Skip to main content

Threat intelligence

How SiteRespond intelligence works

Transparency on data sources, classification, refresh cadence, and what catalog listing does — and does not — mean for your site.

Catalog health

WordPress advisory feed last successfully refreshed 4d ago · CISA KEV catalog refreshed 1h ago.

Data sources and licences

SiteRespond imports WordPress plugin, theme and core advisories from Wordfence Intelligence into a private catalog used for Defence version matching. CVE identifiers are cross-referenced with the CISA Known Exploited Vulnerabilities catalog. Each public record stores source provenance and links to the authoritative original.

Public pages summarise imported fields with attribution. Attribution alone does not necessarily grant redistribution rights — review the respective source terms before republishing advisory content elsewhere.

Refresh frequency

The WordPress advisory feed and CISA KEV catalog are promoted on an automated daily schedule. The timestamp shown on the intelligence catalog reflects the last successful WordPress feed promotion, not live per-request API calls.

Classification rules

Vulnerability types displayed in charts and software profiles are inferred from advisory titles using pattern rules (for example, matching “SQL injection”, “XSS”, or “remote code execution”). This is useful context — not a formal CWE taxonomy. Advisories that do not match a rule appear as unclassified in summary statistics.

Authentication requirements

Whether an issue requires authentication is also inferred from advisory titles — looking for phrases such as “unauthenticated” or role names like “subscriber” or “administrator”. When the feed title does not specify authentication, we label it unspecified and recommend reading the source advisory.

CISA KEV matching

After import, SiteRespond compares each advisory CVE against the full CISA KEV catalog. “CISA KEV catalog checked” is the size of that authoritative list. “Current WordPress feed matches” is how many advisories in this WordPress feed carry a CVE also listed in KEV — not the number of exploited WordPress vulnerabilities SiteRespond independently confirms.

Withdrawn and corrected advisories

When the upstream feed marks an advisory as withdrawn, SiteRespond excludes it from the active public catalog on the next successful promotion. Historical URLs may return not found after withdrawal.

Catalog presence vs Defence matching

Seeing a vulnerability listed does not mean your site is affected. Exposure depends on whether you run the affected software at a vulnerable version.

  • SiteRespond Watch performs external monitoring only. It does not inspect installed WordPress components.
  • SiteRespond Defence matches your installed core, plugin and theme versions against this catalog when the Defence plugin is connected.

What SiteRespond claims

  • We maintain an imported, refreshed WordPress vulnerability catalog for Defence matching.
  • We explain affected version ranges as provided by the source feed.
  • We cross-reference CVEs with CISA KEV where assigned.
  • We add plain-language context to help site owners understand potential impact.

We do not claim:

  • That catalog listing implies your specific site is vulnerable.
  • CVSS scores or official severity ratings unless present in the source.
  • Manual editorial verification of every imported advisory.
  • Live exploit confirmation on your server from this public catalog alone.

← Back to vulnerability intelligence catalog