• Resolved nineplanetsllc

    (@nineplanetsllc)


    We have several sites with Wordfence configured to “Alert me with scan results of this severity level or greater: High” — according to documentation, outdated plugins should not be one of the things that triggers an alert when set to High (rather, documentation indicates outdated plugins should trigger an alert if set to Medium). We run updates nightly and our clients should not ever need to receive outdated plugin notices.

    In scan options, we DO want to have it check for abandoned and vulnerable plugins and themes, though, so we do need to have “Scan for out of date, abandoned, and vulnerable plugins, themes, and WordPress versions” checked.

    How do we keep Wordfence from emailing alerts about these outdated plugins, yet still have it check for them?

Viewing 3 replies - 1 through 3 (of 3 total)
  • Plugin Support wfphil

    (@wfphil)

    Hi @nineplanetsllc

    If you have added this site to the Wordfence Central tool then you may have the Medium option enabled in the Scan Findings section in the settings page below:

    https://www.wordfence.com/central/settings

    Thread Starter nineplanetsllc

    (@nineplanetsllc)

    Thank you, @wfphil, but we are not using Wordfence Central for these sites, so that isn’t it. Much appreciate your idea and reply!

    Plugin Support wfphil

    (@wfphil)

    Hi @nineplanetsllc

    Thank you for the update.

    A plugin scan result that says that an update is available will generate a Medium scan result. If that plugin has an unpatched vulnerability then that will have a Critical scan result and will therefore send an email if you have the alert option Alert me with scan results of this severity level or greater set to High.

    The alert email will also include – Update includes security-related fixes

Viewing 3 replies - 1 through 3 (of 3 total)
  • The topic ‘Outdated Plugin Alerts delivered when they shouldn’t be’ is closed to new replies.