SiteCare – Vulnerability Scanner
Know the instant a plugin, theme or WordPress core has a known security hole - with a security score and clear fixes. Patch before attackers do.
Solid choice
SiteCare – Vulnerability Scanner is a solid plugin choice in 2026, with a few things worth checking first. It runs on 30+ sites, is rated 5/5 and was last updated 3 weeks ago, and scores 74/100 on our health check.
- Actively developed — last update 3 weeks ago
- Tested with the latest WordPress (7.1)
- Small user base (30+ active installs)
- Very few reviews so far
Daily downloads
Download spikes usually follow a new release — each site that auto-updates counts as a download.
Rankings
Where SiteCare stands todayWordPress.org search rankings
Live position in the plugin search, top 100| Keyword | Position |
|---|---|
| plugin vulnerability | #26 |
| security | >100 |
| vulnerabilities | #51 |
| vulnerability scan | #8 |
| vulnerability scanner | #9 |
Version adoption
Share of active sites per release.
Rating breakdown
★★★★★★★★★★ 5 from 2 reviews
About SiteCare – Vulnerability Scanner
From the official readme · v2.2.1Description
Most compromised WordPress sites aren’t hit by some clever, brand-new exploit – they’re breached through a known vulnerability in an outdated plugin or theme that nobody noticed in time. The fix is almost always as simple as running an update. The hard part is knowing there’s a problem at all.
SiteCare Vulnerability Scanner watches that blind spot for you. It checks your installed plugins, themes, and WordPress core against a continuously updated database of publicly known vulnerabilities, then tells you in plain language – right in your dashboard – what is affected and what to do about it.
- Automatic daily monitoring in the background – plus an instant re-scan whenever you install, update or activate a plugin or theme.
- Email alerts the moment a new vulnerability appears, so you find out without having to be logged in.
- Clear severity ratings (CVSS) and CVE references, with the most urgent components listed first.
- One-click updates right from the results whenever a fix is available.
- Security score A-F (0-100) that grades your whole site at a glance, with a trend against your previous scan.
- Abandoned & removed plugin detection – warns you when an installed plugin has been closed on WordPress.org or has had no update for years.
- Slack / Discord alerts via webhook, and a WP-CLI command (
wp vulnerability scan) with a CI-friendly exit code. - Shown where you already look – a dashboard widget and a WordPress Site Health check.
Your site’s data never leaves your server. The plugin only reads public vulnerability information through the WP Vulnerability API – no account, no external tracking, and no noticeable impact on performance.
Key Features
- Accurate version-range detection against a continuously updated vulnerability database
- Automatic background scans (daily, configurable) with instant re-checks after site changes
- Email alerts for newly discovered vulnerabilities – only new ones, never repeated
- Severity ratings (CVSS), CVE references and “fixed in” versions
- One-click updates for affected plugins, themes and WordPress core
- Dashboard widget and WordPress Site Health integration
- Security score (A-F / 0-100) with a trend against the previous scan
- Detection of abandoned and removed (closed) plugins via the WordPress.org API
- Slack and Discord notifications through a webhook URL
- WP-CLI command (
wp vulnerability scan/status) with a CI-friendly exit code - Ships fully translated into five world languages – German, Spanish, French, Portuguese and Russian – plus Czech.
- Read-only: only component slugs and versions are sent; no data leaves your site
- Support development via Buy Me a Coffee
License
This plugin is distributed under the GNU General Public License v2.0 or later. See the license.txt file for details.
Installation
From your WordPress dashboard (recommended)
- Go to Plugins → Add New and search for “SiteCare Vulnerability Scanner”.
- Click Install Now, then Activate.
Manual upload
- Download the plugin .zip file.
- Go to Plugins → Add New → Upload Plugin and choose the .zip.
- Click Install Now, then Activate.
Getting started
Open the Vulnerabilities menu in your WordPress admin. The first scan runs automatically; press Scan now any time to re-check. Fine-tune the automatic scan frequency and email alerts under Vulnerabilities → Settings.
Frequently asked questions
Does it scan automatically?
Yes. It runs a background scan once a day (configurable) and an immediate re-scan whenever you install, update or activate a plugin or theme. You can also press “Scan now” any time.
Will it email me?
