{"id":370537,"date":"2026-09-18T12:48:48","date_gmt":"2026-09-18T12:48:48","guid":{"rendered":"https:\/\/es.wordpress.org\/plugins\/vulncue\/"},"modified":"2026-09-18T12:48:30","modified_gmt":"2026-09-18T12:48:30","slug":"vulncue","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/vulncue\/","author":23567748,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.0","stable_tag":"1.0.0","tested":"7.1.1","requires":"6.0","requires_php":"7.4","requires_plugins":null,"header_name":"VulnCue","header_author":"VulnCue","header_description":"Analiza la seguridad de tu WordPress desde dentro: n\u00facleo\/plugins\/temas desactualizados, configuraci\u00f3n insegura, ficheros sensibles expuestos, vulnerabilidades conocidas y m\u00e1s. Conecta una cuenta de VulnCue para avisos por correo cuando salga un CVE nuevo.","assets_banners_color":"283d62","last_updated":"2026-09-18 12:48:30","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/vulncue.com\/","header_author_uri":"","rating":0,"author_block_rating":0,"active_installs":0,"downloads":52,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"vulncue","date":"2026-09-18 12:48:30","revision":3701997}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3702042,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3702042,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3702009,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3702009,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3702009,"resolution":"1","location":"assets","locale":"","width":1186,"height":674},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3702009,"resolution":"2","location":"assets","locale":"","width":1164,"height":704},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3702009,"resolution":"3","location":"assets","locale":"","width":855,"height":402},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3702009,"resolution":"4","location":"assets","locale":"","width":422,"height":294},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3702009,"resolution":"5","location":"assets","locale":"","width":1273,"height":818}},"screenshots":{"1":"Main screen: 0-100 risk level and findings grouped by severity.","2":"Finding detail, with the fix explained step by step.","3":"VulnCue account connection (optional) to get email alerts for new vulnerabilities.","4":"Summary widget on the WordPress Dashboard.","5":"Help page: what information leaves your site and when, plus the free vs. paid-plan comparison."}},"plugin_section":[262246],"plugin_tags":[8533,31093,6464,600,6460],"plugin_category":[54],"plugin_contributors":[281438],"plugin_business_model":[],"class_list":["post-370537","plugin","type-plugin","status-publish","hentry","plugin_section-dashboard-widgets","plugin_tags-audit","plugin_tags-hardening","plugin_tags-scanner","plugin_tags-security","plugin_tags-vulnerability","plugin_category-security-and-spam-protection","plugin_contributors-vulncue","plugin_committers-vulncue"],"banners":{"banner":"https:\/\/ps.w.org\/vulncue\/assets\/banner-772x250.png?rev=3702009","banner_2x":"https:\/\/ps.w.org\/vulncue\/assets\/banner-1544x500.png?rev=3702009","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/vulncue\/assets\/icon-128x128.png?rev=3702042","icon_2x":"https:\/\/ps.w.org\/vulncue\/assets\/icon-256x256.png?rev=3702042","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/vulncue\/assets\/screenshot-1.png?rev=3702009","caption":"Main screen: 0-100 risk level and findings grouped by severity."},{"src":"https:\/\/ps.w.org\/vulncue\/assets\/screenshot-2.png?rev=3702009","caption":"Finding detail, with the fix explained step by step."},{"src":"https:\/\/ps.w.org\/vulncue\/assets\/screenshot-3.png?rev=3702009","caption":"VulnCue account connection (optional) to get email alerts for new vulnerabilities."},{"src":"https:\/\/ps.w.org\/vulncue\/assets\/screenshot-4.png?rev=3702009","caption":"Summary widget on the WordPress Dashboard."},{"src":"https:\/\/ps.w.org\/vulncue\/assets\/screenshot-5.png?rev=3702009","caption":"Help page: what information leaves your site and when, plus the free vs. paid-plan comparison."}],"raw_content":"<!--section=description-->\n<p>VulnCue scans your WordPress <strong>from the inside<\/strong>, something an external\nscanner can't do with the same precision: an exact inventory of installed\nplugins and themes, outdated core, an unsupported PHP version, uncustomized\nwp-config.php security keys, an active file editor, an exposed \"admin\" user,\nactive XML-RPC, sensitive files left in the public folder (backups, <code>.env<\/code>,\n    .git), and more.<\/p>\n\n<p>All of these checks are <strong>100% free, with no need to create an account or\ngive your email<\/strong>. If you want an email alert when a new vulnerability (CVE)\naffects one of your installed plugins, you can connect a free account from\nVulnCue's client area (https:\/\/vulncue.com\/) \u2014 optional, never required to\nuse the plugin.<\/p>\n\n<h3>External services<\/h3>\n\n<p>By default, this plugin <strong>sends no data to external servers<\/strong>. All checks\nuse WordPress's own data (update transients, wp-config.php constants, the\npublic folder's file listing).