BLACK FRIDAY
Save 59% on PageForge Annual $191/year $485/year
Claim 59% Off →
SiteCare – Vulnerability Scanner icon
Actively maintained Tested with WP 7.1 #1 in plugin vulnerability

SiteCare – Vulnerability Scanner

Know the instant a plugin, theme or WordPress core has a known security hole - with a security score and clear fixes. Patch before attackers do.

Active installs30+10+ tier
Downloads · 30d186▲ +148% vs prev. 30d
Rating5/52 reviews
Health score74/100Good
All-time downloads1.7KSince Oct 2024
Support resolved—No recent threads
RequiresWP 6.1PHP 7.4+
Downloads · 7d26▼ -50% week over week
Our verdict

Solid choice

SiteCare – Vulnerability Scanner is a solid plugin choice in 2026, with a few things worth checking first. It runs on 30+ sites, is rated 5/5 and was last updated 3 weeks ago, and scores 74/100 on our health check.

  • Actively developed — last update 3 weeks ago
  • Tested with the latest WordPress (7.1)
  • Small user base (30+ active installs)
  • Very few reviews so far

Daily downloads

204060Jul 5Aug 18Oct 2
Yesterday4
Daily average (1y)3
Peak day80Jul 21, 2026
Last 12 months1.1K

Download spikes usually follow a new release — each site that auto-updates counts as a download.

Rankings

Where SiteCare stands today

WordPress.org search rankings

Live position in the plugin search, top 100
KeywordPositionCompeting pluginsCategory
plugin vulnerability #26 3,727 Best plugin vulnerability plugins →
security >100 10,000 Best security plugins →
vulnerabilities #51 3,736 Best vulnerabilities plugins →
vulnerability scan #8 483 Best vulnerability scan plugins →
vulnerability scanner #9 287 Best vulnerability scanner plugins →

Version adoption

Share of active sites per release.

  • 2.2100.0%

Rating breakdown

★★★★★★★★★★ 5 from 2 reviews

  • 5★100.0%
  • 4★0.00%
  • 3★0.00%
  • 2★0.00%
  • 1★0.00%

About SiteCare – Vulnerability Scanner

From the official readme · v2.2.1

Description

Most compromised WordPress sites aren’t hit by some clever, brand-new exploit – they’re breached through a known vulnerability in an outdated plugin or theme that nobody noticed in time. The fix is almost always as simple as running an update. The hard part is knowing there’s a problem at all.

SiteCare Vulnerability Scanner watches that blind spot for you. It checks your installed plugins, themes, and WordPress core against a continuously updated database of publicly known vulnerabilities, then tells you in plain language – right in your dashboard – what is affected and what to do about it.

  • Automatic daily monitoring in the background – plus an instant re-scan whenever you install, update or activate a plugin or theme.
  • Email alerts the moment a new vulnerability appears, so you find out without having to be logged in.
  • Clear severity ratings (CVSS) and CVE references, with the most urgent components listed first.
  • One-click updates right from the results whenever a fix is available.
  • Security score A-F (0-100) that grades your whole site at a glance, with a trend against your previous scan.
  • Abandoned & removed plugin detection – warns you when an installed plugin has been closed on WordPress.org or has had no update for years.
  • Slack / Discord alerts via webhook, and a WP-CLI command (wp vulnerability scan) with a CI-friendly exit code.
  • Shown where you already look – a dashboard widget and a WordPress Site Health check.

Your site’s data never leaves your server. The plugin only reads public vulnerability information through the WP Vulnerability API – no account, no external tracking, and no noticeable impact on performance.

Key Features

  • Accurate version-range detection against a continuously updated vulnerability database
  • Automatic background scans (daily, configurable) with instant re-checks after site changes
  • Email alerts for newly discovered vulnerabilities – only new ones, never repeated
  • Severity ratings (CVSS), CVE references and “fixed in” versions
  • One-click updates for affected plugins, themes and WordPress core
  • Dashboard widget and WordPress Site Health integration
  • Security score (A-F / 0-100) with a trend against the previous scan
  • Detection of abandoned and removed (closed) plugins via the WordPress.org API
  • Slack and Discord notifications through a webhook URL
  • WP-CLI command (wp vulnerability scan / status) with a CI-friendly exit code
  • Ships fully translated into five world languages – German, Spanish, French, Portuguese and Russian – plus Czech.
  • Read-only: only component slugs and versions are sent; no data leaves your site
  • Support development via Buy Me a Coffee

License

This plugin is distributed under the GNU General Public License v2.0 or later. See the license.txt file for details.

Installation

From your WordPress dashboard (recommended)

  1. Go to Plugins → Add New and search for “SiteCare Vulnerability Scanner”.
  2. Click Install Now, then Activate.

Manual upload

  1. Download the plugin .zip file.
  2. Go to Plugins → Add New → Upload Plugin and choose the .zip.
  3. Click Install Now, then Activate.

Getting started

Open the Vulnerabilities menu in your WordPress admin. The first scan runs automatically; press Scan now any time to re-check. Fine-tune the automatic scan frequency and email alerts under Vulnerabilities → Settings.

Frequently asked questions

Does it scan automatically?

Yes. It runs a background scan once a day (configurable) and an immediate re-scan whenever you install, update or activate a plugin or theme. You can also press “Scan now” any time.

Will it email me?

