Vulnerable plugins and themes
Every installed plugin and theme identified by real version, matched against known vulnerabilities and exploit probability — the single largest source of WordPress compromise.
Technology Security
Most WordPress sites are not broken into through WordPress itself. They are broken into through a plugin nobody updated, a backup left in the web root, or an admin account with a password from 2019. We look where the breaches actually happen.
WordPress is the most attacked platform on the internet for a simple reason: it is the most used, and most of its risk lives in third-party plugins and themes that the site owner never wrote and rarely updates. A generic scan sees a web server; it does not know that the contact-form plugin is three versions behind a known-exploited flaw.
We assess the whole platform the way an attacker enumerates it — the core version and whether it is still supported, every plugin and theme and the exact versions they run, the files that should never be reachable, and the accounts that can change everything. Each finding is checked by a person before it reaches you, so the report is what to fix, not a plugin inventory.
Coverage
The classes of issue that actually lead to compromised WordPress sites.
Every installed plugin and theme identified by real version, matched against known vulnerabilities and exploit probability — the single largest source of WordPress compromise.
wp-config backups, database dumps, debug logs and archive files left readable in the web root, each of which can hand over the whole site.
The endpoints that leak valid usernames and feed the credential-stuffing that follows.
Login exposure, missing rate limiting, and administrative interfaces reachable by anyone.
Legacy interfaces that enable brute-force amplification and unintended data access when left enabled.
Unsupported versions that no longer receive security fixes, tracked against real support calendars.
Uploads and content directories that expose files never meant to be browsed.
Approach
Passive fingerprinting first, active testing only within the agreed scope.
Core, plugins, themes and versions identified from the live site without touching data.
Detected versions matched to known flaws and exposure checks run against the agreed scope.
Every candidate confirmed by a person — no plugin-inventory noise reported as findings.
Prioritised fixes plus a hardening baseline your team or ours can apply.
Deliverables
The report is the product. If it cannot be acted on by a developer and understood by a director, we have not finished.
Ranked by exploit probability and impact, each with the exact plugin, theme or setting to change.
Every component, its version, and its known-vulnerability status.
The configuration changes that close the common WordPress attack paths for good.
Confirmation that what you changed actually resolved the finding.
How we work
The same engagement model applies to every piece of work we take on, so you always know what happens next.
A 30-minute call, then a written scope: what is in, what is out, what we need from you and what it costs. Nothing starts before you sign it.
Rules of engagement, testing windows, escalation contacts and a signed authorisation. Out-of-hours windows where production cannot take the load.
Automated coverage first, then manual testing where judgement is required. Critical findings are reported the day we confirm them, not at the end.
One report a developer can act on and an executive can read, with evidence, reproduction steps, business impact and a fix for every finding.
A walkthrough call with your engineers. We answer questions on the fix, not just the finding.
A free retest cycle to confirm the fixes hold, and a clean summary you can hand to a customer, auditor or board.
Questions
The questions clients actually ask during scoping. If yours is not here, ask it directly.
Yes — and that is where most of the risk is. We identify every plugin and theme by its real version and match it against known vulnerabilities, because a fully patched core running a vulnerable plugin is still a vulnerable site.
No. Fingerprinting is passive, and any active checks are rate-limited and run only within the scope you agree in writing. We do not run anything designed to disrupt a live service.
Usually yes. Managed hosts patch the core and the server; they do not audit the plugins you installed, the accounts you created or the files your team left in the web root. Those are the things that get sites breached.
Yes. Every report includes a hardening baseline, and our managed service can apply and maintain it. We also re-test after you remediate, so you know the fix worked.
At least annually, and after any major change — a new plugin, a migration, or a theme swap. Plugin vulnerabilities are disclosed constantly, so continuous monitoring of your installed components is the better answer for a site that matters to the business.
Next step
A 30-minute call, then a scope document with what is in, what is out and what it costs. No obligation, and no charge for the conversation.