Create Topic

WP Tavern Forums Create Topic

Create New Topic

Plugin Vulnerabilities

This isn’t actually a vulnerability scanner. What it does is check if Wordfence is claiming that there are vulnerabilities in versions of software.

That is an important distinction as Wordfence’s data is often quite inaccurate and not a reliable source. The problems we have seen with their data run the gamut from falsely claiming that vulnerabilities exist to falsely claiming that real exploited vulnerabilities have been fixed. Doing the work to confirm claimed vulnerabilities before adding them to a data set, as we do, takes a lot of effort. Wordfence can give their data away because they copy inaccurate data from other providers, also providing inaccurate data for free.

If Wordfence was upfront about the lack of accuracy in their free data, that would be one thing, but they don’t warn people their data isn’t reliable.






Newsletter

Subscribe Via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.