# Vulnerability scanner with CVE + CISA KEV intel

> WordPress vulnerability scanner enriched with CVE IDs, CVSS scores, and the CISA Known Exploited Vulnerabilities catalog. No API keys to manage.

- Canonical: <https://royalplugins.com/guardpress/features/vulnerability-scanner/>
- Last updated: 2026-09-10
- HTML version: <https://royalplugins.com/guardpress/features/vulnerability-scanner/>

---

- [Overview](https://royalplugins.com/guardpress/)
- [Features](https://royalplugins.com/guardpress/features/)

  [All Features](https://royalplugins.com/guardpress/features/)
  [Firewall](https://royalplugins.com/guardpress/features/firewall/)
  [Malware Scanner](https://royalplugins.com/guardpress/features/malware-scanner/)
  [Vulnerability Scanner](https://royalplugins.com/guardpress/features/vulnerability-scanner/)
  [Two-Factor Auth](https://royalplugins.com/guardpress/features/two-factor-auth/)
  [Activity Logs](https://royalplugins.com/guardpress/features/activity-logs/)
- [Compare](https://royalplugins.com/guardpress/free-vs-pro/)

  [Free vs Pro](https://royalplugins.com/guardpress/free-vs-pro/)
  [vs Wordfence](https://royalplugins.com/guardpress/vs-wordfence/)
  [vs Sucuri](https://royalplugins.com/guardpress/vs-sucuri/)
  [vs Kadence Security](https://royalplugins.com/guardpress/vs-kadence-security/)
- [Pricing](https://royalplugins.com/guardpress/pricing/)
- [Docs](https://royalplugins.com/support/guardpress/)

Overview
All Features
— Firewall
— Malware Scanner
— Vulnerability Scanner
— Two-Factor Auth
— Activity Logs
Compare
— Free vs Pro
— vs Wordfence
— vs Sucuri
— vs Kadence Security
Pricing
Documentation

Pro Feature

Every finding is enriched with a real CVE ID, a CVSS score, and a red pill if the vulnerability sits on the CISA Known Exploited Vulnerabilities catalog. Data flows through the Royal Plugins vulnerability intelligence proxy, refreshed daily, with zero API keys for you to manage.

By Jameson · Founder & Lead Developer

[Get GuardPress Pro](https://royalplugins.com/guardpress/pricing/)

## What gets checked

The scanner combines three data feeds (the Wordfence Intelligence Production tier CVE database, the CISA Known Exploited Vulnerabilities catalog, and the WordPress.org plugin-status transient) with the classic hygiene checks a well-hardened site should pass. A single scan gives you the CVE-tracked findings and the "silly stuff attackers look for first" checklist in the same report.

### CVE-enriched findings

Every match carries a real CVE ID, CVSS score, affected version range, and remediation guidance from Wordfence Intelligence Production tier.

### CISA KEV cross-reference

Vulnerabilities on the CISA Known Exploited Vulnerabilities catalog carry a red pill so you patch actively-exploited items ahead of theoretical ones.

### Plugin-closed watcher

GuardPress watches every installed plugin against WordPress.org. When one gets closed, you get a high-severity alert with the plugin name, installed version, and closure reason.

### Pending updates

Core, plugin, and theme updates pending too long get elevated out of the regular WordPress update notice.

### Admin hardening

Flag weak default usernames like "admin", WP\_DEBUG left enabled, DISALLOW\_FILE\_EDIT not set, HTTPS missing, and user enumeration still open.

### Legacy artifacts

Detect insecure legacy artifacts still on disk: TimThumb, exposed debug.log, config backups (wp-config.php.bak), and similar.

## Findings are prioritized

When a CVE is present, severity comes from the CVSS score directly. Non-CVE findings (abandoned plugins, hardening misconfigurations, legacy artifacts) get a severity heuristic based on how directly they map to a known attack path.

Critical

#### CVSS ≥ 9.0 or on CISA KEV: address today

Actively-exploited CVEs (any KEV match), critical-severity Wordfence records, HTTPS not configured, or WP\_DEBUG left on in production.

High

#### CVSS 7.0–8.9: address this week

High-severity CVEs, major core update pending, abandoned plugin detected, DISALLOW\_FILE\_EDIT not set, or user enumeration still open.

Medium

#### CVSS 4.0–6.9: schedule

Medium-severity CVEs, minor plugin or theme updates pending, weak default admin username. Fold into your normal maintenance window.

Low

#### CVSS < 4.0: monitor

Low-severity CVEs, inactive themes with pending updates, residual legacy artifacts, and similar housekeeping items.

## How the scanner works

Every scan cycle asks three questions, in order:

1. **Do any installed plugins, themes, or the WordPress core version match a known CVE?** If yes, the finding carries the CVE ID, CVSS score, and severity, sourced from Wordfence Intelligence Production tier.
2. **Is any of those CVEs actively being exploited in the wild?** Cross-reference every CVE ID against the CISA Known Exploited Vulnerabilities catalog. Matches get a red pill and jump the priority queue.
3. **Are there any obvious hygiene gaps attackers look for first?** Pending updates left too long, weak admin username, WP\_DEBUG in production, HTTPS not configured, TimThumb still on disk, and similar.

