Wordfence Intelligence is an industry-leading WordPress vulnerability database and evolving Threat Intelligence platform that contains over 12,000 records for vulnerabilities in WordPress plugins, themes, and core. The database is actively maintained by a team of highly credentialed and industry-leading vulnerability researchers and analysts with dozens of vulnerabilities added per week.
Wordfence Intelligence provides access to more than just an industry leading public interface for WordPress vulnerabilities. It also provides access to:
An API endpoint to retrieve our complete database of WordPress vulnerabilities with detailed information in JSON format
A webhook integration to receive notifications on the latest vulnerabilities added or updated in real-time to Slack, Discord, or a custom HTTP application
An incredibly user-friendly interface to search, view, and learn more about vulnerabilities affecting WordPress plugins, themes, and core
A dashboard with the latest attack data and trends seen across our network of 5 million+ sites under our protection
A bug bounty program that rewards researchers for their contributions to WordPress security
A platform providing personalized profiles for researchers to share their work and achievements in WordPress security
All completely FREE for both commercial and personal use.
Our mission with Wordfence Intelligence is to ensure that high-quality robust vulnerability information remains easily accessible and free for everyone, including enterprises.
Vulnerabilities in open-source software, such as WordPress, are discovered by a community of researchers dedicating hours to testing and reviewing code. Though our own analysts spend numerous hours maintaining the database and ensuring its accuracy, independent researchers discover the vast majority of vulnerabilities in the WordPress ecosystem. We believe it is wrong to paywall this information and make a profit off of these researchers dedicating their time and energy to making the WordPress ecosystem more secure, especially when they do so for free to give back to the community. Their work should be open and freely shared with the individuals and organizations that need this data to remain secure.
That is why we opt to make our vulnerability information free through all of our delivery methods, and reward researchers through our Bug Bounty Program. It is also why we have the best WordPress vulnerability database on the market despite not charging for any form of access to the data within it.
Highlights and Benefits of Wordfence Intelligence
Free HTTP & Slack/Discord Webhook Integration
Staying on top of the latest vulnerabilities is critical for ensuring the security of WordPress sites. While adequate security controls and our industry-leading web application firewall provide crucial protection for WordPress sites, it's still important to know when software on a site includes a known vulnerability so that plugin or theme can be updated or removed immediately. No security solution is perfect, so maintaining layers of security is critical. Site owners, enterprises, and organizations can set up Slack or Discord webhook integration to be notified of the latest vulnerabilities in a central location, and can also use our HTTP webhook integration to build a custom application to serve their customers and ensure they’re notified of vulnerabilities as soon as they are disclosed. No other WordPress vulnerability database on the market offers free access to webhook integrations.
Free API Access to our Complete Database of High Quality WordPress Vulnerability Information
Access to high quality information about vulnerabilities in WordPress products has never been easier, or more cost-effective. Wordfence Intelligence provides access to two vulnerability data feeds formatted in JSON containing all relevant vulnerability data, including affected software name and slug, a concise title and description, affected version and patched version, CVSS Score, CWE ID, and recommended remediation. This information can easily be integrated into a variety of applications to better serve the security needs of site owners, organizations, and enterprises. We've seen hosting providers implement our data to run vulnerability scans for their customers, and we've seen independent researchers and site owners build integrations for tools like WP CLI and Nuclei.
No other WordPress vulnerability database on the market provides free access to their complete database of vulnerability information maintained by industry-leading security professionals, nor is there any other database that has the quality of information we do.
Open Source Bug Bounty Program: Supporting Researchers Who Support the Security of the WordPress Ecosystem
Wordfence Intelligence has been designed by Security Researchers with Security Researchers in mind. Our bug bounty program is designed to reward researchers contributing valuable time to the security of WordPress by spending countless hours finding vulnerabilities and ensuring they get patched. In our program, vulnerabilities that take more time to find, are less common, or are highly impactful get rewarded the most, while those that are easy to find, more common, or are generally less impactful get rewarded the least. We've also made it easy for researchers to register profiles to showcase their work and achievements, all in a central location.
Wordfence Intelligence isn't just a high quality vulnerability database. On the dashboard, you can find statistics such as how many attacks we've blocked in the past 24 hours, 7 days, and 30 days, how many IPs are on our IP Threat Feed, the top 10 attacking IPs within a 24 hour period, the top 10 targeted WordPress vulnerabilities, and more. In addition, any vulnerabilities that warrant the release of it's own firewall rule display individual attack statistics below the vulnerability description so users can view attack volume if these vulnerabilities are being actively exploited.
Highly Flexible Search Engine for Vulnerabilities
One major benefit of the Wordfence Intelligence platform is the ability to conduct robust searches across our database of vulnerabilities. We are not aware of any competitors with a comparable vulnerability search engine. With our database it is possible to search by researcher, vulnerability type, vulnerability severity, title, date range, and more, making security research, journalism, and due diligence a breeze for anyone using the Wordfence Intelligence search engine.
