Vulnerability and package context

Know which components deserve your attention first.

Component Trust combines installed-version inventory, known vulnerability intelligence, repository availability and Rescue Center context across plugins, themes and MU-plugins.

Vulnerability intelligenceRepository statusMU-plugin inventoryRescue Center sync
COMPONENT TRUSTINVENTORY CURRENT
Known vulnerabilityInstalled version affected
Repository unavailableManual trust review required
Package verifiedOfficial source available

Known vulnerability monitor

Match installed versions against current vulnerability intelligence with explicit affected ranges.

Repository and source context

Show whether a component can be verified against an official source or needs manual review.

Recovery connection

Open affected components in the Rescue Center and choose update, compare, quarantine or investigation paths.

Trust is contextual

A version number is not the whole security story.

A component can be vulnerable, removed from a repository, modified locally, custom-built or simply unknown to the public ecosystem. Nexus keeps these states separate.

  • Plugin, theme and MU-plugin inventory
  • Version-aware vulnerability matching
  • Repository presence and official-source checks
  • Last-good vulnerability cache with safe refresh fallback
Capability map

A clearer component risk map.

The module helps administrators prioritize updates and investigations rather than react to one undifferentiated alert list.

Vulnerability intelligence

Compare installed component versions with affected ranges and available advisory context.

  • Installed-version matching
  • Severity and fixed-version context
  • Manual component checks

Repository verification

Identify whether the installed package has an official WordPress.org source suitable for comparison.

  • Removed or closed repository state
  • Official package availability
  • Private component caution

Complete inventory

Include active, inactive and must-use components so hidden operational code is not omitted.

  • Plugins and themes
  • MU-plugins
  • Version and source metadata

Rescue Center integration

Move from the component record to integrity comparison, update, evidence or recovery tools.

  • Targeted scan routes
  • Package comparison
  • Repair context
Operational flow

From installed inventory to the right action.

Different component states require different responses.

01

Inventory

Nexus identifies installed plugins, themes and must-use components.

02

Match

Versions and repository status are compared with current cached intelligence.

03

Prioritize

Affected, unverifiable and changed components are separated by evidence.

04

Act

The administrator updates, compares, scans or documents an accepted exception.

What Nexus does

Explain component risk precisely.

  • Keep vulnerable and compromised states separate
  • Retain last-good data after temporary feed failure
  • Include inactive and must-use components
  • Show fixed-version or repository context when available
What Nexus avoids

Turn every unknown component into malware.

  • Assume private plugins are malicious
  • Discard cached intelligence after one timeout
  • Hide affected-version logic
  • Claim a clean repository version proves the running files are clean
Feature questions

What buyers usually want to know.

Does Component Trust block vulnerable plugins automatically?

No. It provides vulnerability and trust context plus routes to safer actions. Automatic deactivation could break a live site and is not the default behavior.

What happens when the remote vulnerability feed times out?

Nexus keeps the previous last-good cache, uses retry/backoff behavior and avoids replacing useful data with an empty result.

Are inactive plugins included?

Yes. Inactive code can still matter if it remains installed or is reachable through another weakness.

How are custom plugins handled?

They are identified as custom or without an official comparison source. That state calls for a trusted local baseline or manual review, not an automatic malware verdict.

Lumiverse Nexus PRO

Prioritize component risk with context—not panic.

Component Trust and vulnerability intelligence are included in Nexus PRO.