Please use the “Print” function at the bottom of the page to create a PDF.
Valid for WordPress created after September 2022.
To ensure the highest level of security for your WordPress installation, IONOS is introducing a new feature in its WordPress Security Plugin – the security scan. This article provides you with details about the IONOS Security Plugin's scanning feature.
What is the security scan?
The WordPress security scan is a feature integrated into the WordPress plugin, “IONOS Security”. The security scan utilizes the extensive database from WPScan – the leading source of information on WordPress security vulnerabilities – to check your WordPress installation for security risks. The scan covers plugins, themes, and the WordPress core itself.
Availability and provision
For new installations, the “IONOS Security” plugin is installed automatically. If the plugin is not installed on your site, you can simply install it via the plugin management section.
For information on installing plugins in WordPress, see: Installing plugins and themes in WordPress
How does the scan work?
Every day, the plugin automatically runs a scan to check for vulnerabilities. The results are categorized into three groups:
- Green: No vulnerabilities found
- Yellow: Low to medium-risk vulnerabilities found
- Red: High-risk vulnerabilities found
You will receive notifications about any vulnerabilities found directly in the WordPress admin panel and by email, so that you can respond quickly to potential threats.
View scan results
To view the scan results, click on IONOS > Tools & Security in the left-hand menu of the WordPress admin panel and look at the Website security section.
Recommended measures
If a vulnerability is detected, the plugin provides recommendations, such as:
- Install an update or patch: If an update is available for a plugin or theme, it should be installed as soon as possible.
- Deactivate the plugin or theme: If no update is available, it is recommended that you temporarily deactivate the plugin or theme until the provider releases a suitable update.
Note
Please note that IONOS does not update or delete any plugins or themes on behalf of the customer. It is your responsibility to take the recommended actions or, in the event of any issues, to deactivate or uninstall the relevant plugin. If necessary, you can also contact the plugin developer or seek help via wordpress.org or the community.
Additional security measures
The security scan is also carried out when installing new themes and plugins. Depending on the results, installations may either be blocked if serious issues are found, or a warning may be displayed if only high-risk installations are at risk.