Skip to content

Find plugins with known vulnerabilities in ReDock Web

A plugin that is out of date is one thing. A plugin whose installed version has a published hole in it is another, and ReDock Web tells you which is which.

Every hour ReDock pulls the Wordfence Intelligence feed of published vulnerabilities and keeps the records for the plugins and themes your connected sites actually run. Each time a site’s state is read, every few hours, the versions it runs are compared with those records. Nothing extra is asked of the site, and there is nothing to switch on.

Vulnerability records are sourced from Wordfence Intelligence and MITRE.

  1. Open the site and its Security tab. The card at the top says whether anything is known against the site, and when it was last checked.

    The Security tab of a site page, open under a row of tabs reading Overview, Health, Security, Manage, AI, Logs and Settings. The Security card says, beside a green dot, nothing known against this site, checked 1 hour ago, 3 of 6 protections on. Underneath, a line says every plugin and theme the site reports was compared with the published vulnerability records, and that vulnerability records are sourced from Wordfence Intelligence and MITRE.

  2. Open Manage, then Plugins. A plugin whose installed version falls inside a published affected range carries a red Vulnerable marker beside its update state.

    Three rows of a site’s plugin list, cropped to the State, Update and Actions columns. Every row reads Running. The first row’s update column reads Needs attention with an Update button, the second reads up to date, and the third carries a red Vulnerable marker beside Needs attention, with Update, Deactivate and Delete buttons.

    The line under the list says where the records come from.

  3. Read what was found on the site’s Health tab. Each vulnerable plugin or theme gets one sentence, worst first, naming the version installed, the score and the version that fixes it:

    The plugin Berth Gallery 4.9.1 has a known vulnerability (CVSS 9.8); 4.9.5 fixes it. Update it from the site’s own dashboard, or queue it as a job here.

    Two records against the same plugin still make one sentence, naming the version that clears both. The version named is the nearest fix on the line the site is running, so a site on 4.9.1 is told 4.9.5 even when a 5.x release fixes it too.

    When nobody has published a fix yet, the sentence says so and what to do in the meantime:

    The plugin Quay Slider 3.0 has a known vulnerability (CVSS 9.8) and no fix has been published yet. Deactivate it until one is, or replace it.

    Themes are checked the same way.

  4. Update it. Update on the plugin’s row does it on this site. For many sites at once, queue a job, or a safe update that looks at each site before and after.

The same sentences appear wherever ReDock prints a site’s state:

  • Needs attention on the Overview page, and the site’s state on All sites;
  • the site’s Health tab;
  • the alert email;
  • the monthly report, which names them for each site, and its JSON export.

Each of those carries the line about where the records come from, once. A site with more than ten vulnerable plugins and themes lists the ten worst and counts the rest, so an email stays readable.

“We found nothing” and “we could not look” are opposite statements, and ReDock never prints the first when the second is true.

A site whose answer did not carry its full plugin list, or that did not say what it has installed, is marked as needing attention with a sentence of its own:

ReDock Web could not check this site against the vulnerability database: the site’s answer was too big to carry the list of its 412 plugins, so only the counts arrived. That is not the same as finding nothing.

Whatever part of the list did arrive is still compared, and a vulnerable plugin in it is still named beside that sentence. A site with more plugins than one answer can carry stays in this state, because the rest of its list still cannot be read.

A plugin that no published record mentions is simply not mentioned. ReDock never calls it safe.

When you roll a plugin back to a version, the version picker marks every version that has a published record, and the confirm names the vulnerability before anything changes on the site.


Open ReDock Web, or create an account if you do not have one yet.