Free tool · Security
WordPress Plugin Vulnerability Lookup
Use the WordPress plugin vulnerability lookup when you already know the plugin and version installed on your site. Enter its slug to compare that release with available vulnerability records without scanning your website.
Free WordPress plugin vulnerability lookup
Free to use without an account. View the result here and choose whether to receive it by email.
What the tool covers
Check a known plugin release
Known vulnerability matches for the plugin slug and version you provide, including linked record identifiers when the available sources supply them.
The exact plugin identifier
The supplied slug identifies the component being looked up. A similar display name or an incorrect slug can refer to a different plugin.
Your supplied release
Available vulnerability records are checked against the version you enter. Using the installed release keeps the comparison relevant to your own website.
One priority finding
The lookup highlights one matching advisory, prioritising the highest reported severity, with source credit and a reference link when available.
Understand the limits
Results depend on correct inputs and available records. No match does not prove that a plugin is secure or actively maintained.
Understanding your result
Follow the record from a match to a maintenance decision
The lookup makes a version comparison using the details you provide. It does not verify your installation, update the plugin or establish whether an issue has been exploited.
Follow a match to its advisory
Open the reference and confirm its affected versions, conditions and developer guidance. Prepare a backup and a staging test for the available fix before updating a critical site.
Keep an empty result in perspective
Check that the slug and version were entered correctly. No matching record in the available sources does not establish that an undisclosed issue cannot exist.
Unavailable coverage needs another source
Read the plugin vendor's security notices when the lookup cannot verify coverage, particularly for premium software. Keep the result with your installed version so a developer can investigate the same release.
Find the correct plugin identifier
A plugin's display name can differ from its slug. For a WordPress.org plugin, use the final part of its directory address, such as woocommerce. Then copy the installed version from the Plugins screen in your dashboard. A wrong slug or version can produce an irrelevant result.
Follow the source before planning an update
The lookup shows at most one finding for the plugin, selected by the highest severity supplied by the sources. The total still includes other matching advisories, so the displayed finding is not an exhaustive list of issues. Review the record supplied through Wordfence and its advisory reference, then confirm the affected releases and the plugin developer's update guidance. Back up the site and test the available fix before changing a production store or another critical website.
Keep gaps in coverage visible
A plugin can have no matching record because no issue is listed, the supplied identifier is wrong or the available data does not cover it. Check premium plugin advisories directly with the vendor. Continue maintaining the software even when the lookup returns no match.
Questions about this tool
What is a WordPress plugin slug?
It is the plugin's machine-readable identifier. For WordPress.org plugins it appears in the directory address after /plugins/, such as woocommerce.
Where do I find my installed plugin version?
Open the Plugins screen in WordPress and read the version displayed with that plugin. Use the installed version, not the newest version advertised online.
Does the lookup connect to my website?
No. It uses the plugin slug and version you enter. Use the vulnerability scanner if you want to investigate public clues from a website address.
Does no match mean a plugin is safe?
No. It means the lookup found no matching issue in the available records for the inputs supplied. It cannot prove that undisclosed vulnerabilities do not exist.
Can I receive the plugin lookup result by email?
Yes. The optional email form appears after you start the lookup. You can also read the completed result on this page.
Free website widget
Add this tool to your website
Let visitors use the WordPress Plugin Vulnerability Lookup on your own page, including the option to email their results. Copy the code into an Elementor HTML widget or a WordPress Custom HTML block, then preview the published page.
Get the embed code
The widget fits the width of its container. Increase the height value if you want more of the report visible at once; longer results can be scrolled inside the widget.
BugShield hosts and runs the tool. Results and email addresses stay inside the widget and are not shared with the page embedding it. If your editor removes the code or your site blocks external widgets, ask your website administrator to allow frames from bugshield.co.uk.
Need help with the next step?
A BugShield developer can review the findings and help you decide what your WordPress site needs.
Explore WordPress support