Linux 软件免费装
Banner图

VulnCue

开发者 vulncue
更新时间 2026年9月18日 21:17
PHP版本: 7.4 及以上
WordPress版本: 7.1
版权: GPLv2 or later
版权网址: 版权信息

标签

security vulnerability scanner audit hardening

下载

1.0.0

详情介绍:

VulnCue scans your WordPress from the inside, something an external scanner can't do with the same precision: an exact inventory of installed plugins and themes, outdated core, an unsupported PHP version, uncustomized wp-config.php security keys, an active file editor, an exposed "admin" user, active XML-RPC, sensitive files left in the public folder (backups, .env, .git), and more. All of these checks are 100% free, with no need to create an account or give your email. If you want an email alert when a new vulnerability (CVE) affects one of your installed plugins, you can connect a free account from VulnCue's client area (https://vulncue.com/) — optional, never required to use the plugin.

安装:

  1. Upload the vulncue-security folder to /wp-content/plugins/, or install it from Dashboard → Plugins → Add New, searching for "VulnCue".
  2. Activate it.
  3. Go to "VulnCue" in the side menu to see the result of the first scan (it runs automatically on activation).

屏幕截图:

  • Finding detail, with the fix explained step by step.
  • VulnCue account connection (optional) to get email alerts for new vulnerabilities.
  • Summary widget on the WordPress Dashboard.
  • Help page: what information leaves your site and when, plus the free vs. paid-plan comparison.

常见问题:

Does this replace a full security audit?

No. This plugin only sees what's visible from inside your WordPress installation. An external scan (like the one VulnCue runs from the outside, or a pentest) checks additional things that can only be seen from the outside: TLS certificate, HTTP headers, email SPF/DMARC records, mixed content, etc.

Do I have to create an account to use it?

No. Scanning and the known-vulnerability check work without creating any account. The account is optional and only adds email alerts for new CVEs.

Does the plugin fix issues automatically?

No. By design, it doesn't modify anything on your site — it only detects issues and explains how to fix each one. Applying the change (updating, moving a file, editing wp-config.php) is up to you or whoever manages the site.

Does it slow down my site?

No. The whole scan only runs when you open the plugin's screen in wp-admin — never for your visitors or on the public side of your site.

How is the 0-100 risk level calculated?

It starts at 0 and each finding adds points based on its severity: up to 30 for critical, 18 for high, 8 for medium, 3 for low, and 1 for informational — each additional finding of the same severity adds less and less, so lots of minor warnings don't drive up the risk as much as a single serious one. 0 means no problem was detected in the last scan, and 100 is the maximum risk.

How often should I scan my site again?

You can click "Scan again" whenever you want. If you connect an account, it also scans itself automatically: every 7 days on the free account, every day on a paid plan.

Does it work on WordPress Multisite installs?

Yes. Each site on the network is scanned separately (its own findings and risk level), and the Network Dashboard shows a combined summary of every site.

What happens if I uninstall the plugin?

Everything the plugin saved on your WordPress is deleted, and the client area is notified that this site is no longer connected. Your VulnCue account itself isn't deleted (in case you use it on another site with the same email).

更新日志:

1.0.0