Known vulnerability monitor
Match installed versions against current vulnerability intelligence with explicit affected ranges.
Component Trust combines installed-version inventory, known vulnerability intelligence, repository availability and Rescue Center context across plugins, themes and MU-plugins.
Match installed versions against current vulnerability intelligence with explicit affected ranges.
Show whether a component can be verified against an official source or needs manual review.
Open affected components in the Rescue Center and choose update, compare, quarantine or investigation paths.
A component can be vulnerable, removed from a repository, modified locally, custom-built or simply unknown to the public ecosystem. Nexus keeps these states separate.
The module helps administrators prioritize updates and investigations rather than react to one undifferentiated alert list.
Compare installed component versions with affected ranges and available advisory context.
Identify whether the installed package has an official WordPress.org source suitable for comparison.
Include active, inactive and must-use components so hidden operational code is not omitted.
Move from the component record to integrity comparison, update, evidence or recovery tools.
Different component states require different responses.
Nexus identifies installed plugins, themes and must-use components.
Versions and repository status are compared with current cached intelligence.
Affected, unverifiable and changed components are separated by evidence.
The administrator updates, compares, scans or documents an accepted exception.
No. It provides vulnerability and trust context plus routes to safer actions. Automatic deactivation could break a live site and is not the default behavior.
Nexus keeps the previous last-good cache, uses retry/backoff behavior and avoids replacing useful data with an empty result.
Yes. Inactive code can still matter if it remains installed or is reachable through another weakness.
They are identified as custom or without an official comparison source. That state calls for a trusted local baseline or manual review, not an automatic malware verdict.
Component Trust and vulnerability intelligence are included in Nexus PRO.