Every WordPress and Bedrock site on FlyWP is automatically scanned for known vulnerabilities in its plugins, themes, and WordPress core — at no extra cost, and with no setup required.
What the free scanner does
FlyWP runs a lightweight inventory of your site’s installed plugins, themes, and core version over SSH, then matches it against a vulnerability advisory feed (powered by Patchstack) that FlyWP syncs hourly. This happens automatically:
- A scan runs daily for every eligible site.
- You can also trigger a scan on demand—go to Site → Security → Vulnerabilities and click Scan Now.
- Findings are listed with the affected plugin/theme/core component, the vulnerability’s name, CVE (if available), and severity (Critical, High, Medium, Low, or Unknown).
- A weekly digest email summarizes any new findings across your sites.

The free scanner does not require installing anything on your site — it’s a read-only inventory check, so there’s nothing to configure.
If you’d rather not scan a particular site automatically, you can turn off automated scanning for it from the same Vulnerabilities page.
Free vs. FlySecurity Pro
The free scanner tells you a vulnerability exists. For Critical, High, and Medium severity findings, the specific “fixed in” version is locked until the site has active protection — this is the one piece of detail reserved for FlySecurity Pro. Low and Unknown severity findings, and all other details (name, CVE, affected component), are always fully visible on the free tier.

FlySecurity Pro goes further than reporting — it actively virtually patches vulnerable plugins, themes, and core via Patchstack, protecting your site even before an official update is released. See the FlySecurity Pro guide for pricing, the 30-day trial, and how to enable it.
Note: FlySecurity Pro’s managed protection is only available for standard, single-install WordPress sites — Bedrock sites and WordPress multisite installs can still use the free scanner, but can’t currently enroll in managed protection.
Managing scans across your whole team
If you manage multiple sites, Team → Vulnerable Sites gives you a single table of every scannable site with its vulnerability counts and protection status, so you don’t have to check each site individually. See Team Vulnerable Sites for details.