Skip to content
  • Contact us: +34 944 58 06 58
  • Plesk Partner Program
  • Plesk Lifecycle Policy
  • Blog
  • Contact us
  • Plesk 360
  • Contact us: +34 944 58 06 58
  • Plesk Partner Program
  • Plesk Lifecycle Policy
  • Blog
  • Contact us
  • Plesk 360
  • Solutions
    By Role
    • Developers
    • Content Managers
    • Digital Agencies
    • IT Admins
    • Web Hosters
    • Hyperscalers
    • Developers
    • Content Managers
    • Digital Agencies
    • IT Admins
    • Web Hosters
    • Hyperscalers
    By Edition
    • Web Admin Edition
    • Web Pro Edition
    • Web Host Edition
    • Business & Collaboration
    • Plesk WP Edition
    • Web Admin Edition
    • Web Pro Edition
    • Web Host Edition
    • Business & Collaboration
    • Plesk WP Edition
    By Cloud
    • Amazon Web Services
    • Microsoft Azure
    • Alibaba Cloud
    • GCP Marketplace
    • Vultr
    • DigitalOcean
    • Linode
    • UpCloud
    • Amazon Web Services
    • Microsoft Azure
    • Alibaba Cloud
    • GCP Marketplace
    • Vultr
    • DigitalOcean
    • Linode
    • UpCloud
    Partner Program
    Exclusive discounts, benefits and exposure to take your business to the next level
    Become a partner
    • By Role
      • Developers
      • Content Managers
      • Digital Agencies
      • IT Admins
      • Web Hosters
      • Hyperscalers
    • By Edition
      • Web Admin Edition
      • Web Pro Edition
      • Web Host Edition
      • Business & Collaboration
      • WP Edition
    • By Cloud
      • Amazon Web Services
      • Microsoft Azure
      • Alibaba Cloud
      • GCP Marketplace
      • Vultr
      • DigitalOcean
      • Linode
      • UpCloud
    • Partner Program
      • Partner Program
  • Product
    Explore Features
    • Everyone
    • Admins & Web Hosters
    • Developers
    • Designers & Agencies
    • Plesk Features
    • Everyone
    • Admins & Web Hosters
    • Developers
    • Designers & Agencies
    • Plesk Features
    Key Topics
    • SocialBee
    • WP Toolkit
    • Sitejet Builder
    • SEO Toolkit
    • Joomla! Toolkit
    • Plesk Premium Email
    • Plesk Email Security
    • SocialBee
    • WP Toolkit
    • Sitejet Builder
    • SEO Toolkit
    • Joomla! Toolkit
    • Plesk Premium Email
    • Plesk Email Security
    Feature Packs
    • Business & Collaboration
    • WP Pack
    • Hosting Pack
    • Power Pack
    • Language Pack
    • Business & Collaboration
    • WP Pack
    • Hosting Pack
    • Power Pack
    • Language Pack
    Featured Extension
    SocialBee
    • Explore Features
      • Everyone
      • Admins & Web Hosters
      • Developers
      • Designers & Agencies
      • Plesk Features
    • Key Topics
      • SocialBee
      • WP Toolkit
      • Sitejet Builder for Plesk
      • SEO Toolkit
      • Plesk Premium Email
      • Plesk Email Security
    • Feature Packs
      • Business & Collaboration
      • WP Pack
      • Hosting Pack
      • Power Pack
      • Language Pack
    • Featured Extension
      • Extension
  • Pricing
  • Extensions
  • Help Center
  • More
    • Careers
    • Events
    • Plesk University
  • FREE TRIAL
  • Solutions
    • By Role
      • Developers
      • Content Managers
      • Digital Agencies
      • IT Admins
      • Web Hosters
      • Hyperscalers
    • By Edition
      • Web Admin Edition
      • Web Pro Edition
      • Web Host Edition
      • Business & Collaboration
      • WP Edition
    • By Cloud
      • Amazon Web Services
      • Microsoft Azure
      • Alibaba Cloud
      • GCP Marketplace
      • Vultr
      • DigitalOcean
      • Linode
      • UpCloud
    • Partner Program
      • Partner Program
  • Product
    • Explore Features
      • Everyone
      • Admins & Web Hosters
      • Developers
      • Designers & Agencies
      • Plesk Features
    • Key Topics
      • SocialBee
      • WP Toolkit
      • Sitejet Builder
      • SEO Toolkit
      • Joomla! Toolkit
      • Plesk Premium Email
      • Plesk Email Security
    • Feature Packs
      • Business & Collaboration
      • WP Pack
      • Hosting Pack
      • Power Pack
      • Language Pack
    • Featured Extension
      • SocialBee
  • Pricing
  • Extensions
  • Help center
  • More
    • Careers
    • Events
    • Plesk University
    • Blog
    • Plesk Partner Program
    • Contact Us
  • FREE TRIAL
  • Solutions
    • By Role
      • Developers
      • Content Managers
      • Digital Agencies
      • IT Admins
      • Web Hosters
      • Hyperscalers
    • By Edition
      • Web Admin Edition
      • Web Pro Edition
      • Web Host Edition
      • Business & Collaboration
      • WP Edition
    • By Cloud
      • Amazon Web Services
      • Microsoft Azure
      • Alibaba Cloud
      • GCP Marketplace
      • Vultr
      • DigitalOcean
      • Linode
      • UpCloud
    • Partner Program
      • Partner Program
  • Product
    • Explore Features
      • Everyone
      • Admins & Web Hosters
      • Developers
      • Designers & Agencies
      • Plesk Features
    • Key Topics
      • SocialBee
      • WP Toolkit
      • Sitejet Builder
      • SEO Toolkit
      • Joomla! Toolkit
      • Plesk Premium Email
      • Plesk Email Security
    • Feature Packs
      • Business & Collaboration
      • WP Pack
      • Hosting Pack
      • Power Pack
      • Language Pack
    • Featured Extension
      • SocialBee
  • Pricing
  • Extensions
  • Help center
  • More
    • Careers
    • Events
    • Plesk University
    • Blog
    • Plesk Partner Program
    • Contact Us
  • FREE TRIAL

