Think Build Implement Repeat
London, UK +44 7367 067226
WhatsApp FOLLOW f in X
  1. Home
  2. Blog
  3. A Plugin Vulnerability Is Announced. How Do We Quickly Tell Which of Our Client Sites Are Affected?
Problems We Solve

A Plugin Vulnerability Is Announced. How Do We Quickly Tell Which of Our Client Sites Are Affected?

Web design agencies cannot quickly say which client sites run a given plugin, PHP version or host. We build a live inventory of every site's stack.

Updated 3 min readBy SpiderHunts Technologies

Free estimateNo obligation

Get a free estimate

Tell us what you need. A senior engineer reads every enquiry.

Takes under a minute. We never share your details.

  • Free consultation
  • No commitment
  • NDA on request

Prefer to talk? Book a free 30-minute call →

Quick answer — TL;DR

When a serious plugin vulnerability is announced, or a host retires a PHP version, a studio needs to know at once which client sites are affected. Most cannot answer without logging into each site. We build a live inventory of every client site you look after, recording platform, versions, plugins, host, PHP version, DNS and who is responsible, so questions like that are a search rather than a morning of logins.

A security advisory on a Wednesday

A popular plugin announces a serious vulnerability. The studio knows it has used that plugin, but on which sites? Some are in the management dashboard, some are not. Some are hosted by the studio, some by clients. A developer starts logging into sites one by one, and by the end of the day has checked most of them.

A week later the host announces it is retiring an older PHP version. Same question, same process. Then a client asks which of their three sites still use the old page builder. Same again.

Why nobody has the full picture

  • Sites were built over many years, by different people, on different stacks.
  • Only some sites are connected to a management tool, often the ones on maintenance plans.
  • Sites hosted by clients or other providers are outside the studio's own servers.
  • Information like PHP version, DNS host and page builder is scattered or unrecorded.
  • Responsibility for each site is informal, so questions go to whoever remembers.

The studio knows each site well when it builds it, and less well every month after that.

What not knowing costs

Response to security issues is slow, which is exactly when speed matters. Developer time is spent logging into sites to answer simple questions. Some sites are missed entirely, and they are usually the ones most at risk. Clients who ask about their exposure get a slow or vague answer.

The site inventory we build

  1. Every client site you look after is listed, whether you host it or not, with client, plan and responsible developer.
  2. For sites you manage, platform, version, plugins, themes and PHP version are read regularly through your management tool or a small reporting plugin.
  3. For sites you do not manage directly, a public scan records what can be seen from outside.
  4. Hosting, DNS provider and mail setup are recorded from DNS lookups and your records.
  5. The inventory is searchable: which sites run this plugin, which are on this PHP version, which use this page builder, which are hosted with this provider.
  6. Public vulnerability feeds are matched against the inventory, and affected sites are flagged to their responsible developer automatically.
  7. Host announcements, such as PHP retirements, can be turned into a list of affected sites in one search.
QuestionBeforeWith the inventory
Which sites run this plugin?Log into each siteOne search
Which sites are on an old PHP version?Ask the host, check each siteOne filter
Who is responsible for this site?Ask aroundOn the record
Are client-hosted sites affected?Often unknownScanned and recorded
Which sites does this advisory affect?Manual checkFlagged automatically

The inventory also supports your other processes: update runs, maintenance reports, licence tracking and client offboarding all read from the same list.

The next advisory

A vulnerability is announced. The inventory matches it against every site straight away and flags the affected ones to their developers. Sites on maintenance plans are updated through the tested update routine. Clients on sites the studio does not maintain get a short, honest note that their site uses the affected plugin and what to do. The day continues as planned.

Could you answer these questions quickly?

  • You cannot quickly list which client sites run a given plugin.
  • Only some sites are in your management tool.
  • PHP versions and hosts are not recorded for every site.
  • Security advisories mean a day of logging into sites.
  • Responsibility for each site is informal.

FAQ

Frequently asked questions

The questions readers ask us after this guide.

Still have a question?

Ask us directly — a senior engineer will get back to you.

Ask about your project

Does it include sites we do not host?

Yes. Sites you manage get full detail. Others get what a public scan can see, plus anything you record.

Which vulnerability feeds does it use?

Public WordPress vulnerability databases and similar sources for other platforms. We choose based on the platforms you work with.

Do we need a management tool like ManageWP?

It helps, but a small reporting plugin can provide the same information for sites that are not connected.

Can clients see their own inventory?

If you want, a client view can show their sites and their status.

What does the cost depend on?

How many sites and platforms you look after, and whether you already use a management tool.

Keep reading

More on Problems We Solve

Start here

Tell us where your web projects get stuck

Describe how a website project runs at your studio, from signed proposal to launch and the maintenance plan afterwards, and which tools you use, such as Figma, WordPress, Basecamp, ManageWP or Xero. We will tell you what we would build and what we would leave alone, and if a plugin or a setting you already have would solve it, we will say so.

  1. You tell us what you needTwo minutes on the form, or a message on WhatsApp.
  2. A senior engineer reviews itAnd comes back with questions, a realistic range and an honest view on fit.
  3. Free 30-minute scoping callWe talk through scope, options and a realistic estimate — with no obligation.
Free estimateNo obligation

Talk to someone who builds this

Send a short brief and we will come back with an honest view and a realistic range.

Takes under a minute. We never share your details.

  • Free consultation
  • No commitment
  • NDA on request

Prefer to talk? Book a free 30-minute call →