Managed by Industry-Leading Professionals
Our vulnerability database isn't managed by a single person, or a bunch of interns. It's run and managed by some of the top WordPress vulnerability researchers in the industry. This means that all of the vulnerability data you see is reviewed and analyzed by industry professionals with numerous security certifications including CISSP, OSCP, OSWE, Security+, GWAPT, and more. You don’t need to worry about verifying whether a vulnerability is valid, or be concerned about whether the severity of the vulnerability is accurate. You can be assured that we put forth the best, most accurate information available to help site owners and organizations.
Integrated into Wordfence CLI for High-Performance Vulnerability Scanning
Wordfence Intelligence has integrated its datasets into the Wordfence CLI scanner so users have easy access to scan sites and networks for known vulnerabilities in WordPress plugins, themes, and core. This is completely free to use for commercial purposes, so hosting providers and enterprises can integrate this data as they see fit to conduct vulnerability scanning in a highly scalable and performant way for their clients.
Whether you're a security researcher, an enterprise organization, a hosting provider, or just a simple blog owner, Wordfence Intelligence is for you.
If you're looking to easily search the most comprehensive WordPress vulnerability database when conducting plugin or theme vulnerability research, or you're interested in checking out the latest attack data and trends then we recommend getting familiar with the Wordfence Intelligence public interface.
If you'd like to earn rewards for your security contributions to WordPress, or have a public profile showcasing all of your contributions and milestones, you can learn more about the Wordfence Intelligence Bug Bounty Program by clicking "Learn More," and register as a researcher today.
If you'd like to receive real-time updates on vulnerabilities added/modified/deleted to the Wordfence Intelligence WordPress Vulnerability Database, then our HTTP and Slack/Discord Webhook Integrations are a perfect fit for you. You can get started with webhooks by creating an account on wordfence.com then navigating to
If you need access to a comprehensive and complete database dump of the thousands of known vulnerabilities affecting WordPress plugins, themes, and core, formatted in JSON, to integrate into a product, service, or custom integration then you can familiarize yourself with the Wordfence Intelligence Vulnerability Data API Endpoints.
If you'd like to conduct server-level vulnerability scanning without building a custom service or integration, then get started with Wordfence CLI, a robust security scanner built to detect WordPress-based vulnerabilities and PHP/other malware in a highly performant and scalable way, today.
This website uses cookies, pixels, and similar technologies (collectively “Cookies”) to improve your browsing experience. By clicking “Accept All”, you agree to the storing of Cookies on your device and that we may share, track, store, and analyze your interactions with the website to enhance site navigation, analyze site usage, and assist in our marketing efforts. For more information on our use of cookies please review our Cookie Policy.
Cookie Options
For additional information on how this site uses cookies, please review our Privacy Policy. The cookies used by this site are classified into the following categories and can be configured below.
Strictly Necessary
Always active
The “Strictly Necessary” cookies are necessary for the Sites and Services to work properly, and cannot be disabled. They include any essential authentication and authorization cookies for the Services. If you select the “Reject All” button, or choose to do nothing, only the strictly necessary cookies are active by default.
Functional
Disabled via "Do Not Sell or Share My Information" request. This category cannot be enabled.
Your browser is sending a Global Privacy Control signal which automatically disables this category. You may change your browser settings to enable it.
These cookies allow us to remember choices you make, such as your username, language, or region. This helps provide a more personalized and consistent experience by tailoring the Services to your preferences. For example, we can remember your preferred settings or login details, so you don't have to re-enter them each time you visit.
Performance/Analytical
Disabled via "Do Not Sell or Share My Information" request. This category cannot be enabled.
Your browser is sending a Global Privacy Control signal which automatically disables this category. You may change your browser settings to enable it.
These Cookies allow us to collect certain information about how you navigate the Sites or utilize the Services running on your device. They help us understand which areas you use and what we can do to improve them.
Targeting
Disabled via "Do Not Sell or Share My Information" request. This category cannot be enabled.
Your browser is sending a Global Privacy Control signal which automatically disables this category. You may change your browser settings to enable it.
These Cookies are used to deliver relevant information related to the Services to an identified machine or other device (not a named or otherwise identifiable person) which has previously been used to visit our Sites. Some of these types of Cookies on our Sites are operated by third parties with our permission and are used to identify advertising sources that are effectively driving customers to our Sites.
Do Not Sell or Share My Personal Information
This form enables you to request that we stop selling or sharing your personal information with third parties. "Selling" includes exchanging your information for money or other benefits, while "sharing" refers to providing your data to third parties for targeted advertising purposes. For more information on how we process personal information, please review our Privacy Notice.
When you submit this form, we will:
Immediately disable retargeting and remarketing cookies on your current browser/device
Browser/Device Specific: This opt-out applies to the specific browser from which you submit the request. To opt out on additional devices or browsers, you will need to submit separate requests.
Cookie Management: You may also manage cookies directly through your browser settings, or on our Cookie Control form.
Your request has been received. We will no longer share or sell your personal information on this browser.
An error occurred while attempting to submit your request. Please try again or contact support.