Every vulnerability, tracked. Your alert, on day zero.

MalCare reviews vulnerability disclosures from 10+ sources every day and reconciles them into one clean, current database — 39,000+ flaws tracked over 5+ years, no gaps, no contradictions. Your site's stack is checked against it daily, and you're alerted the day a flaw that affects you is disclosed — with the fix one click away.

39,000+vulns tracked
10+sources · 1 verdict
Dailystack checks
10+ SOURCES · ONE DATABASEFIG. 0 · REVIEWED DAILYnatl vuln databasesresearcher disclosuresvendor changelogsexploit trackersbug bounties+ 5 moreTHE DESK10+ sources · reviewed dailyduplicates & noise · discardedform-builder-prov3.2 · CRITICALyour site runs itpatch ready · 1 clickyour alert · day zero
your stack · daily checklive

Trusted by 400,000+ websites across 120 countries

Intel
Toshiba
eBay
Manthan
SiteCare
NMU
01Why vulnerabilities

A disclosure isn't news. It's a countdown.

When a flaw in a plugin goes public, attackers weaponize it within hours and spray it at every site running that version — they don't find you, scripts find everyone. 91% of hacks start in plugins and themes. And 46% of flaws have no patch on the day they're disclosed.

FIG. 1The countdown · from disclosure to your door
DISCLOSUREhour zeroexploit publishedwithin hoursmass scanning beginsday 1your site probedday 2 onwardYOU · alerted at hour zeroalarm + verdict + one-click fixmost owners find out here —from the hack itselfaverage exposure: 180 daysthe clock starts whether you know or not. knowing is the head start.

Read: an alert doesn't protect you by itself — it starts the clock in your favor. What happens next is one click away (§05).

FIG. 1The countdown
00:00

Disclosure

The flaw goes public — and you get the alarm.

YOU KNOW
+hrs

Exploit published

Weaponized and shared within hours.

THE RACE
day 1+

Mass scanning

Scripts probe every site running the version — including yours.

AT YOUR DOOR
day 180

The other way

Most owners find out from the hack itself.

TOO LATE
02The verdict

One database, built from 10+ sources — reviewed daily.

The same flaw shows up in different databases with different severities — or not at all. Our security team reviews disclosures from 10+ sources every day, deduplicates them, resolves the conflicts, and re-scores each flaw for how it's actually exploitable. The result is the most robust, up-to-date vulnerability database in WordPress: no gaps, no contradictions, no stale entries.

FIG. 2The disagreement, resolved
SOURCE A · NATL DATABASEHIGH · 7.5SOURCE B · EXPLOIT TRACKERCRITICAL · 9.8SOURCE C · VENDORnot listedsame flaw · CVE-2026-1184 · three answersMALCARE VERDICT · CVE-2026-1184CRITICAL exploitable without login exploit circulating in the wild your site runs the affected versionfix: safe update — or shield nowreasons attached · not just a numbera score is an opinion. a verdict is a decision.

Read: severity gets re-evaluated for reality — does it need a login, is an exploit loose, do you even run the version. The verdict carries its reasons.

FIG. 2The disagreement, resolved
A

Source A

HIGH · 7.5

ONE OPINION
B

Source B

CRITICAL · 9.8

ANOTHER
C

Source C

Not listed at all.

SILENCE

MalCare verdict

CRITICAL — exploitable without login, exploit circulating, your site runs it. Fix attached.

A DECISION
Expand: what re-scoring weighs

A published severity score (CVSS or otherwise) is a starting point, not an answer. Our team re-evaluates each disclosure for what decides real-world risk: can it be exploited without logging in; is a working exploit circulating; how large is the install base; is a fixed version actually available. Two flaws with the same paper score can deserve completely different urgency — and that difference is what your alarm reflects.

03Personal alarms

Alerts personalized to your site.

Most disclosures don't affect you — and alert fatigue is why the real warnings get ignored. We know your exact stack, check it against the database daily, and alert you only when your site is exposed: your plugins, your versions, your alarm — three a year that matter, not three thousand headlines.

FIG. 3Signal, not noise
THIS YEAR'S DISCLOSURES · THOUSANDSyour stack · 23 plugins · 4 themesalarm · form-builder-proCRITICAL · fix readyalarm · seo-toolkitHIGH · update availablealarm · gallery-maxMEDIUM · shieldedyou heard about three. the three that mattered.

Read: personalization isn't a preference setting — it's the difference between an alarm you act on and a newsletter you archive.

FIG. 3Signal, not noise
···

Thousands of disclosures

Most don't affect you — and never reach your inbox.

FILTERED OUT

Your stack · checked daily

23 plugins, 4 themes — every version known.

WATCHED
3

Your alarms this year

The three that mattered — each with the fix attached.

ACTED ON
04One dashboard

All your updates in one place — vulnerabilities clearly marked.

Without vulnerability data, updates are guesswork: update everything constantly and risk breakage, or update nothing and stay exposed. With it, "when should I update?" has an answer: the marked ones now — the rest when convenient.

