletter RSS Block for Newsletter Adds a RSS block to the Newsletter composer to embed content in newsletters from external… by Stefano Lissa 60+ ★★★★★★★★★★ No reviews 3 years ago 25
6 BCorp Visual Editor BCorp Visual Editor Powerful drag and drop page builder. by BCorp 20+ ★★★★★★★★★★ 5 (3) 11 years ago 31
7 Rexpansive Builder Rexpansive Builder The new and awesome plugin to build a page in 1 minute! Expand your mind! by neweb_agency 10+ ★★★★★★★★★★ 5 (3) 12 months ago 45
8 Tiny Addons for WPBakery Page Builder Tiny Addons for WPBakery Page Builder Adds useful elements to WPBakery Page Builder. Build awesome websites with these light… by Sei Nakamura 10+ ★★★★★★★★★★ No reviews 8 years ago 23
9 Newsletter Composer Newsletter Composer This plugins makes an HTML newsletter file with the category you have selected. by ralerin 10+ ★★★★★★★★★★ No reviews 13 years ago 23
10 Known Plugin Dependencies Known Plugin Dependencies Add-on plugin for the WordPress Plugin Dependencies plugin, injecting additional… by Juliette Reinders Folmer 10+ ★★★★★★★★★★ 5 (1) 11 years ago 30

FAQ

CodeMedic SupplyScope: quick answers

Straight answers, pulled from live WordPress.org data.

Live data from WordPress.org · checked Oct 4, 2026

Is CodeMedic SupplyScope free?

Yes. CodeMedic SupplyScope is free to download and use from the official WordPress.org plugin directory.

Is CodeMedic SupplyScope safe to use in 2026?

CodeMedic SupplyScope works, but test it on a staging site before relying on it in 2026. Was last updated 2 months ago, and scores 55/100 on our health check.

How many websites use CodeMedic SupplyScope?

CodeMedic SupplyScope is active on <10 WordPress websites and has been downloaded 177 times since it launched in July 2026. It was downloaded 55 times in the last 30 days.

Does CodeMedic SupplyScope work with WordPress 7.1?

CodeMedic SupplyScope is officially tested up to WordPress 7.0.6, while the latest release is 7.1.2. It may still work, but try it on a staging site first.

What PHP version does CodeMedic SupplyScope need?

CodeMedic SupplyScope requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.

When was CodeMedic SupplyScope last updated?

The latest version, 1.0.0, was released on July 25, 2026 (2 months ago).

Who makes CodeMedic SupplyScope?

CodeMedic SupplyScope is developed and maintained by adrianmikula.

What are the best alternatives to CodeMedic SupplyScope?

The most popular alternatives to CodeMedic SupplyScope are Falang for YOOtheme Lite (200+ installs), Advanced Composer Blocks fo… (100+ installs) and WP Composer (70+ installs).

Powered by PageForge

Want thousands of pages that rank like these? Build them in an afternoon.

This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.

  • CSV, Google Sheets & API data sources
  • AI content, schema & internal links per page
  • Works with Elementor, Gutenberg, Yoast & Rank Math
  • Free on WordPress.org — no credit card
Sarah is here to help!
Hi there! 👋 Need help finding what you're looking for?
Sarah
Sarah
Online & Ready to Help
Hi there! 👋 Need help finding what you're looking for?

We'll use this to continue our conversation

Just now ✓ Verified

Join 500+ SEO Pros Scaling Their Strategy

Get exclusive programmatic SEO tactics, AI content workflows, and the latest PageForge updates delivered straight to your inbox. Stay ahead of the algorithm.

We care about your data in our privacy policy.