VulnCue Wordpress Plugin - Rating, Reviews, Demo & Download
Plugin Description
VulnCue scans your WordPress from the inside, something an external
scanner can’t do with the same precision: an exact inventory of installed
plugins and themes, outdated core, an unsupported PHP version, uncustomized
wp-config.php security keys, an active file editor, an exposed “admin” user,
active XML-RPC, sensitive files left in the public folder (backups, .env,
.git), and more.
All of these checks are 100% free, with no need to create an account or
give your email. If you want an email alert when a new vulnerability (CVE)
affects one of your installed plugins, you can connect a free account from
VulnCue’s client area (https://vulncue.com/) — optional, never required to
use the plugin.
External services
By default, this plugin sends no data to external servers. All checks
use WordPress’s own data (update transients, wp-config.php constants, the
public folder’s file listing).
Six exceptions, all of which can be turned off or only trigger on your
explicit action (the first three from the plugin’s screen; the fourth and
fifth only activate if you connect an account yourself; the sixth only if
you choose to send it):
- Checks that make the site send a request to itself: XML-RPC
(xmlrpc.php), user enumeration via the REST API (/wp-json/wp/v2/users),
SSL/TLS certificate expiry and trust (two HTTPS connections to the site’s
own domain), directory listing onwp-content/uploads/, and whether the
homepage reveals the WordPress version in the<meta name="generator">
tag. None of these requests go out to VulnCue or any third party — it’s
your own WordPress talking to itself to check how it responds. The whole
group can be disabled with the “Include checks that make this site send a
request to itself” checkbox. - Known vulnerability check (enabled by default, no account or email
needed): the plugin sends vulncue.com the list of installed plugins and
themes (only the technical name and version, never personal data or
anything about your site) to check them against VulnCue’s public CVE
catalog. Can be disabled with the “Check installed plugins/themes against
VulnCue’s public vulnerability catalog” checkbox. - Core integrity verification (enabled by default, no account or email
needed): the plugin queriesapi.wordpress.org(WordPress’s own official
server, not VulnCue’s) to get the public checksums for your WordPress
version and check that the core files haven’t been modified. Only the
WordPress version and language are sent, never anything about your site.
Can be disabled with the “Check WordPress core integrity” checkbox. - Account connection (optional, the only one that sends your email): if
you choose to enter your email to connect a free account, the plugin sends
your site’s URL, your email, and your WordPress version to vulncue.com, to
create your account and be able to email you about new CVEs. Privacy
policy: https://vulncue.com/politica-privacidad.html - Scheduled auto-scan + inventory report (only if you connected an
account): every hour, WP-Cron checks (sending only your connection key)
whether a new automatic scan is due — every 7 days on the free plan, every
day on a paid plan; the hourly check only shortens the wait for the first
scan after connecting, it doesn’t increase the actual frequency. When it’s
due, besides scanning your site it sends the
list of installed plugins and themes (technical name and version, never
personal data) so it can email you if any of them has a new vulnerability
— each alert is sent only once per vulnerability. Also, once your account
is connected, you’ll get a weekly email with your current risk level and
findings (this summary is sent by your own WordPress, not by vulncue.com).
If you haven’t connected an account, none of this happens and scanning
stays fully manual (“Scan again”). - Deactivation survey (optional): when you deactivate the plugin you can
say why. Choosing “Skip” sends nothing. Writing something and confirming
sends vulncue.com the site’s URL, the reason, and the WordPress/PHP/plugin
versions — never your email or any other personal data.
Screenshots
No screenshots provided