Plesk WP Toolkit 5.8 Release: Site Vulnerability Scan, Autodetection WordPress Login URL, and More

  • By Andrey Kugaevskiy
  • December 13, 2021
  • Learning, Plesk news and announcements, Product and technology
4
Minutes

The Plesk WP Toolkit 5.8 is now available. This release comes with the biggest game charger feature of the year – the Site Vulnerability Scan. Let’s have a look at why we’re so excited about this feature going forward:

Site Vulnerability Scan

WP Toolkit can now regularly scans active plugins, themes, and WordPress versions to identify known vulnerabilities, using information provided by our friendly partners at Patchstack. Before we go further into the details of this feature, let’s quickly go through some numbers to understand how much of a game changer this really is:

First of all, WordPress is used on roughly 43% of all sites on the internet, with the figure going up to 65% for sites made on a CMS (content management system). These figures are constantly growing, meaning that WordPress is becoming an even bigger target for hackers every day. Case in point:

  • Cybercrime is up 600% due to the COVID-19 pandemic
  • Over 18 million websites are infected with malware each week
  • 25% of top WordPress plugins are flagged with critical vulnerabilities
  • 60% of data breach victims said they were breached due to an unpatched known vulnerability where the patch was not applied

We can go on and on quoting various security-related stats, but the point is clear: addressing vulnerabilities is arguably the most important thing you can do for your site.

To make the internet a safer place for all, WP Toolkit is now introducing an automated vulnerability scan. Every hour we’re examining the Patchstack database to identify whether there’s a new vulnerability reported. Every hour we are verifying if there are any plugins, themes, or WordPress sites on a given server with known vulnerabilities. Once a vulnerability is detected, WP Toolkit will mark the site in the interface, letting site admins know they should take action. Since a picture is worth a thousand words, the screenshots below tell the story for us.

This is what site admins will see when they access WP Toolkit and one of their sites has a known vulnerability:

WordPress Toolkit

If you only have one site, or you have expanded a site in the list, there will be an additional indication about the presence of vulnerabilities:

Site Vulnerability Scan

If you open the Plugins or Themes tabs, you will be able to see which ones are vulnerable:

You will also see this information when opening the global Plugins or Themes tabs:

Site Vulnerability Scan Plugins
Once you follow the Call-To-Action prompts, the following menu will open in the case of a single site:
Security Measures

As you can see, the old Security Measures menu has been moved to a separate tab. This was done because it contains rarely used operations (even though they are important). Furthermore, since the site admins will be using this more frequently, the first (and default) tab now contains vulnerability information.

The options for site admin are self-explanatory and can be seen in the screenshots above. However, If you have activated the Security menu for multiple sites, you will be seeing a different picture:

Security WordPress Vulnerabilities
This menu allows you to see and address vulnerabilities on all your sites at once. It looks and works just like other mass management menus in the WP Toolkit, with one important difference: you can switch from per-site view to per-vulnerability view, which groups the information by vulnerabilities:
WordPress Vulnerabilities Update

You can also switch between different views on the fly, giving everyone a convenient way to review and solve the issues on their sites.

To summarize, the Site Vulnerability Scan introduced in the 5.8 release provides site administrators with the necessary tools to quickly assess the situation and take appropriate measures going forward. Besides our continuous effort at Plesk to improve user experience by monitoring user feedback, we already have a bunch of improvements lined up for the next WP Toolkit releases.

Furthermore, in case you were wondering, this feature is completely free for all WP Toolkit users. We hope this feature will bring a smile to web professionals all over the world.

This feature will be gradually rolled out on Plesk to assess its performance going forward, so if you don’t see this feature appear on your server immediately, don’t worry! It will appear soon.