<\/p>\n\n<p>Six exceptions, all of which can be turned off or only trigger on your\nexplicit action (the first three from the plugin's screen; the fourth and\nfifth only activate if you connect an account yourself; the sixth only if\nyou choose to send it):<\/p>\n\n<ul>\n<li><strong>Checks that make the site send a request to itself<\/strong>: XML-RPC\n(<code>xmlrpc.php<\/code>), user enumeration via the REST API (<code>\/wp-json\/wp\/v2\/users<\/code>),\nSSL\/TLS certificate expiry and trust (two HTTPS connections to the site's\nown domain), directory listing on <code>wp-content\/uploads\/<\/code>, and whether the\nhomepage reveals the WordPress version in the <code>&lt;meta name=\"generator\"&gt;<\/code>\ntag. None of these requests go out to VulnCue or any third party \u2014 it's\nyour own WordPress talking to itself to check how it responds. The whole\ngroup can be disabled with the \"Include checks that make this site send a\nrequest to itself\" checkbox.<\/li>\n<li><strong>Known vulnerability check (enabled by default, no account or email\nneeded)<\/strong>: the plugin sends vulncue.com the list of installed plugins and\nthemes (only the technical name and version, never personal data or\nanything about your site) to check them against VulnCue's public CVE\ncatalog. Can be disabled with the \"Check installed plugins\/themes against\nVulnCue's public vulnerability catalog\" checkbox.<\/li>\n<li><strong>Core integrity verification (enabled by default, no account or email\nneeded)<\/strong>: the plugin queries <code>api.wordpress.org<\/code> (WordPress's own official\nserver, not VulnCue's) to get the public checksums for your WordPress\nversion and check that the core files haven't been modified. Only the\nWordPress version and language are sent, never anything about your site.\nCan be disabled with the \"Check WordPress core integrity\" checkbox.<\/li>\n<li><strong>Account connection (optional, the only one that sends your email)<\/strong>: if\nyou choose to enter your email to connect a free account, the plugin sends\nyour site's URL, your email, and your WordPress version to vulncue.com, to\ncreate your account and be able to email you about new CVEs. Privacy\npolicy: https:\/\/vulncue.com\/politica-privacidad.html<\/li>\n<li><strong>Scheduled auto-scan + inventory report (only if you connected an\naccount)<\/strong>: every hour, WP-Cron checks (sending only your connection key)\nwhether a new automatic scan is due \u2014 every 7 days on the free plan, every\nday on a paid plan; the hourly check only shortens the wait for the first\nscan after connecting, it doesn't increase the actual frequency. When it's\ndue, besides scanning your site it sends the\nlist of installed plugins and themes (technical name and version, never\npersonal data) so it can email you if any of them has a new vulnerability\n\u2014 each alert is sent only once per vulnerability. Also, once your account\nis connected, you'll get a weekly email with your current risk level and\nfindings (this summary is sent by your own WordPress, not by vulncue.com).\nIf you haven't connected an account, none of this happens and scanning\nstays fully manual (\"Scan again\").<\/li>\n<li><strong>Deactivation survey (optional)<\/strong>: when you deactivate the plugin you can\nsay why. Choosing \"Skip\" sends nothing. Writing something and confirming\nsends vulncue.com the site's URL, the reason, and the WordPress\/PHP\/plugin\nversions \u2014 never your email or any other personal data.<\/li>\n<\/ul>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>vulncue-security<\/code> folder to <code>\/wp-content\/plugins\/<\/code>, or install\nit from Dashboard \u2192 Plugins \u2192 Add New, searching for \"VulnCue\".<\/li>\n<li>Activate it.<\/li>\n<li>Go to \"VulnCue\" in the side menu to see the result of the first scan (it\nruns automatically on activation).<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20this%20replace%20a%20full%20security%20audit%3F\"><h3>Does this replace a full security audit?<\/h3><\/dt>\n<dd><p>No. This plugin only sees what's visible <strong>from inside<\/strong> your WordPress\ninstallation. An external scan (like the one VulnCue runs from the outside,\nor a pentest) checks additional things that can only be seen from the\noutside: TLS certificate, HTTP headers, email SPF\/DMARC records, mixed\ncontent, etc.<\/p><\/dd>\n<dt id=\"do%20i%20have%20to%20create%20an%20account%20to%20use%20it%3F\"><h3>Do I have to create an account to use it?<\/h3><\/dt>\n<dd><p>No. Scanning and the known-vulnerability check work without creating any\naccount. The account is optional and only adds email alerts for new CVEs.<\/p><\/dd>\n<dt id=\"does%20the%20plugin%20fix%20issues%20automatically%3F\"><h3>Does the plugin fix issues automatically?<\/h3><\/dt>\n<dd><p>No. By design, it doesn't modify anything on your site \u2014 it only detects\nissues and explains how to fix each one. Applying the change (updating,\nmoving a file, editing wp-config.php) is up to you or whoever manages the\nsite.