SiteFort documentation
Vulnerability Scanner
See which plugins, themes, and WordPress core have known security vulnerabilities. Covers the CVE table, how to read severity, and what to do about each finding.
Vulnerability Scanner
The Vulnerability Scanner monitors installed WordPress plugins, themes, and core for known CVEs and patch guidance. It is not a general update reminder; it highlights components with known security exposure. Click Check Now to run an immediate check. If a License Required banner appears, activate the license before relying on vulnerability results.| Area | What you see | How to use it |
|---|---|---|
| Summary cards | Critical / High, Total Vulnerabilities, and Affected Assets. | Use Critical / High to prioritize urgent work. Use Affected Assets to estimate change impact. |
| Asset groups | Component name, type, installed version, and issue count. | Review by component so you can update, replace, or remove one asset at a time. |
| Vulnerability table | Vulnerability, Affected, CVE, and Severity columns. | Expand a row for the description or CVE link when available. |
| Actions | Delete Theme, Update Plugin, Update Theme, or Take Action. | Use the action that matches the affected asset. Delete abandoned or unused themes and plugins instead of carrying the risk. |
How to Respond to CVEs
- Patch first when a supported update exists. Update the affected plugin, theme, or WordPress core. Recheck afterward.
- Remove what you do not use. Inactive themes and plugins still represent code on disk. Delete unused vulnerable components.
- Replace abandoned software. If no update exists and the component is business-critical, plan a replacement and use Firewall and Hardening controls to reduce exposure until migration.
- Document exceptions. If a vulnerability cannot be fixed immediately, record severity, affected version, business owner, compensating control, and target fix date.
- Do not ignore Critical or High findings silently. The Dashboard will continue to surface active vulnerabilities because they affect site risk.