Know which sites are vulnerable, and fix the easy things.
Each WordPress site has a Security tab that lists known vulnerabilities in WordPress core and the plugins it runs, and one Settings list of insecure settings you can fix.
For WordPress sites. Needs the KontrolWP Connect plugin.
Vulnerabilities, rated and sorted.
KontrolWP matches each site's WordPress and plugin versions against the Wordfence Intelligence vulnerability feed.
- Vulnerabilities in core and plugins, rated by CVSS score from Low to Critical
- The CVE, a link to the report and the version that fixes it
- A checkmark for settings that are fine, Fix now when KontrolWP can fix one, and a warning when the change is manual
- Fix all in the header
Vulnerabilities2 need attention
Example Forms 4.2.1
7.5 (High)
Sample Gallery 2.0.4
6.4 (Medium)
SettingsFix all
The site uses HTTPS
Directory listing is prevented
The WordPress version is visible
XML-RPC is enabled
A user is named admin
The details
How it works, point by point.
Vulnerabilities
- Ratings show the CVSS score and band, for example 6.4 (Medium). Low is yellow, Medium orange, High red and Critical a darker red
- The fix status sits under the rating, so you can see at a glance whether an update exists
- Core and every plugin that a connected site has installed are matched, using the versions from the last sync
- Themes are not checked, because sites report only their active theme's name
The data source
- Data comes from the Wordfence Intelligence feed. You add a free API key from a Wordfence account once, in Settings. It is stored encrypted
- KontrolWP downloads the feed once a day from its scheduled job, and once when you save the key. There is no refresh button, because Wordfence allows only one download every 30 minutes
- If a download fails, KontrolWP keeps the data it already has and shows a quiet note
The Settings list
- One list shows what is fine, what you can fix now and what needs a manual change. Open items come first
- Findings include HTTPS, a PHP version that no longer gets fixes, a pending core update, inactive plugins, and a user named admin (a manual fix)
- Fix now applies a hardening fix and turns into a checkmark. Fix all applies every open one
- Fixes: prevent directory listing, hide the WordPress version, remove RSD and Windows Live Writer links, hide database and PHP errors, delete readme.html, and turn off the code editor and XML-RPC
- A checkmark is read from the live site, so it also shows protection that something else provides
Per site
- Turn security checks off for one site in its settings. Scheduled work skips it and the tab is hidden, and what was stored is kept
Good to know
- The Settings findings need KontrolWP Connect 0.12.0, and the hardening fixes need 0.13.0. Sites on an older plugin show only the checks the dashboard can make itself, with a note.
- This is a check against a public vulnerability feed plus a few settings. It does not scan files for malware.
Related
More from KontrolWP.
Accessibility
A score out of 100 for each site, issues ranked by impact and a daily scan. On WordPress, six one-click fixes.
Updates
Every core, plugin and theme update across all sites in one list, queued with one click or run on a schedule.
Plugins
Install, activate, deactivate and delete plugins, and set auto-updates, on one site or many at once.
Take control of every WordPress site you run.
Deploy KontrolWP to your Cloudflare account and connect your first site.