MalCare reviews vulnerability disclosures from 10+ sources every day and reconciles them into one clean, current database — 39,000+ flaws tracked over 5+ years, no gaps, no contradictions. Your site's stack is checked against it daily, and you're alerted the day a flaw that affects you is disclosed — with the fix one click away.
When a flaw in a plugin goes public, attackers weaponize it within hours and spray it at every site running that version — they don't find you, scripts find everyone. 91% of hacks start in plugins and themes. And 46% of flaws have no patch on the day they're disclosed.
Read: an alert doesn't protect you by itself — it starts the clock in your favor. What happens next is one click away (§05).
The flaw goes public — and you get the alarm.
YOU KNOWWeaponized and shared within hours.
THE RACEScripts probe every site running the version — including yours.
AT YOUR DOORMost owners find out from the hack itself.
TOO LATEThe same flaw shows up in different databases with different severities — or not at all. Our security team reviews disclosures from 10+ sources every day, deduplicates them, resolves the conflicts, and re-scores each flaw for how it's actually exploitable. The result is the most robust, up-to-date vulnerability database in WordPress: no gaps, no contradictions, no stale entries.
Read: severity gets re-evaluated for reality — does it need a login, is an exploit loose, do you even run the version. The verdict carries its reasons.
HIGH · 7.5
ONE OPINIONCRITICAL · 9.8
ANOTHERNot listed at all.
SILENCECRITICAL — exploitable without login, exploit circulating, your site runs it. Fix attached.
A DECISIONA published severity score (CVSS or otherwise) is a starting point, not an answer. Our team re-evaluates each disclosure for what decides real-world risk: can it be exploited without logging in; is a working exploit circulating; how large is the install base; is a fixed version actually available. Two flaws with the same paper score can deserve completely different urgency — and that difference is what your alarm reflects.
Most disclosures don't affect you — and alert fatigue is why the real warnings get ignored. We know your exact stack, check it against the database daily, and alert you only when your site is exposed: your plugins, your versions, your alarm — three a year that matter, not three thousand headlines.
Read: personalization isn't a preference setting — it's the difference between an alarm you act on and a newsletter you archive.
Most don't affect you — and never reach your inbox.
FILTERED OUT23 plugins, 4 themes — every version known.
WATCHEDThe three that mattered — each with the fix attached.
ACTED ONWithout vulnerability data, updates are guesswork: update everything constantly and risk breakage, or update nothing and stay exposed. With it, "when should I update?" has an answer: the marked ones now — the rest when convenient.
Read: the queue is ranked by the verdict, not by release date — urgency you can see at a glance, across every site you run.
Every alert arrives with the action attached. Vulnerability Shield covers the flaw within hours of disclosure, and a Safe Update fixes it permanently — with a visual regression test so the update can't silently break your site.
Read: the shield buys you time (how virtual patching works →); the safe update ends the story — and the regression test means the fix can't quietly cost you your layout.
form-builder-pro · CRITICAL · 09:02.
YOU KNOWVirtual patch, live in hours — covered while you decide.
COVEREDVisual regression test — before = after ✓. The permanent fix.
FIXEDThe database, and the reality it tracks.
average exposure without alerts: 180 days
an alarm you can act on — or it's just another headline
Point-in-time figures as of July 2026 · refreshed monthly
The scanner is the intelligence layer — the rest of the suite turns what it knows into protection.
Knows about the flaw on day zero — and whether you run it.
THE INTELLIGENCEVirtually patches it within hours — covered while you decide.
THE STOPGAPThe permanent fix, visual-regression-tested so it can't break your site.
THE FIXThe backstop — if something got in before the alarm, it gets found.
THE SEARCHLIGHTDetection layers tell you what's happening. This layer tells you what's coming.
Real customers — quotes from our reviews and case studies.
Always one step ahead! Before any clients or customers have a weird experience, I get a vulnerability notification which is easily fixed with one click. Really impressed with their scanner precision!
I was on the beach with my family when MalCare notified me of a plugin vulnerability across 50 of my sites. With one click on my smartphone, all sites were fixed within minutes.
Paul LaceyWordPress ExpertI had been running iThemes, WordFence & Sucuri, but they kept getting hacked. Then I installed MalCare, which quickly found the malware and cleaned up the entire site.
Adam SilverConciergeWP · FounderTiming. The malware scanner finds infections that already happened; the vulnerability scanner warns you about the flaw before anyone uses it. One looks backward, one looks forward — you want both.
The scanner is the intelligence — it knows about the flaw and whether you're exposed. The Shield is the protection — a virtual patch that covers the flaw within hours. The alarm connects them: know, then be covered, then fix.
No. Alarms are personalized to your exact stack — your plugins, your versions. Most disclosures never reach you, because they don't affect you. When an alarm arrives, it matters.
That's nearly half of all disclosures — 46% have no patch on day zero. That's exactly what Vulnerability Shield exists for: a virtual patch covers the flaw within hours, no vendor required.
It can — which is why Safe Updates run a Visual Regression Test: your site is compared before and after the update, and if anything visually breaks, you know before your visitors do.
Disclosures are reviewed from 10+ sources and the database is updated continuously; your stack is checked against it daily. New or old, a tracked flaw doesn't go stale.
Constantly — the same flaw can be High in one database, Critical in another, and missing from a third. That's why we reconcile everything into one verdict, re-scored for real exploitability, with the reasons attached.
Yes — updates are the permanent fix. What changes is how: you'll know which updates are security-critical, the shield covers you until you're ready, and the safe update makes the fix risk-free.
The most comprehensive vulnerability database in WordPress, checked against your stack daily — with the shield and the safe update one click away.
Your stack, checked daily · alarms only when it matters · works on any host