Description

The Vulnerability Checker add-on scans plugins and themes installed on Child sites against the MainWP NVD API (free, maintained by NIST) and the WPScan Vulnerability Database (paid), displaying real-time alerts on the MainWP dashboard. The extension consolidates the security status of all monitored sites into a single dashboard and offers an Ignore feature to dismiss false positives without losing the audit history.

Key Features

  • Scanning against two CVE databases
    Queries the free MainWP NVD API and, optionally, the paid WPScan Vulnerability Database.
  • Centralized vulnerability dashboard
    Lists all vulnerable plugins and themes from Child sites in a single screen in MainWP.
  • Ignore feature for false positives
    Allows you to hide alerts that have already been reviewed without removing them from the audit database.
  • Automatic risk notifications
    Sends alerts when new vulnerabilities are published for installed components.
  • Real-time database updates
    Receives new records from both APIs as soon as they are published, with no need for manual scanning.

Benefits of the Vulnerability Checker

  • Reduced risk of exploitation by known CVEs
    Anticipates fixes before public vulnerabilities are exploited on client sites.
  • Standardized auditing across multiple sites
    Applies the same scanning criteria to the entire portfolio managed by MainWP.
  • Time savings in maintenance
    Replaces site-by-site checking with a consolidated, prioritized view of outstanding items.
  • Support for security compliance
    Generates a history of detected and addressed vulnerabilities, useful for client reports.

Who Is It For?

  • Agencies and maintenance providers that manage dozens or hundreds of WordPress sites through MainWP.
  • Freelancers responsible for ongoing care plans who need recurring security auditing.
  • Internal IT teams that maintain multiple corporate portals under the same central dashboard.

By centralizing CVE checking in the MainWP dashboard itself, this add-on eliminates the need to log into each Child site to check the status of plugins and themes. The combination of the MainWP NVD API with the WPScan Vulnerability Database covers two distinct collections of security intelligence, increasing the chance of early detection and giving managers a concrete basis for prioritizing critical updates within their maintenance routine.

Frequently asked questions

Is MainWP Vulnerability Checker GPL-licensed?

Yes. MainWP Vulnerability Checker is distributed under the GPL (GNU General Public License). You may legally use, modify and redistribute it on as many sites as you want.

Can I use MainWP Vulnerability Checker on multiple sites?

Yes. You can use MainWP Vulnerability Checker on multiple sites. The number of sites connected to Ultrapack Auto Updater is limited by your plan.

How much does MainWP Vulnerability Checker cost at Ultrapack?

MainWP Vulnerability Checker costs US$2.99 as a single purchase, and it is also included in the subscription plans starting at US$12/mo (VIP I).

Does MainWP Vulnerability Checker include updates?

Yes. The current version of MainWP Vulnerability Checker is 5.0.4, published at Ultrapack on Jan 10, 2026. Subscribers update straight from the WordPress dashboard with UAU (Ultrapack Auto Updater).

Is MainWP Vulnerability Checker scanned before publication?

Yes. Every version of MainWP Vulnerability Checker goes through a malware scan (ClamAV and YARA rules, at UltraHub) before it is published.