Changelog
What changed on WP Alerts and when. We build in the open: improvements, fixes and new features are listed here as they ship.
Version-aware alerts, reopened plugins, dark/light mode
6 September 2026- NEW Alerts and the dashboard now compare the installed version of every plugin and theme with the affected range. You only hear about vulnerabilities that hit the version you actually run.
- NEW Site pages show only active issues; older, already-fixed issues are folded away behind a "show" link.
- NEW When a plugin that was closed on WordPress.org comes back with a newer version, you get a note that it can be updated.
- NEW Closed plugins are re-verified against WordPress.org (daily for recent closures, monthly after three months), so a lifted closure is picked up automatically.
- NEW Light theme toggle in the header; your choice is remembered.
- NEW Admin: overview of all monitored sites with per-site detail, email settings for the promotional block, and a settings page.
- IMPROVED Closed-plugin reminders are sent once and then weekly instead of every four hours. Premium plugins that were never on WordPress.org are no longer reported as "removed".
- IMPROVED WP Alerts Scanner plugin 1.2.0: sends daily and right after every update, reports active state and PHP version, and shows an update notice when a newer version is available.
- FIXED Vulnerability import from WPVulnerability had been failing since the API moved; it now uses the new API and imports per plugin and theme.
- FIXED Spam registrations: honeypot and timing checks on the forms, and accounts that never verify their email are removed after 72 hours.
- FIXED Bounced and complained email addresses are synced from Amazon SES and never mailed again.
Alert preferences, public plugin pages, email log
6 September 2026- NEW Choose a minimum severity for alert emails and pause alerts per site while it stays monitored.
- NEW Webhook support: every alert is also posted as JSON to a URL of your choice (works with Slack and Discord out of the box).
- NEW Public pages per plugin and theme with all known vulnerabilities, WordPress.org release info and closure status.
- NEW "Resolved" mails: once an alerted vulnerability no longer affects your sites, you hear that too.
- NEW Site pages flag plugins without a release for two years or tested far behind your WordPress version, and show the PHP version's support status.
- IMPROVED URL scans now detect plugin and theme versions from asset URLs, readme.txt and style.css, so far more vulnerabilities can be matched without the plugin.
- IMPROVED This changelog is now managed from the admin; entries can be kept private.
- IMPROVED Admin email log with message preview and resend.
- SECURITY Two-factor authentication with an authenticator app, including recovery codes, for every account.
- NEW Printable security report per site: score, open issues, what was resolved, component inventory and recommendations. Save it as PDF from the print dialog.
- NEW Teams for agencies and freelancers: share monitored sites with colleagues, group sites per client, and every member receives the alerts with their own preferences.
Multiple vulnerability sources
23 August 2026- NEW Vulnerabilities are aggregated from WPVulnerability, NVD/NIST, ENISA EUVD and CVE.org.
- NEW Personal alerts, daily newsletter, site scanner and the WP Alerts Scanner plugin.
Missing something or found a bug? Mail hallo@kyzoe.be.