[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f7l8-AvxdaEkQ28kQPGsQgufw0oNBtG9f-qIXMYhQvLA":3},{"slug":4,"display_name":4,"profile_url":5,"plugin_count":6,"total_installs":7,"avg_security_score":8,"avg_patch_time_days":9,"trust_score":10,"computed_at":11,"plugins":12},"trgomez","https:\u002F\u002Fprofiles.wordpress.org\u002Ftrgomez\u002F",1,0,100,30,94,"2026-08-25T01:47:48.761Z",[13],{"slug":14,"name":15,"version":16,"author":4,"author_profile":5,"description":17,"short_description":18,"active_installs":7,"downloaded":19,"rating":7,"num_ratings":7,"last_updated":20,"tested_up_to":21,"requires_at_least":22,"requires_php":23,"tags":24,"homepage":30,"download_link":31,"security_score":8,"vuln_count":7,"unpatched_count":7,"last_vuln_date":32,"fetched_at":33},"pura-vida-vulnerability-scanner","Pura Vida Vulnerability Scanner","1.1.0","\u003Cp>Pura Vida Vulnerability Scanner checks everything installed on your site, including plugins, themes and WordPress core, against the \u003Cstrong>Wordfence Intelligence\u003C\u002Fstrong> vulnerability database, audits your site’s security posture, and shows you exactly what is at risk and how to fix it.\u003C\u002Fp>\n\u003Cp>It does not invent findings. It correlates your installed software and configuration against authoritative public sources (Wordfence Intelligence, CVE\u002FMITRE, the WordPress.org update channel) and live checks of your own server.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Security overview\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>The dashboard opens with an at-a-glance status table covering:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>WordPress Version: OK \u002F Warning\u003C\u002Fli>\n\u003Cli>Vulnerable Plugins: OK \u002F Critical \u002F High \u002F Medium\u003C\u002Fli>\n\u003Cli>Missing Headers: Present \u002F Missing \u002F N\u002FA (HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy)\u003C\u002Fli>\n\u003Cli>SSL: Valid \u002F Expiring soon \u002F Expired \u002F N\u002FA (certificate expiry)\u003C\u002Fli>\n\u003Cli>DNS: OK \u002F Issues \u002F N\u002FA\u003C\u002Fli>\n\u003Cli>Email Security: SPF and DMARC (DKIM is selector-specific)\u003C\u002Fli>\n\u003Cli>CDN\u002FWAF: Detected \u002F Not detected \u002F N\u002FA\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>What it does\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Inventories every installed plugin, theme and the WordPress core version.\u003C\u002Fli>\n\u003Cli>Matches each item and version against a continuously updated vulnerability feed.\u003C\u002Fli>\n\u003Cli>Shows severity (CVSS), the CVE identifier, a description and the recommended fix for every finding.\u003C\u002Fli>\n\u003Cli>Audits your configuration and lists prioritized hardening recommendations (2FA, updates, HTTPS, file editor, and more).\u003C\u002Fli>\n\u003Cli>Optional scheduled scans with email alerts when new critical\u002Fhigh issues appear.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Data sources\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Wordfence Intelligence Vulnerability Data Feed: free for personal and commercial use; includes CVE (MITRE) and CVSS information.\u003C\u002Fli>\n\u003Cli>CVE (MITRE Corporation): the canonical vulnerability identifiers.\u003C\u002Fli>\n\u003Cli>WordPress.org update channel: available core, plugin and theme updates.\u003C\u002Fli>\n\u003Cli>Live site checks performed by the plugin: HTTP headers, SSL, DNS, SPF\u002FDMARC and CDN\u002FWAF.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>This product includes data that may be copyrighted by Defiant Inc. (Wordfence Intelligence) and by the MITRE Corporation (CVE®); their notices are displayed alongside the relevant findings.\u003C\u002Fp>\n\u003Cp>Developed by Pura Vida Design Studio, Open Source Security & Website Tools (https:\u002F\u002Fpuravidadesignstudio.com\u002F).\u003C\u002Fp>\n\u003Ch3>External services\u003C\u002Fh3>\n\u003Cp>This plugin connects to one external service to function: the Wordfence Intelligence Vulnerability Data Feed.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Wordfence Intelligence Vulnerability Data Feed (Defiant Inc.)\u003C\u002Fstrong>\u003Cbr \u002F>\nThis plugin downloads the public WordPress vulnerability database from Wordfence in order to match it against the plugins, themes and core version installed on your site.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>What is sent: your Wordfence Intelligence API key (in the request Authorization header) and your site’s URL (in the request User-Agent header), sent to https:\u002F\u002Fwww.wordfence.com\u002F. The list of plugins and themes installed on your site is NOT transmitted; matching is performed locally on your own server.\u003C\u002Fli>\n\u003Cli>When it is sent: when you run a manual scan, and when a scheduled scan runs (about once per day). The downloaded database is cached locally for 24 hours so the service is contacted at most about once per day.\u003C\u002Fli>\n\u003Cli>Service terms: https:\u002F\u002Fwww.wordfence.com\u002Fwordfence-intelligence-terms-and-conditions\u002F\u003C\u002Fli>\n\u003Cli>Privacy policy: https:\u002F\u002Fwww.wordfence.com\u002Fprivacy-policy\u002F\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>The plugin also performs read-only checks against your own site for the Security Overview: a loopback HTTP request to your own home URL (to inspect response headers and detect a CDN\u002FWAF) and DNS lookups for your own domain (to check DNS resolution and SPF\u002FDMARC records). These query your own domain and public DNS only; no data is sent to any third party.\u003C\u002Fp>\n","Scan your plugins, themes and WordPress core against trusted vulnerability databases and get a clear, prioritized security overview.",132,"2026-06-16T17:46:00.000Z","7.0.2","5.6","7.2",[25,26,27,28,29],"hardening","malware","scanner","security","vulnerability","","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fpura-vida-vulnerability-scanner.1.1.0.zip",null,"2026-07-22T17:31:50.256Z"]