WordPress Security Monitoring

Stop tracking plugin CVEs by hand.

Most WordPress compromises don't start with a zero-day — they start with a known-vulnerable plugin or theme that nobody got around to updating. With dozens of plugins across even a single site, and dozens of sites for an agency, checking every component against every new disclosure by hand doesn't scale. Continuous monitoring does it automatically, on a schedule.

Why WordPress sites get compromised

WordPress powers a large share of the web, which makes it the most consistently attacked content management system in existence. Attackers don't need to find a new flaw — they run automated scanners against known-vulnerable plugin and theme versions the moment a CVE is disclosed, checking thousands of sites within days of publication. If a plugin you run gets a disclosure and you don't hear about it, you're exposed for as long as it takes you to notice.

The scale of the problem is what makes it hard to manage manually. A single site can run a dozen plugins and a theme, each with its own update cadence and its own vulnerability history. An agency managing client sites multiplies that across every site in its portfolio. Checking each component against a vulnerability feed by hand, for every site, every week, is not a realistic ongoing process — it gets skipped, and the gap is exactly where a compromise happens.

Continuous WordPress monitoring closes that gap the same way it does for any other security surface: check on a schedule, compare against current vulnerability data, and alert the moment something installed becomes known-vulnerable — rather than finding out when the site is already compromised.

What NetTests WordPress monitoring checks

NetTests enumerates your WordPress core version, installed plugins, and active theme, then checks each one against our vulnerability database, built from published WordPress vulnerability disclosures. A component that was safe last week can become vulnerable the moment a new disclosure names its version — monitoring catches that the next time it checks, without you having to track disclosures yourself.

The scan also checks for username enumeration exposure — a common reconnaissance step attackers use ahead of a credential-stuffing or brute-force attempt — and can be paired with a general exposure scan to catch misconfigured uploads directories, exposed wp-config.php backups, and other accidental disclosures common on WordPress installs specifically.

If your portfolio isn't WordPress-only, a dedicated Drupal scanner checks core and contributed-module versions the same way the WordPress check does. Everything surfaces in one dashboard regardless of which CMS a given site runs.

Findings are ranked by severity, and a newly-vulnerable component is flagged distinctly from findings you've already seen, so a fresh disclosure never gets lost in a long report. Alerts reach your team through email, Slack, Microsoft Teams, or SMS.

Key features

Core version & CVE detection

Detects your installed WordPress core version and checks it against known vulnerabilities.

Plugin & theme vulnerability checks

Every installed plugin and theme checked against our vulnerability database on every run.

Username enumeration check

Flags exposed usernames — a common reconnaissance step ahead of credential-stuffing attempts.

Drupal coverage too

A dedicated Drupal scanner extends the same monitoring to Drupal sites, for portfolios that aren't WordPress-only.

New-vulnerability alerts

A component that becomes newly-vulnerable is flagged distinctly from findings you've already triaged.

Agency-friendly dashboard

Monitor every client site from a single dashboard instead of checking each one by hand.

Severity-ranked findings

Every finding ranked by severity, so the most urgent issue is always the first thing you see.

Multi-channel alerts

Reach your team through email, Slack, Microsoft Teams, or SMS the moment a new issue is found.

What you'll see

A live look at installed components checked against known vulnerabilities, and the alert that fires when one turns up vulnerable.

WordPress Scan — acme.com COMPONENT VERSION STATUS WordPress core 6.4.3 OK Contact Form Plugin 5.1.0 Vulnerable SEO Plugin 20.4 OK Active theme 3.2.1 OK Alert sent — Contact Form Plugin 5.1.0 is known-vulnerable
Example scan — illustrative data

Not ready to commit?

Try the free WordPress Scanner first. Enumerate your core version, plugins, themes, and usernames against our vulnerability database, then set up continuous monitoring when you're ready.

Try the free tool →

Free CMS diagnostic tools

Run a one-off scan now, or set up continuous monitoring.

Frequently asked questions

How do you know which WordPress plugins and themes are vulnerable?

Installed components are checked against our vulnerability database, built from published WordPress vulnerability disclosures. Each installed plugin, theme, and the core version itself are matched against that data on every scheduled check.

Does this replace keeping WordPress updated?

No — monitoring doesn't install updates for you, it tells you when one is needed. The value is in the gap between a disclosure and when you'd otherwise notice it: instead of finding out during an incident, you get an alert as soon as an installed component becomes known-vulnerable.

Can I monitor multiple WordPress sites, like a client roster?

Yes. Every site you monitor appears in one dashboard, which is built for exactly this — agencies checking a portfolio of client sites without auditing each one by hand.

Do you scan Drupal too?

Yes. A dedicated Drupal scanner checks core and contributed-module versions the same way the WordPress check does — useful if your portfolio isn't WordPress-only.

How is this different from a WordPress security plugin?

A security plugin runs from inside the site itself, which means it can be disabled or tampered with if the site is already compromised. NetTests checks from outside, independent of the site's own state — so it still works, and still alerts you, even in a scenario where an in-site plugin would already be blind.

Will scanning my own WordPress site trigger my host's abuse alerts?

Scans are scoped to sites you own or administer and run at a measured pace intended for legitimate ongoing monitoring, not a burst crawl. If your host or a security plugin like Wordfence alerts on any automated traffic, let your provider know you run scheduled security scans against your own domain.

Stop checking plugin versions by hand

NetTests checks your WordPress core, plugins, and themes against current vulnerability data on every run — so a known-vulnerable component gets caught before it's exploited.

Start monitoring free →
No credit card required  ·  Free plan available