Vulnerability scanner with CVE + CISA KEV intel
Every finding is enriched with a real CVE ID, a CVSS score, and a red pill if the vulnerability sits on the CISA Known Exploited Vulnerabilities catalog. Data flows through the Royal Plugins vulnerability intelligence proxy, refreshed daily, with zero API keys for you to manage.
What gets checked
The scanner combines three data feeds (the Wordfence Intelligence Production tier CVE database, the CISA Known Exploited Vulnerabilities catalog, and the WordPress.org plugin-status transient) with the classic hygiene checks a well-hardened site should pass. A single scan gives you the CVE-tracked findings and the "silly stuff attackers look for first" checklist in the same report.
CVE-enriched findings
Every match carries a real CVE ID, CVSS score, affected version range, and remediation guidance from Wordfence Intelligence Production tier.
CISA KEV cross-reference
Vulnerabilities on the CISA Known Exploited Vulnerabilities catalog carry a red pill so you patch actively-exploited items ahead of theoretical ones.
Plugin-closed watcher
GuardPress watches every installed plugin against WordPress.org. When one gets closed, you get a high-severity alert with the plugin name, installed version, and closure reason.
Pending updates
Core, plugin, and theme updates pending too long get elevated out of the regular WordPress update notice.
Admin hardening
Flag weak default usernames like "admin", WP_DEBUG left enabled, DISALLOW_FILE_EDIT not set, HTTPS missing, and user enumeration still open.
Legacy artifacts
Detect insecure legacy artifacts still on disk: TimThumb, exposed debug.log, config backups (wp-config.php.bak), and similar.
Findings are prioritized
When a CVE is present, severity comes from the CVSS score directly. Non-CVE findings (abandoned plugins, hardening misconfigurations, legacy artifacts) get a severity heuristic based on how directly they map to a known attack path.
CVSS ≥ 9.0 or on CISA KEV: address today
Actively-exploited CVEs (any KEV match), critical-severity Wordfence records, HTTPS not configured, or WP_DEBUG left on in production.
CVSS 7.0–8.9: address this week
High-severity CVEs, major core update pending, abandoned plugin detected, DISALLOW_FILE_EDIT not set, or user enumeration still open.
CVSS 4.0–6.9: schedule
Medium-severity CVEs, minor plugin or theme updates pending, weak default admin username. Fold into your normal maintenance window.
CVSS < 4.0: monitor
Low-severity CVEs, inactive themes with pending updates, residual legacy artifacts, and similar housekeeping items.
How the scanner works
Every scan cycle asks three questions, in order:
- Do any installed plugins, themes, or the WordPress core version match a known CVE? If yes, the finding carries the CVE ID, CVSS score, and severity, sourced from Wordfence Intelligence Production tier.
- Is any of those CVEs actively being exploited in the wild? Cross-reference every CVE ID against the CISA Known Exploited Vulnerabilities catalog. Matches get a red pill and jump the priority queue.
- Are there any obvious hygiene gaps attackers look for first? Pending updates left too long, weak admin username, WP_DEBUG in production, HTTPS not configured, TimThumb still on disk, and similar.
This isn't a runtime defense; that's what the firewall is for. It's discovery and prioritization, running on a daily schedule. When a critical CVE lands on a plugin you have installed, GuardPress surfaces it on the next scan and can email you immediately.
Data delivery: the CVE feed flows through the Royal Plugins vulnerability intelligence proxy at my.royalplugins.com. Your Pro license key authenticates the request; Royal Plugins calls Wordfence with our key server-side. No Wordfence account, no separate subscription, no API key management on your side.
What's included
- CVE-enriched findings. Every match carries a real CVE ID, CVSS score, and severity rating from Wordfence Intelligence Production tier.
- CISA KEV cross-reference. Actively-exploited CVEs get flagged with a red pill and prioritized in alerts.
- Plugin-closed watcher. GuardPress alerts you when WordPress.org closes a plugin you've installed, with the plugin name, installed version, and closure reason.
- Managed data delivery. Data flows through the Royal Plugins vulnerability intelligence proxy. No Wordfence API key, no separate subscription; your Pro license authenticates.
- CVSS-based severity. Findings prioritized by real CVSS scores when a CVE is present; heuristic severity for non-CVE findings.
- Daily refreshed data. Wordfence Intelligence and CISA KEV feeds refresh once per day, cached locally, so scans stay fast and predictable.
- Pending update alerts. Core, plugin, and theme updates pending too long get elevated out of the regular WordPress update notice.
- Hardening misconfiguration checks. Weak admin username, WP_DEBUG enabled, DISALLOW_FILE_EDIT unset, HTTPS missing, user enumeration open.
- Legacy artifact detection. TimThumb, debug.log left in document root, config backups (wp-config.php.bak), other well-known footguns.
- Email notifications. Findings summarized to email on your preferred schedule; KEV matches carry a
[CRITICAL - CISA KEV]prefix. - Dashboard widget. Quick status tile on the WordPress dashboard: green, yellow, or red at a glance.
- Automated + manual scans. Runs daily by default; hit "Scan Now" from the admin page whenever you want a fresh check.
Common questions
GuardPress Pro sources CVE data from Wordfence Intelligence Production tier, delivered through the Royal Plugins vulnerability intelligence proxy at my.royalplugins.com. Wordfence Intelligence Production tier includes CVE IDs, CVSS scores, affected version ranges, and remediation details on tens of thousands of WordPress plugin, theme, and core vulnerabilities. The proxy handles the API key management so no key is embedded in the plugin or exposed on your site.
CISA KEV is the Known Exploited Vulnerabilities catalog maintained by the US Cybersecurity and Infrastructure Security Agency. A CVE only makes it onto the KEV catalog when there is credible evidence of active exploitation in the wild. For a WordPress site owner, a KEV match means the vulnerability isn't theoretical, since someone is actively running scans and exploits against it right now. GuardPress cross-references every CVE against KEV and surfaces matches with a red pill so you patch active-exploit items first.
No. Data flows through the Royal Plugins vulnerability intelligence proxy at my.royalplugins.com. Your Pro license key authenticates the request, and Royal Plugins calls Wordfence with our key server-side. No Wordfence account or subscription is required from you.
Wordfence Intelligence data refreshes once per day. CISA KEV catalog refreshes once per day. Both fetches piggyback the existing daily GuardPress scan cron, so there are no new outbound HTTP requests per plugin, per scan, or per pageload. Local cache is filtered to only match installed plugin slugs, keeping storage typically under a megabyte.
GuardPress Pro's plugin-closed watcher fires a high-severity alert with the plugin name, installed version, and closure reason. WordPress.org typically closes plugins for undisclosed security reasons, so the alert is your signal to review whether to deactivate. The watcher piggybacks WordPress core's own update-check transient, so there is no new outbound HTTP on the hot path.
The classic hygiene checks (pending updates, hardening misconfigurations, legacy artifacts) are available in GuardPress Lite. The CVE data enrichment, CISA KEV cross-reference, and plugin-closed watcher are Pro-only features.
See every CVE affecting your site
Every GuardPress Pro license unlocks the CVE + CISA KEV scanner plus every other Pro feature. One license, one plugin.