This isn't a runtime defense; that's what the [firewall](https://royalplugins.com/guardpress/features/firewall/) is for. It's discovery and prioritization, running on a daily schedule. When a critical CVE lands on a plugin you have installed, GuardPress surfaces it on the next scan and can email you immediately.

**Data delivery:** the CVE feed flows through the Royal Plugins vulnerability intelligence proxy at `my.royalplugins.com`. Your Pro license key authenticates the request; Royal Plugins calls Wordfence with our key server-side. No Wordfence account, no separate subscription, no API key management on your side.

## What's included

- **CVE-enriched findings.** Every match carries a real CVE ID, CVSS score, and severity rating from Wordfence Intelligence Production tier.
- **CISA KEV cross-reference.** Actively-exploited CVEs get flagged with a red pill and prioritized in alerts.
- **Plugin-closed watcher.** GuardPress alerts you when WordPress.org closes a plugin you've installed, with the plugin name, installed version, and closure reason.
- **Managed data delivery.** Data flows through the Royal Plugins vulnerability intelligence proxy. No Wordfence API key, no separate subscription; your Pro license authenticates.
- **CVSS-based severity.** Findings prioritized by real CVSS scores when a CVE is present; heuristic severity for non-CVE findings.
- **Daily refreshed data.** Wordfence Intelligence and CISA KEV feeds refresh once per day, cached locally, so scans stay fast and predictable.
- **Pending update alerts.** Core, plugin, and theme updates pending too long get elevated out of the regular WordPress update notice.
- **Hardening misconfiguration checks.** Weak admin username, WP\_DEBUG enabled, DISALLOW\_FILE\_EDIT unset, HTTPS missing, user enumeration open.
- **Legacy artifact detection.** TimThumb, debug.log left in document root, config backups (wp-config.php.bak), other well-known footguns.
- **Email notifications.** Findings summarized to email on your preferred schedule; KEV matches carry a `[CRITICAL - CISA KEV]` prefix.
- **Dashboard widget.** Quick status tile on the WordPress dashboard: green, yellow, or red at a glance.
- **Automated + manual scans.** Runs daily by default; hit "Scan Now" from the admin page whenever you want a fresh check.

FAQ

## Common questions

GuardPress Pro sources CVE data from Wordfence Intelligence Production tier, delivered through the Royal Plugins vulnerability intelligence proxy at `my.royalplugins.com`. Wordfence Intelligence Production tier includes CVE IDs, CVSS scores, affected version ranges, and remediation details on tens of thousands of WordPress plugin, theme, and core vulnerabilities. The proxy handles the API key management so no key is embedded in the plugin or exposed on your site.

CISA KEV is the Known Exploited Vulnerabilities catalog maintained by the US Cybersecurity and Infrastructure Security Agency. A CVE only makes it onto the KEV catalog when there is credible evidence of active exploitation in the wild. For a WordPress site owner, a KEV match means the vulnerability isn't theoretical, since someone is actively running scans and exploits against it right now. GuardPress cross-references every CVE against KEV and surfaces matches with a red pill so you patch active-exploit items first.

No. Data flows through the Royal Plugins vulnerability intelligence proxy at `my.royalplugins.com`. Your Pro license key authenticates the request, and Royal Plugins calls Wordfence with our key server-side. No Wordfence account or subscription is required from you.

Wordfence Intelligence data refreshes once per day. CISA KEV catalog refreshes once per day. Both fetches piggyback the existing daily GuardPress scan cron, so there are no new outbound HTTP requests per plugin, per scan, or per pageload. Local cache is filtered to only match installed plugin slugs, keeping storage typically under a megabyte.

GuardPress Pro's plugin-closed watcher fires a high-severity alert with the plugin name, installed version, and closure reason. WordPress.org typically closes plugins for undisclosed security reasons, so the alert is your signal to review whether to deactivate. The watcher piggybacks WordPress core's own update-check transient, so there is no new outbound HTTP on the hot path.

The classic hygiene checks (pending updates, hardening misconfigurations, legacy artifacts) are available in [GuardPress Lite](https://wordpress.org/plugins/guardpress-lite/). The CVE data enrichment, CISA KEV cross-reference, and plugin-closed watcher are Pro-only features.

## Related security features

[### Web Application Firewall

Block attacks before they happen with intelligent request filtering.](https://royalplugins.com/guardpress/features/firewall/)
[### Malware Scanner

Deep scanning finds malware, backdoors, and suspicious code.](https://royalplugins.com/guardpress/features/malware-scanner/)
[### Two-Factor Authentication

Add an extra layer of login security with TOTP-based 2FA.](https://royalplugins.com/guardpress/features/two-factor-auth/)
[### Activity Logging

Complete audit trail of all user actions and security events.](https://royalplugins.com/guardpress/features/activity-logs/)

## See every CVE affecting your site

Every GuardPress Pro license unlocks the CVE + CISA KEV scanner plus every other Pro feature. One license, one plugin.

[View Pricing](https://royalplugins.com/guardpress/pricing/)
[Compare Free vs Pro](https://royalplugins.com/guardpress/free-vs-pro/)