While the Site Vulnerability Scan was the feature and highlight of this release, the Plesk WP Toolkit 5.8 furthermore includes several minor changes that are worth a mention:

Autodetection of WordPress login URL

Many WordPress sites change their login URL to protect themselves from automated bot attacks looking to bruteforce a password or two. WP Toolkit has supported this feature, but one had to manually input the new login URL in order to use the one-click login feature of WP Toolkit. Now we’ve figured out a way to detect the login URL without asking site admins, so we’ve implemented this change to make your lives a bit easier:

Changes under the hood & various improvements

Plesk WP Toolkit 5.8 includes a variety of other changes that cannot be displayed via screenshots, so here’s a brief bullet list:

  • Blocklist now works with CLI operations and doesn’t check updates for blocked plugins.
  • The Scan procedure no longer rescans sites already added to WP Toolkit, meaning it now works much faster.
  • The Smart Updates procedure is now more ‘eco-friendly’, meaning it no longer leaves empty folders behind itself.
  • The performance of installing and removing WordPress sites on servers with a lot of connected databases has improved significantly.
  • Performance of the Action Log was also improved when working with very large log files.
  • In comparison to the previous release, twice as many customer bugs were fixed.

What’s Next?

We are planning to improve the Site Vulnerability Scan even further for email along with new auto-update features and more! Finally, we are working on introducing a modern API that should eventually cover all the relevant WP Toolkit functionalities.

With that said, we hope we’ll see you again soon for yet another quick WP Toolkit update. Thank you kindly for your attention, and see you next time!

Tweet
Share
Share
Email
0 Shares
Picture of Andrey Kugaevskiy

Andrey Kugaevskiy

Andrey is the Program Manager at Plesk in charge of everything to do with the Plesk WP Toolkit.

3 Comments

  1. Thierry
    Thierry
    Jan 17, 2022 / 10:51 am # Link Reply

    The vulnerability scan for the websites is a great tool. gives a quick overview if there are any issues to fix and with one click you can solve it. also for people who are quite new to plesk, it is very intuitive and guarantees the security, which is nowadays getting more and more important.

  2. giuseppe amodio
    giuseppe amodio
    Apr 20, 2022 / 3:36 pm # Link Reply

    Hello,

    I have Plesk with my dedicated server used with only one wordpress website.

    I have added WordPress toolkit but it applies in automated way security measures (that are untickable) that stop the website working, so I have switched off all the toolkit adding [ext-wp-toolkit]
    enabled=off to Panel.ini .

    Is there a way to switch off the automated security measures activating them one by one?

    Many thanks,

    Giuseppe

    • Louis Vanfraechem
      Louis Vanfraechem
      May 26, 2022 / 12:26 pm # Link Reply

      Hi there,

      We kindly suggest you submit a request with our Plesk Support, as they will be able to look at your specific case. Hope this can help.

Add a CommentCancel Reply

Your email address will not be published. Required fields are marked *

More results...

Generic filters
Exact matches only
Search in title
Search in content
Search in excerpt

GET LATEST NEWS AND TIPS

  • Yes, please, I agree to receiving my personal Plesk Newsletter! WebPros International GmbH and other WebPros group companies may store and process the data I provide for the purpose of delivering the newsletter according to the WebPros Privacy Policy. In order to tailor its offerings to me, Plesk may further use additional information like usage and behavior data (Profiling). I can unsubscribe from the newsletter at any time by sending an email to [email protected] or use the unsubscribe link in any of the newsletters.

  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form

Related Posts

Securing the WordPress Frontier with WP Guardian

Read More »

Introducing WP Guardian Vulnerability Protection: Now available for WP Toolkit

Read More »

What is Cloudflare and How To Set It Up For Your Site?

Read More »

Knowledge Base

IIS Web Server Settings – Directory Security Settings

Read More »

Windows Accounts Used by Plesk to Manage Hosted Windows Objects

Read More »

WP Toolkit – Preinstalling WordPress on Users’ Domains

Read More »

WP Toolkit – Updating WordPress Installations

Read More »

WP Toolkit – Securing WordPress

Read More »

Industry
Partners

industry-partner_ALIBABA
industry-partner_GOOGLEPARTNER
industry-partner_MICROSOFT
industry-partner_REDHAT-r2
industry-partner_ALIBABA
industry-partner_AUTOMATTIC
industry-partner_AWS
industry-partner_DIGITALOCEAN
industry-partner_SCALEWAY
Follow us:
Facebook Twitter Linkedin Youtube Github

COMPANY

About Plesk
Our Brand
Legal
Careers
Impressum

PRODUCT

Pricing 
Extensions
What’s new

KNOWLEDGE BASE

Documentation
Help Center
Migrate to Plesk
Contact Us
Hosting Wiki
Preview releases

PROGRAMS

Contributor Program NEW
Partner Program
Affiliate ProgramNEW

COMMUNITY

Blog
Forums 
Plesk University

First defaul

Company

About Plesk
Our Brand
Legal
Careers
Impressum

PRODUCT

Pricing 
Extensions
What’s new

KNOWLEDGE BASE​

Documentation
Help Center
Migrate to Plesk
Contact Us
Hosting Wiki
Preview releases

PROGRAMS​

Contributor Program NEW
Partner Program
Affiliate ProgramNEW

COMMUNITY​

Blog
Forums
Plesk University

Follow us:
Facebook Twitter Linkedin Youtube Github

© 2025 WebPros International GmbH. All rights reserved. Plesk and the Plesk logo are trademarks of WebPros International GmbH.

Managed with love with Plesk WP Toolkit