Current WP Toolkit versions use Security Risk ratings to help identify WordPress installations and components that need attention.
WP Toolkit 6.10 replaced the previous Vulnerabilities widget with Security Risk and renamed the previous WordPress Vulnerabilities area to Vulnerable Components.
What can be affected?
- WordPress core.
- Installed plugins.
- Installed themes.
When a risk is reported
- Open the Security Risk information and identify the affected component.
- Check whether a supported update is available.
- Create a backup when appropriate.
- Install the update and test the website.
- Remove unused plugins or themes that are no longer required.
A disabled component can still represent unnecessary code on the server, so unused software should generally be removed instead of abandoned in place.
Security Risk information is separate from WP Toolkit hardening. Security is best approached as multiple layers: current software, strong credentials, backups, careful administration, and prompt attention to known vulnerabilities.