Yes, if email alerts are enabled (they are by default). You are notified only about new vulnerabilities, never repeatedly about the same one. You can turn this off under Vulnerabilities → Settings.
How does it decide something is vulnerable?
It compares your installed version against the affected version ranges published for each known vulnerability – so it catches issues even when you are several versions behind, not only on an exact-version match.
Does it send my data anywhere?
No. Only the public slug and version of each plugin, theme and WordPress core are looked up against the WP Vulnerability API. No site content, credentials or personal data ever leave your server.
Does it slow down my site?
No. Lookups are cached and scans run in the background via WP-Cron, so your admin stays fast.
What is the security score?
A single A-F grade (0-100) that summarises the health of your whole site – lower when you have open vulnerabilities or abandoned components, higher when everything is up to date. Each scan also shows whether the score went up or down since last time.
How do abandoned / removed plugins get flagged?
The plugin checks each installed component against the WordPress.org directory. If a plugin has been closed (removed) or has had no update for a very long time, it is flagged so you can plan a replacement. Premium or off-directory plugins are not falsely flagged.
Can I get Slack or Discord alerts?
Yes. Paste a Slack or Discord webhook URL under Vulnerabilities → Settings and new findings are posted there.
Is there a WP-CLI command?
Yes: wp vulnerability scan and wp vulnerability status. It returns a non-zero exit code when vulnerabilities are found, so you can use it in CI.
Can I support plugin development?
Yes, via Buy Me a Coffee.
Changelog
Major upgrade: the detection engine was rewritten to catch vulnerabilities it previously missed, and now adds automatic daily scanning and email alerts. Strongly recommended for all users.
2.2.1
- Hardened admin output: all icon and button markup now passes through wp_kses().
- Set “Requires at least” to 5.2 to match the readme and the scheduling functions used.
- Added direct-access protection to the WP-CLI file.
- Completed the translations – all six locales now cover every string.
2.2.0
- Critical-severity rows now have a distinct stronger red highlight, separate from Unknown/Unrated rows.
- Webhook URL is sanitized with esc_url_raw() on save.
2.1.9
- The scanner screens are now ad-free: notices and promos injected by other plugins no longer appear inside them.
2.1.8
- Czech translation is back on board alongside the five world languages.
2.1.7
- Unified translations across the SiteCare family: five world languages (German, Spanish, French, Portuguese, Russian).
- Refreshed screenshots.
2.1.6
- Shortened the directory description to fit WordPress.org limits.
For developers
Is this your plugin? Show off the numbers.
Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.
FAQ
SiteCare – Vulnerability Scanner: quick answers
Straight answers, pulled from live WordPress.org data.
Live data from WordPress.org · checked Oct 3, 2026
Is SiteCare – Vulnerability Scanner free?
Yes. SiteCare – Vulnerability Scanner is free to download and use from the official WordPress.org plugin directory.
Is SiteCare – Vulnerability Scanner safe to use in 2026?
SiteCare – Vulnerability Scanner is a solid plugin choice in 2026, with a few things worth checking first. It runs on 30+ sites, is rated 5/5 and was last updated 3 weeks ago, and scores 74/100 on our health check.
How many websites use SiteCare – Vulnerability Scanner?
SiteCare – Vulnerability Scanner is active on 30+ WordPress websites and has been downloaded 1,674 times since it launched in October 2024. It was downloaded 186 times in the last 30 days.
Does SiteCare – Vulnerability Scanner work with WordPress 7.1?
Yes. The developer has tested SiteCare – Vulnerability Scanner up to WordPress 7.1.2, the latest release. It requires WordPress 6.1 or newer.
What PHP version does SiteCare – Vulnerability Scanner need?
SiteCare – Vulnerability Scanner requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.
When was SiteCare – Vulnerability Scanner last updated?
The latest version, 2.2.1, was released on September 11, 2026 (3 weeks ago).
Who makes SiteCare – Vulnerability Scanner?
SiteCare – Vulnerability Scanner is developed and maintained by SiteCare.
Powered by PageForge
Want thousands of pages that rank like these? Build them in an afternoon.
This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.
- CSV, Google Sheets & API data sources
- AI content, schema & internal links per page
- Works with Elementor, Gutenberg, Yoast & Rank Math
- Free on WordPress.org — no credit card