Yes, if email alerts are enabled (they are by default). You are notified only about new vulnerabilities, never repeatedly about the same one. You can turn this off under Vulnerabilities → Settings.

How does it decide something is vulnerable?

It compares your installed version against the affected version ranges published for each known vulnerability – so it catches issues even when you are several versions behind, not only on an exact-version match.

Does it send my data anywhere?

No. Only the public slug and version of each plugin, theme and WordPress core are looked up against the WP Vulnerability API. No site content, credentials or personal data ever leave your server.

Does it slow down my site?

No. Lookups are cached and scans run in the background via WP-Cron, so your admin stays fast.

What is the security score?

A single A-F grade (0-100) that summarises the health of your whole site – lower when you have open vulnerabilities or abandoned components, higher when everything is up to date. Each scan also shows whether the score went up or down since last time.

How do abandoned / removed plugins get flagged?

The plugin checks each installed component against the WordPress.org directory. If a plugin has been closed (removed) or has had no update for a very long time, it is flagged so you can plan a replacement. Premium or off-directory plugins are not falsely flagged.

Can I get Slack or Discord alerts?

Yes. Paste a Slack or Discord webhook URL under Vulnerabilities → Settings and new findings are posted there.

Is there a WP-CLI command?

Yes: wp vulnerability scan and wp vulnerability status. It returns a non-zero exit code when vulnerabilities are found, so you can use it in CI.

Can I support plugin development?

Yes, via Buy Me a Coffee.

Changelog

Major upgrade: the detection engine was rewritten to catch vulnerabilities it previously missed, and now adds automatic daily scanning and email alerts. Strongly recommended for all users.

2.2.1

  • Hardened admin output: all icon and button markup now passes through wp_kses().
  • Set “Requires at least” to 5.2 to match the readme and the scheduling functions used.
  • Added direct-access protection to the WP-CLI file.
  • Completed the translations – all six locales now cover every string.

2.2.0

  • Critical-severity rows now have a distinct stronger red highlight, separate from Unknown/Unrated rows.
  • Webhook URL is sanitized with esc_url_raw() on save.

2.1.9

  • The scanner screens are now ad-free: notices and promos injected by other plugins no longer appear inside them.

2.1.8

  • Czech translation is back on board alongside the five world languages.

2.1.7

  • Unified translations across the SiteCare family: five world languages (German, Spanish, French, Portuguese, Russian).
  • Refreshed screenshots.

2.1.6

  • Shortened the directory description to fit WordPress.org limits.

Full changelog on WordPress.org →

Screenshots

A vulnerable plugin caught: severity badges, CVE links, "fixed in" versions and the security score reacting instantly.
A vulnerable plugin caught: severity badges, CVE links, "fixed in" versions and the…
All clear - the A-F security score, severity tiles and every plugin, theme and WordPress core checked.
All clear - the A-F security score, severity tiles and every plugin, theme and WordPress…
Settings: automatic scan frequency, email alerts and an optional Slack/Discord webhook.
Settings: automatic scan frequency, email alerts and an optional Slack/Discord webhook.

For developers

Is this your plugin? Show off the numbers.

Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.

Active installs badge Rating badge Health score badge

FAQ

SiteCare – Vulnerability Scanner: quick answers

Straight answers, pulled from live WordPress.org data.

Live data from WordPress.org · checked Oct 3, 2026

Is SiteCare – Vulnerability Scanner free?

Yes. SiteCare – Vulnerability Scanner is free to download and use from the official WordPress.org plugin directory.

Is SiteCare – Vulnerability Scanner safe to use in 2026?

SiteCare – Vulnerability Scanner is a solid plugin choice in 2026, with a few things worth checking first. It runs on 30+ sites, is rated 5/5 and was last updated 3 weeks ago, and scores 74/100 on our health check.

How many websites use SiteCare – Vulnerability Scanner?

SiteCare – Vulnerability Scanner is active on 30+ WordPress websites and has been downloaded 1,674 times since it launched in October 2024. It was downloaded 186 times in the last 30 days.

Does SiteCare – Vulnerability Scanner work with WordPress 7.1?

Yes. The developer has tested SiteCare – Vulnerability Scanner up to WordPress 7.1.2, the latest release. It requires WordPress 6.1 or newer.

What PHP version does SiteCare – Vulnerability Scanner need?

SiteCare – Vulnerability Scanner requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.

When was SiteCare – Vulnerability Scanner last updated?

The latest version, 2.2.1, was released on September 11, 2026 (3 weeks ago).

Who makes SiteCare – Vulnerability Scanner?

SiteCare – Vulnerability Scanner is developed and maintained by SiteCare.

Powered by PageForge

Want thousands of pages that rank like these? Build them in an afternoon.

This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.

  • CSV, Google Sheets & API data sources
  • AI content, schema & internal links per page
  • Works with Elementor, Gutenberg, Yoast & Rank Math
  • Free on WordPress.org — no credit card
Sarah is here to help!
Hi there! 👋 Need help finding what you're looking for?
Sarah
Sarah
Online & Ready to Help
Hi there! 👋 Need help finding what you're looking for?

We'll use this to continue our conversation

Just now ✓ Verified

Join 500+ SEO Pros Scaling Their Strategy

Get exclusive programmatic SEO tactics, AI content workflows, and the latest PageForge updates delivered straight to your inbox. Stay ahead of the algorithm.

We care about your data in our privacy policy.