Vulnerability monitoring for your WordPress plugins & themes.
Relvato checks the plugins and themes you actually have installed against known vulnerabilities, and flags any that have been closed or abandoned on wp.org — the ones that quietly become a security hole.
- ✓Installed plugins and themes matched against known CVEs
- ✓Powered by the Wordfence Intelligence vulnerability database
- ✓Plugins or themes closed or removed from wp.org
- ✓Abandoned plugins or themes with no updates in a long time
- ✓Curated vendor/remote-access advisories — an update that grants the vendor admin access to your site
- ✓Severity plus a fix or replace recommendation
Most WordPress hacks come through a plugin or theme with a public CVE that never got updated, or one the author abandoned. Your dashboard won't tell you. Relvato compares your installed plugin and theme slugs and versions against the Wordfence Intelligence vulnerability data and warns you which to update or replace.
Works on any WordPress or WooCommerce site.
- Reads your installed plugin and theme slugs and versions via the plugin (shared only when you enable this check).
- Matches them against the Wordfence Intelligence vulnerability feed (and WPScan), plus wp.org's closed or abandoned status.
- Reports each risky plugin or theme with its CVE and severity, linked to its Wordfence record, so you know what to update or replace first.
Data sourceWordfence Intelligence Vulnerability Database, CISA Known Exploited Vulnerabilities (KEV) catalog
Does it cover themes as well as plugins?
Yes. Relvato reads both your installed plugins and your themes and checks each against the vulnerability database and wp.org's closed/abandoned status.
Where does the vulnerability data come from?
From the Wordfence Intelligence Vulnerability Database — an industry-leading, continuously updated feed of WordPress plugin and theme CVEs — optionally combined with WPScan. Each finding links back to its Wordfence record.
What data does it share?
Only your installed plugin and theme names and versions, and only when you enable this check — never file contents.
Does it need the plugin?
Yes — reading the installed plugin and theme inventory needs the WordPress plugin.
What's a “vendor / remote-access advisory”?
A deliberate plugin behaviour that no vulnerability feed reports — for example, an update that grants the plugin's vendor administrative or remote-management access to your site. Relvato surfaces these as a factual, sourced heads-up so you can decide whether you trust that access; it's a prompt to review, not an accusation.
Put this check on autopilot.
Free while you set it up — 100 checks or 30 days. No card, no sales call.