FIG. 4The updates queue · security-critical first
updates · all sites2 security-critical
14 updates pending · 2 security-critical · 1 security
form-builder-pro3.2 → 3.3SECURITY · CRITICAL
member-vault1.8 → 1.9SECURITY · CRITICAL
seo-toolkit4.2 → 4.3SECURITY
woocommerce9.1 → 9.2routine
astra theme4.8 → 4.8.1routine
quick-forms2.0 → 2.1routine
update the marked ones now — the rest when convenient ✓

Read: the queue is ranked by the verdict, not by release date — urgency you can see at a glance, across every site you run.

05The two exits

Act on an alert: shield now, or update safely.

Every alert arrives with the action attached. Vulnerability Shield covers the flaw within hours of disclosure, and a Safe Update fixes it permanently — with a visual regression test so the update can't silently break your site.

FIG. 5Alarm → covered → fixed
ALARM · 09:02form-builder-pro · CRITICALSHIELD · covered in hoursvirtual patch, built from thevulnerable code — while you decideno waiting on the vendor=SAFE UPDATE · fixed for goodvisual regression test: before = after ✓EXPOSURE: CLOSEDknow → covered → fixed

Read: the shield buys you time (how virtual patching works →); the safe update ends the story — and the regression test means the fix can't quietly cost you your layout.

FIG. 5The two exits
!

The alarm

form-builder-pro · CRITICAL · 09:02.

YOU KNOW
1

Shield now

Virtual patch, live in hours — covered while you decide.

COVERED
2

Safe update

Visual regression test — before = after ✓. The permanent fix.

FIXED
06Telemetry

Measured, not claimed.

The database, and the reality it tracks.

0vulnerabilities tracked
0of vulnerability data
0sources · one verdict
Dailychecks · every site's stack
0shield patches shipped

FIG. 6 — why this layer exists

hacks starting in plugins/themes91%
flaws with no patch at disclosure46%
more vulns exploited yoy+42%

average exposure without alerts: 180 days

What an alarm includes

the verdictwith reasons
your exposureplugin + version
the fixone click away

an alarm you can act on — or it's just another headline

Point-in-time figures as of July 2026 · refreshed monthly

07Where it fits

Where the scanner fits in 7-layer security.

The scanner is the intelligence layer — the rest of the suite turns what it knows into protection.

7.1

Vulnerability scanner

Knows about the flaw on day zero — and whether you run it.

THE INTELLIGENCE
7.2

Vulnerability Shield

Virtually patches it within hours — covered while you decide.

THE STOPGAP
7.3

Safe auto-updates

The permanent fix, visual-regression-tested so it can't break your site.

THE FIX
7.4

Malware scanner

The backstop — if something got in before the alarm, it gets found.

THE SEARCHLIGHT

Detection layers tell you what's happening. This layer tells you what's coming.

08Voices

From the people who rely on it.

Real customers — quotes from our reviews and case studies.

"

Always one step ahead! Before any clients or customers have a weird experience, I get a vulnerability notification which is easily fixed with one click. Really impressed with their scanner precision!

David McCanWebTNG
"

I was on the beach with my family when MalCare notified me of a plugin vulnerability across 50 of my sites. With one click on my smartphone, all sites were fixed within minutes.

Paul LaceyPaul LaceyWordPress Expert
Watch case study →
"

I had been running iThemes, WordFence & Sucuri, but they kept getting hacked. Then I installed MalCare, which quickly found the malware and cleaned up the entire site.

Adam SilverAdam SilverConciergeWP · Founder
Watch case study →
09Questions

Answered straight.

How is this different from the malware scanner?+

Timing. The malware scanner finds infections that already happened; the vulnerability scanner warns you about the flaw before anyone uses it. One looks backward, one looks forward — you want both.

How is this different from Vulnerability Shield?+

The scanner is the intelligence — it knows about the flaw and whether you're exposed. The Shield is the protection — a virtual patch that covers the flaw within hours. The alarm connects them: know, then be covered, then fix.

Will I get spammed with alerts?+

No. Alarms are personalized to your exact stack — your plugins, your versions. Most disclosures never reach you, because they don't affect you. When an alarm arrives, it matters.

What if there's no patch yet?+

That's nearly half of all disclosures — 46% have no patch on day zero. That's exactly what Vulnerability Shield exists for: a virtual patch covers the flaw within hours, no vendor required.

Can an update break my site?+

It can — which is why Safe Updates run a Visual Regression Test: your site is compared before and after the update, and if anything visually breaks, you know before your visitors do.

How current is the database?+

Disclosures are reviewed from 10+ sources and the database is updated continuously; your stack is checked against it daily. New or old, a tracked flaw doesn't go stale.

Do vulnerability databases really disagree?+

Constantly — the same flaw can be High in one database, Critical in another, and missing from a third. That's why we reconcile everything into one verdict, re-scored for real exploitability, with the reasons attached.

Do I still need to update my plugins?+

Yes — updates are the permanent fix. What changes is how: you'll know which updates are security-critical, the shield covers you until you're ready, and the safe update makes the fix risk-free.

10Start

Get vulnerability alerts on day zero.

The most comprehensive vulnerability database in WordPress, checked against your stack daily — with the shield and the safe update one click away.

Your stack, checked daily · alarms only when it matters · works on any host