Category: Vulnerabilities
Staying ahead of vulnerabilities
There are many high quality plugins available on the WordPress Plugin Directory, offering a lot of flexibility to customize WordPress to your needs without having to write any code yourself. However, installing third-party plugins and themes also means that you’re trusting code from another developer to run on your website. And since even the best developer could accidentally introduce a security vulnerability; it’s impossible to rule out the possibility of a vulnerability being discovered in a plugin/theme that you use
Run a Manual Vulnerability Check
Really Simple SSL, when Vulnerability Detection is enabled, runs a regular check every few hours to see if new vulnerabilities are added to our database, which may be relevant to your website. It automatically runs a check when we see a change in your WordPress installation. For example, if you update a plugin to a new version Really Simple SSL runs a check. This is also true when installing a new plugin. In some cases, Really Simple SSL doesn’t know
Number of reported WordPress Plugin & Theme vulnerabilities doubled in the first 6 months of 2023
We recently introduced vulnerability detection in Really Simple Security and have been working on a database of vulnerabilities sourced from the open WordPress Vulnerability Database API project (https://www.wpvulnerability.com) since the beginning of 2023. We have been monitoring WordPress plugin and Theme vulnerabilities for years and have seen an increase in reported vulnerabilities yearly. Having access to detailed information in our own database enabled us to look closer into the details and numbers. We were surprised to find the number of
Vulnerability Detection for WordPress
WP Vulnerabilities – An open-source initiative WP Vulnerabilities is an open-source, free API by Javier Casares with contributions from other open-source, freely available databases and many manual hours from moderators and security officers from other plugins, including our own security officer. Really Simple Security mirrors the free database with its own instance to secure stability and deliverability, but of course provides the origin database with an API to enrich, or improve its current data. An open-source platform, with an enormous
About Vulnerabilities
A vulnerability is a known security flaw in a plugin, theme, or WordPress core. When one is discovered, it gets added to public databases that attackers use to automatically find sites to target. Really Simple Security scans your installed plugins and themes against these databases and alerts you when something you are running has a known vulnerability. The alert tells you exactly which item is affected and what to do — usually updating to the latest patched version or temporarily