<\/p><\/dd>\n<dt id=\"does%20it%20slow%20down%20my%20site%3F\"><h3>Does it slow down my site?<\/h3><\/dt>\n<dd><p>No. The whole scan only runs when you open the plugin's screen in wp-admin \u2014\nnever for your visitors or on the public side of your site.<\/p><\/dd>\n<dt id=\"how%20is%20the%200-100%20risk%20level%20calculated%3F\"><h3>How is the 0-100 risk level calculated?<\/h3><\/dt>\n<dd><p>It starts at 0 and each finding adds points based on its severity: up to 30\nfor critical, 18 for high, 8 for medium, 3 for low, and 1 for informational \u2014\neach additional finding of the same severity adds less and less, so lots of\nminor warnings don't drive up the risk as much as a single serious one. 0\nmeans no problem was detected in the last scan, and 100 is the maximum risk.<\/p><\/dd>\n<dt id=\"how%20often%20should%20i%20scan%20my%20site%20again%3F\"><h3>How often should I scan my site again?<\/h3><\/dt>\n<dd><p>You can click \"Scan again\" whenever you want. If you connect an account, it\nalso scans itself automatically: every 7 days on the free account, every day\non a paid plan.<\/p><\/dd>\n<dt id=\"does%20it%20work%20on%20wordpress%20multisite%20installs%3F\"><h3>Does it work on WordPress Multisite installs?<\/h3><\/dt>\n<dd><p>Yes. Each site on the network is scanned separately (its own findings and\nrisk level), and the Network Dashboard shows a combined summary of every\nsite.<\/p><\/dd>\n<dt id=\"what%20happens%20if%20i%20uninstall%20the%20plugin%3F\"><h3>What happens if I uninstall the plugin?<\/h3><\/dt>\n<dd><p>Everything the plugin saved on your WordPress is deleted, and the client area\nis notified that this site is no longer connected. Your VulnCue account\nitself isn't deleted (in case you use it on another site with the same\nemail).<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>First public release. 100% local, free-forever check engine, no account or\nemail needed: outdated core\/plugins\/themes, PHP EOL, WP_DEBUG, default\nsecurity keys, DISALLOW_FILE_EDIT, exposed \"admin\" user, open registration\nwith administrator as the default role, exposed sensitive files, exposed\nreadme.html and generator tag, PHP execution and directory listing in the\nuploads folder, table prefix and wp-config.php permissions, inactive\nplugins\/themes, automatic core updates, two-factor authentication,\nbrute-force protection, backup plugin, new or recently promoted\nadministrator accounts, XML-RPC, REST user enumeration, and SSL\/TLS\ncertificate expiry\/trust.<\/li>\n<li>Known vulnerability (CVE) check against VulnCue's public catalog and core\nintegrity check against wordpress.org's official checksums \u2014 both enabled\nby default, no account or email needed, and both can be disabled.<\/li>\n<li>Optional connection of a free VulnCue account (email only, with\nlink-based confirmation) for new-CVE email alerts and a weekly risk-level\nsummary \u2014 never required for the rest of the plugin. Scheduled auto-scan\nvia WP-Cron for connected accounts.<\/li>\n<li>0-100 risk level with a visual ring (0 = no issues found, the higher it\nis, the more important the findings; repeated findings of the same\nseverity weigh less each time so the scale doesn't saturate), a severity\nbar, and a history chart of the risk level with each scan's number always\nvisible.<\/li>\n<li>Hide individual findings you're already aware of (with its own list so\nyou can unhide them whenever you want) \u2014 they don't count toward the\nrisk level or the menu badge while hidden.<\/li>\n<li>Menu-bar alert for new critical\/high findings, a reminder if it's been a\nwhile since your last scan, a \"what's changed since your last scan\"\nsummary, Tools \u2192 Site Health integration, PDF export, and WordPress\nMultisite support (a summary of every site on the network, from the\nNetwork Dashboard).<\/li>\n<li>Full English translation (en_US, en_GB, en_AU, en_CA, en_NZ, en_ZA): the\nwhole plugin also works on English-language WordPress installs.<\/li>\n<li>Optional \"why are you deactivating VulnCue?\" survey when clicking\n\"Deactivate\" on Dashboard \u2192 Plugins, with the option to skip it and just\ndeactivate.<\/li>\n<li>WP-Cron check every hour (previously once a day) so the first automatic\nscan\/report after connecting an account takes at most ~1 h instead of up\nto 24 h \u2014 the real scan frequency (7 days free, 1 day paid) doesn't\nchange, only the first-time worst case.<\/li>\n<\/ul>","raw_excerpt":"Scans your WordPress security and tells you what to fix. Connect an account for alerts on new vulnerabilities.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/370537","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=370537"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/vulncue"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=370537"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=370537"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=370537"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=370537"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=370537"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=370537"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}