MainWP Vulnerability Checker extension uses either the free MainWP NVD API or the paid WPScan Vulnerability Database API to bring you information about vulnerable plugins and themes on your Child Sites so you can act accordingly.
Get information on vulnerable plugins and themes and what the issues are directly from your MainWP Dashboard.
- The Vulnerability Extension gathers the latest information in real-time.
- Get notified about vulnerabilities on your websites.
- Update vulnerable plugins.
- Delete vulnerable plugins.
MainWP NVD API
This is a free API provided by the National Institute of Standards and Technology (NIST) in the U.S. Department of Commerce.
The NIST NVD is the U.S. government repository of standards-based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables the automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, misconfigurations, product names, and impact metrics.
NVD Nist API Database can not be searched by plugin/theme slug (which would be unique for each item) and assure better accuracy; it can be searched by keyword only. This means that the API can return some false-positive results.
The NVD Nist API lacks the “Fixed in version” info for some vulnerabilities, leading to an Extension showing vulnerabilities that have already been resolved. To remove false positives and get accurate results, you can use the “Ignore” function to detect vulnerabilities if you recognize them as false-positive.
The WPScan Vulnerability Database is an online browsable version of WPScan’s data files used to detect known WordPress core, plugin, and theme vulnerabilities. WPScan is an enterprise-strength vulnerability scanner operated by Automattic, the maker of WordPress.com.
All vulnerabilities are manually entered into their database by dedicated WordPress security professionals. WPScan works with security researchers, vendors, and WordPress to triage vulnerabilities.
Their vulnerability database is updated constantly as new information becomes available. We allow our users to utilize the WPScan API on MainWP, and access is available for purchase directly on WPScan.com.
WPScan API can be used free of charge, with an API request limit of 50 per day. To increase this limit, WPScan offers paid API usage, increasing the daily request limit to 250. Please note that reaching the daily API request limit is very easy. If you have ten sites with three plugins and a theme, you will hit the free 50 right away.
- 10 WordPress Checks (1*10)
- 30 Plugins checks (3*10)
- 10 Theme checker (1*10)
Once you reach the daily API Requests limit, the extension stops reporting and potentially leads to misleading results.
If you need to make more than 250 API requests per day, you need to contact the WPScan team for pricing.
Extension Data Privacy Info
You can use this Extension on unlimited MainWP Dashboards that you own.