Site Fleet HealthGuide

How to check client sites for vulnerable or closed plugins, without logging in

Updated 2026-10-10 ยท by Hieu Tran, written with AI agents and checked against the sources below

Your management dashboard says what it updated. To know what's actually running, check from the outside: every WordPress site serves files that reveal plugin versions, and WordPress.org and Wordfence publish what's outdated, closed or vulnerable.

Free tool: Check up to 10 client sites: versions, closed plugins and known vulnerabilities

Paste site addresses; it reads public files only and compares them with WordPress.org and the Wordfence Intelligence database.

What you can see from outside

What to compare against

  1. Latest version: the WordPress.org plugin API returns the current version for each slug.
  2. Closed plugins: the same API says if a plugin was closed, when and why (for example "Security Issue"). A closed plugin gets no more updates from the directory.
  3. Known vulnerabilities: the Wordfence Intelligence feed (free API key) lists affected version ranges and the fixed version for each vulnerability.

Read the results with care

Free tool: Check up to 10 client sites: versions, closed plugins and known vulnerabilities

Paste site addresses; it reads public files only and compares them with WordPress.org and the Wordfence Intelligence database.