Every vulnerability flagged on day zero.Covered within hours.

Most WordPress hacks start at a known flaw in a plugin or theme. MalCare checks every version you run against 39,000+ tracked vulnerabilities daily, alarms you the day a flaw affects your site — and Vulnerability Shield covers it within hours, whether or not a patch exists.

39,000+ VULNS TRACKED · ALARM ON DAY ZERO · COVERED IN HOURS
Trusted by 400,000+ sites · 120 countries
The countdown

After a disclosure, exploitation starts in hours.

Exploit scripts don't pick targets — they probe every site running the flawed version. Most owners learn about the flaw from the hack.

91%
of hacks

start in plugins and themes

Known weaknesses are the usual entry point.

+42%
year over year

more vulnerabilities exploited

Attackers are moving faster after disclosure.

180 days
average exposure

before the owner finds out

MalCare's alarm arrives on day zero instead.

Databases disagree about the same flaw. You get one verdict, with reasons.

Our security team reviews disclosures from 10+ sources every day — duplicates removed, conflicts resolved, every flaw re-scored for how it's actually exploitable.

  • 10+ source categories, reviewed daily
  • One entry per flaw — no contradictions, no stale scores
  • Re-scored for real risk — exploitable without a login, exploit already circulating, fix available or not
  • 39,000+ flaws tracked over 5+ years
CVE-2026-1184form-builder-pro ≤ 3.2
Reconciled · reviewed daily
The same flaw, CVE-2026-1184 in form-builder-pro 3.2 and below, as reported by three disclosure sources and as reconciled by MalCare. Six fields are compared. The national database rates it High with a score of 7.5; the exploit tracker rates the same flaw Critical at 9.8 — a contradiction on both severity and score. The vendor has published nothing at all, so every one of its cells is empty. Two further fields — whether a vendor patch exists, and whether this site runs the affected version — are answered by no source. Counting only firm answers, the national database fills two of the six fields, the exploit tracker four, and the vendor none. MalCare's column fills all six: Critical, 9.8, no login needed, an exploit already circulating, no vendor patch yet but the shield covers it, and yes — this site runs version 3.2.
National databaseCVSS v3.1answers 2/6Exploit trackerin-the-wild feedanswers 4/6Vendor advisorynothing publishedanswers 0/6What the sources sayanswered 2 / 4 / 0MalCare verdictone entry, re-scoredanswers 6/6
SeverityHighCriticalno entryHigh / Critical / —Critical
Score7.59.8no entry7.5 / 9.8 / —9.8
Needs a loginNot statedNono entryNot stated / No / —No
Exploit in the wildNot trackedCirculatingno entryNot tracked / Circulating / —Circulating
Vendor patchno entryNot trackedno entry— / Not tracked / —None yetshield covers it
Affects your siteno entryno entryno entry— / — / —Yesversion 3.2 installed
2 contradictions resolved · 2 fields no source answersCritical
Your stack

Most disclosures don't affect you. You hear about the ones that do.

MalCare knows every plugin, theme and core version on your site and checks them against the database daily. No alarm unless your stack is exposed.

INVENTORY

Every version known

Plugins, themes, and WordPress core.

CADENCE

Checked daily

Against every tracked flaw.

THE ALARM

Names the exposure

Your plugin, your version, and the fix.

The queue

Updates ranked by risk — across every site.

Without vulnerability data, updating is guesswork. The queue marks which updates are security-critical, so “now or later?” has an answer.

  • 4.1Security-critical firstSorted by the verdict, not the release date.
  • 4.2Every site, one screenPending updates across all your sites.
  • 4.3The rest can waitRoutine updates aren't marked urgent — because they aren't.
What happens when you act on one
Act on it

Every alarm arrives with the fix attached.

Two ways to close the exposure — shield it now, or update it safely. Each is one click.

Step 1

The alarm

Names the plugin, the version, and the verdict — with the reasons.

Step 2

Shield now

46% of flaws have no patch on disclosure day. A virtual patch covers yours within hours. How virtual patching works →

Step 3

Update safely

A Visual Regression Test compares your site before and after the update.

The scanner warns you. The rest of MalCare acts on the warning.

The scanner is MalCare's intelligence layer — the suite turns what it knows into protection.

THE INTELLIGENCE

Vulnerability scanner

Knows the flaw on day zero, and whether you run it.

THE STOPGAP

Vulnerability Shield

A virtual patch covers it within hours.

THE FIX

Safe updates

Permanent and regression-tested.

Behind the database, every disclosure is reviewed.

10+ sources, reviewed daily — deduplicated, conflict-resolved, and re-scored before anything reaches you.

Proof

The database, in numbers.

0vulnerabilities tracked
5+ yrsof disclosure data
0sources, one verdict
0shield patches shipped

In their words. Warned before it mattered.

Rated 5 out of 5
Always one step ahead! Before any clients or customers have a weird experience, I get a vulnerability notification which is easily fixed with one click. Really impressed with their scanner precision!
David McCanWebTNG
Rated 5 out of 5
I was on the beach with my family when MalCare notified me of a plugin vulnerability across 50 of my sites. With one click on my smartphone, all sites were fixed within minutes.
Paul LaceyWordPress Expert
Rated 5 out of 5
I had been running iThemes, WordFence & Sucuri, but they kept getting hacked. Then I installed MalCare, which quickly found the malware and cleaned up the entire site.
Adam SilverConciergeWP · Founder

Common questions, answered.

Timing. The malware scanner finds infections that already happened; the vulnerability scanner warns you about the flaw before anyone uses it. One looks backward, one looks forward — you want both.
The scanner is the intelligence — it knows about the flaw and whether you're exposed. The Shield is the protection — a virtual patch that covers the flaw within hours. The alarm connects them: know, then be covered, then fix.
No. Alarms are personalized to your exact stack — your plugins, your versions. Most disclosures never reach you, because they don't affect you. When an alarm arrives, it matters.
That's nearly half of all disclosures — 46% have no patch on day zero. That's exactly what Vulnerability Shield exists for: a virtual patch covers the flaw within hours, no vendor required.
It can — which is why Safe Updates run a Visual Regression Test: your site is compared before and after the update, and if anything visually breaks, you know before your visitors do.
Disclosures are reviewed from 10+ sources and the database is updated continuously; your stack is checked against it daily. New or old, a tracked flaw doesn't go stale.
Constantly — the same flaw can be High in one database, Critical in another, and missing from a third. That's why we reconcile everything into one verdict, re-scored for real exploitability, with the reasons attached.
Yes — updates are the permanent fix. What changes is how: you'll know which updates are security-critical, the shield covers you until you're ready, and the safe update makes the fix risk-free.

Know about the flaw before anyone uses it.

Your stack, checked daily against 39,000+ tracked vulnerabilities — the shield and the safe update one click away.

DAILY CHECKS / ALARMS ONLY WHEN IT MATTERS / WORKS ON ANY HOST