New 24/7 monitoring and daily cloud backups now included in every Shield Pro plan.

Free tool · Security

WordPress Plugin Vulnerability Lookup

Use the WordPress plugin vulnerability lookup when you already know the plugin and version installed on your site. Enter its slug to compare that release with available vulnerability records without scanning your website.

Free WordPress plugin vulnerability lookup

Enter a plugin's slug and installed version to check for known vulnerabilities affecting that release.

The identifier in its WordPress.org address, for example woocommerce.

Copy the exact version shown under Plugins in WordPress, for example 9.0.0.

Free to use without an account. View the result here and choose whether to receive it by email.

What the tool covers

Check a known plugin release

Known vulnerability matches for the plugin slug and version you provide, including linked record identifiers when the available sources supply them.

The exact plugin identifier

The supplied slug identifies the component being looked up. A similar display name or an incorrect slug can refer to a different plugin.

Your supplied release

Available vulnerability records are checked against the version you enter. Using the installed release keeps the comparison relevant to your own website.

One priority finding

The lookup highlights one matching advisory, prioritising the highest reported severity, with source credit and a reference link when available.

Understand the limits

Results depend on correct inputs and available records. No match does not prove that a plugin is secure or actively maintained.

Understanding your result

Follow the record from a match to a maintenance decision

The lookup makes a version comparison using the details you provide. It does not verify your installation, update the plugin or establish whether an issue has been exploited.

Follow a match to its advisory

Open the reference and confirm its affected versions, conditions and developer guidance. Prepare a backup and a staging test for the available fix before updating a critical site.

Keep an empty result in perspective

Check that the slug and version were entered correctly. No matching record in the available sources does not establish that an undisclosed issue cannot exist.

Unavailable coverage needs another source

Read the plugin vendor's security notices when the lookup cannot verify coverage, particularly for premium software. Keep the result with your installed version so a developer can investigate the same release.

Find the correct plugin identifier

A plugin's display name can differ from its slug. For a WordPress.org plugin, use the final part of its directory address, such as woocommerce. Then copy the installed version from the Plugins screen in your dashboard. A wrong slug or version can produce an irrelevant result.

Follow the source before planning an update

The lookup shows at most one finding for the plugin, selected by the highest severity supplied by the sources. The total still includes other matching advisories, so the displayed finding is not an exhaustive list of issues. Review the record supplied through Wordfence and its advisory reference, then confirm the affected releases and the plugin developer's update guidance. Back up the site and test the available fix before changing a production store or another critical website.

Keep gaps in coverage visible

A plugin can have no matching record because no issue is listed, the supplied identifier is wrong or the available data does not cover it. Check premium plugin advisories directly with the vendor. Continue maintaining the software even when the lookup returns no match.

Questions about this tool

What is a WordPress plugin slug?

It is the plugin's machine-readable identifier. For WordPress.org plugins it appears in the directory address after /plugins/, such as woocommerce.

Where do I find my installed plugin version?

Open the Plugins screen in WordPress and read the version displayed with that plugin. Use the installed version, not the newest version advertised online.

Does the lookup connect to my website?

No. It uses the plugin slug and version you enter. Use the vulnerability scanner if you want to investigate public clues from a website address.

Does no match mean a plugin is safe?

No. It means the lookup found no matching issue in the available records for the inputs supplied. It cannot prove that undisclosed vulnerabilities do not exist.

Can I receive the plugin lookup result by email?

Yes. The optional email form appears after you start the lookup. You can also read the completed result on this page.

Free website widget

Add this tool to your website

Let visitors use the WordPress Plugin Vulnerability Lookup on your own page, including the option to email their results. Copy the code into an Elementor HTML widget or a WordPress Custom HTML block, then preview the published page.

Get the embed code
Preview the widget

The widget fits the width of its container. Increase the height value if you want more of the report visible at once; longer results can be scrolled inside the widget.

BugShield hosts and runs the tool. Results and email addresses stay inside the widget and are not shared with the page embedding it. If your editor removes the code or your site blocks external widgets, ask your website administrator to allow frames from bugshield.co.uk.

Need help with the next step?

A BugShield developer can review the findings and help you decide what your WordPress site needs.

Explore WordPress support