Since the MainWP Vulnerability Checker Extension 4.1, MainWP NVD API that uses the NVD Nist API to find potential vulnerabilities on your child sites is available for all users.
MainWP NVD API requires MainWP Dashboard and MainWP Child 4.1.7!
The NVD is the U.S. government repository of standards-based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables the automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, misconfigurations, product names, and impact metrics.
This API is free so it’s a good alternative for users that don’t have an active subscription to the WPVulnDB (https://wpscan.com/).
To enable the MainWP NVD API,
- Go to the MainWP > Extensions > Vulnerability Checker > Settings page,
- Find the Select Service option and select MainWP NVD API,
- Save Settings.
Once the API Service has been selected, you can run the scan:
- Go to the MainWP > Extensions > Vulnerability Checker > Overview page,
- Click the Check All Sites button
NVD Nist API Database can not be searched by plugin/theme slug (which would be unique for each item) and assure better accuracy, it can be searched by keyword only. This means that the API can return some false-positive results. For some vulnerabilities, the NVD Nist API lacks the “Fixed in version” info which can lead to extension showing vulnerabilities that already have been resolved. In order to remove false positives and get accurate results, you can use the “Ignore” function for the detected vulnerabilities if you recognize them as false-positive.