Active exploitation — September 2026
Five plugin vulnerabilities are being actively exploited or freshly disclosed right now — nearly all of them let an unauthenticated attacker take full control of your server outright, no login required. Separately, PHP 8.4 is fatal-erroring sites that haven't been updated for it. The free check below tells you, plainly, whether you're affected. It does not hand you the fix for free.
SQLi → RCE · 3.25M+ installs, 65% unpatched
Object injection → RCE · CVSS 9.8, unauthenticated
File upload → RCE · CVSS 9.8, unauthenticated
File upload → RCE · CVSS 9.8, unauthenticated
File upload → RCE · CVSS 9.8, unauthenticated
Submit your URL and we'll check your site's public plugin fingerprints against the five CVEs above. You get a straight yes or no — which of the five (if any) you're running, nothing more. No version numbers, no PHP 8.4 findings, no remediation steps. That level of detail is the paid report below, on purpose: a free tool that hands over the full findings isn't actually free to us to keep producing, and it's not something we're going to give away and then bill you for after the fact.
Two separate deliverables, on purpose — a free flag, and a paid report.
Public plugin fingerprint checked against the five active CVEs. You get a yes/no, same business day.
$200 gets you the full breakdown — exact versions, severity, and the PHP 8.4 compatibility scan if you share source.
Take the report to your own team, or have us apply the fix and keep watching the server going forward.
The free check above is not on this list — it's a yes/no gate, not a tier.
Starter
$200
Full diagnostic report: exact versions, CVE matches, PHP 8.4 findings. This is what the free check above does not include.
Standard
$450
Report, plus patching every flagged plugin to a safe version and a re-scan to confirm it's closed.
Advanced
from $1,800
Incident response — for a site already showing signs of compromise, not just exposure. Scoped after the free check.
Ongoing
$750/mo
We keep watching the server this runs on going forward — not a plugin-alert email, actual server-level checks.
Skip the free check and go straight to the $200 report — tell us your URL and we'll invoice and deliver the same business day.