Updates and known vulnerabilities
The panel rates every plugin, theme and WordPress version on your sites against the advisories that wpvulnerability.net publishes, a free feed. The ratings appear wherever updates do: on each site’s WordPress tab and on Sites → Bulk management.

What is sent to wpvulnerability.net
Section titled “What is sent to wpvulnerability.net”The panel asks the feed about each plugin and theme by its slug, and about WordPress by its version number. It asks from the panel’s own server, at most once a day per slug, and keeps the answer. Whether an installed version is affected is worked out on the panel, so one answer serves every site. No site name, domain or visitor address is part of a request.
Switch the ratings off
Section titled “Switch the ratings off”In Settings → Security, under WordPress updates & security, switch off Rate installed plugins and themes against known vulnerabilities. Then choose Save settings. The panel stops asking, and the ratings disappear. Updates keep working.
Read a rating
Section titled “Read a rating”A rating is the worst advisory that covers the installed version: critical, high, medium or low, with its CVSS score beside it. unrated means the advisory gives no severity. Each advisory names the release that fixes it, or says no fix available.
| Shown | Means |
|---|---|
| closed | wordpress.org removed the plugin. It gets no more updates, so replace it. |
| no data | The feed has no record of this slug, as with most premium plugins. That is not the same as safe. |
| not checked | The slug has not been looked up yet. The next scan does it. |
| check overdue | The saved answer is more than a day old. |
| check failed | The last lookup failed, and the previous answer is shown. |
| range unclear | The advisory names no version range the panel can evaluate. It may not apply. |
Update one site
Section titled “Update one site”On the site’s WordPress tab:
- Update all updates everything that has an update, WordPress included.
- Update core updates WordPress only.
- Fix vulnerable, in the Security card, updates only what an available release fixes.
- Update on a plugin’s or theme’s row updates that one at once.
The first three ask first. Set the two switches, then choose Run it:
- Back up first takes a backup before anything changes, kept until you delete it. It is on by default for a live site.
- Check the site answers afterwards fails the job if the site stops answering.
A row’s Update uses the switches as last set on the page, so by default a live site gets a backup first.
What the update job does
Section titled “What the update job does”One job per site works in this order: the backup, the plugin updates, the theme updates, WordPress last, then the check. It fails when an update fails or the site stops answering, and its message names the backup to go back to. Nothing is rolled back by itself: restore that backup from the site’s Backups tab.
Update many sites
Section titled “Update many sites”On Sites → Bulk management, select rows and choose Update. Each site gets its own job, with the same two switches, as Bulk management explains.
Update on a schedule
Section titled “Update on a schedule”- Open Automations → Schedules and choose New schedule.
- Under What, pick Update plugins, themes and WordPress. Under On, pick the sites.
- Under Options, tick Plugins, Themes or WordPress core. Tick Only updates that fix a known vulnerability to apply only those.
- Set Back up first and Check the site answers afterwards, and under When, how often it runs.
Each run reads the site again and decides then what to update. Its backups count as scheduled backups, so retention removes the old ones.
Limits
Section titled “Limits”- A new advisory shows once the panel next refreshes that slug, up to a day later.
- A failed update is not undone automatically. Restoring the backup also undoes every other change made to the site since.
- Where no fixed release exists, Fix vulnerable leaves the plugin as it is. Deactivating it is your decision.