Vulnerabilities
Opt-in daily match of installed versions against a vulnerability feed (fixture until live API).
What it does
Builds an inventory of core, plugins, and themes. When you opt in, matches versions against Stalza’s feed (or a local fixture) and shows advisories.
How it works
Off by default — no outbound requests until opt-in. Refresh from the Vulnerabilities tab or the daily cron.
Settings
- Allow vulnerability matching — Settings tab (explicit opt-in)
What findings mean
Kind vuln.advisory with severity and advisory link when available. Stale badge when cache is old.
Recommended action
Update the affected component. Re-run match after upgrades.