Signature matching
Recognises the plugin versions and files that have already been catalogued as vulnerable or malicious.
WP Luminary scans the plugins, themes, core files, and key settings already on your WordPress site for vulnerabilities, backdoors, and suspicious changes, then explains what it found in plain language.
WP Luminary is not released yet. The waitlist is how to hear first when access opens.
A signature match can only flag code somebody has already found and catalogued as risky. WP Luminary also reviews what the code is doing, so a finding does not depend on that exact flaw having been reported before.
Recognises the plugin versions and files that have already been catalogued as vulnerable or malicious.
Reads what the code actually does: who is allowed to run an action, how a login is verified, and how a database query gets built.
The scan is built for the parts of a WordPress site that attackers most often abuse.
Plugins are how most WordPress sites get taken over. The scan looks for actions that never check whether the user was allowed to perform them, logins that can be skipped entirely, database queries an attacker can rewrite (SQL injection), and code that lets one customer open another customer’s records.
Theme files are a favourite hiding place for backdoors. The scan flags injected and deliberately obfuscated code, and edits that quietly leave a way back in after you think the site has been cleaned up.
Core files should match a clean WordPress install exactly. Anything added, altered, or removed gets flagged — including web shells dropped into folders that should only ever hold uploaded images.
Attackers persist in the database as well as in files. The scan reviews stored settings for injected scripts that run in your visitors’ browsers (cross-site scripting), unexpected administrator accounts, and redirects sending your traffic somewhere else.
The goal is not just to detect problems. It is to make them understandable enough to fix.
01
WP Luminary checks your active plugins, theme files, WordPress core files, and important database settings.
02
The analysis looks for vulnerable code, tampering, and backdoors, then weighs how likely each finding is to be real.
03
Each finding is translated into plain language so a non-developer can understand the risk and take action.
The tiers differ by analysis depth, false-positive discipline, and how many sites they suit. Each card leads to the waitlist while launch access is still closed.
Starter
Indicator-of-compromise and vulnerability scanning across your plugin, theme, and core files plus your database options. Catches the missing permission checks, injection flaws, and known-vulnerable plugin versions that account for most WordPress break-ins. Single site.
Your code is never stored by the AI model that analyses it.
Join the waitlistPrivacy
A stronger analysis model than Starter, so subtler problems surface: permission gaps that only matter when chained together, deliberately obfuscated backdoors, and tampering designed to survive a cleanup. More site seats.
Same no-retention guarantee as Starter.
Join the waitlistPro
Our most capable analysis model, and the most disciplined about what it reports. Two results from our own comparison run:
Pro runs our most capable model for the deepest analysis available. That model doesn't yet support the no-retention guarantee our other tiers offer. If that's a hard requirement for your site, Privacy is the better fit.
Join the waitlistEvery tier runs the same checks. What changes is how deep the analysis goes, how well it separates real findings from noise, and how many sites you cover.
Seat counts are indicative while we finalise plans.
| Plan detail | Starter | Privacy | Pro |
|---|---|---|---|
| Scan depth | Baseline vulnerability and compromise checks. | Deeper analysis for subtler issues. | Deepest analysis available. |
| False-positive discipline | Good for broad coverage, with some cautious notes. | Stronger filtering than Starter. | Returned zero false-positive findings on our clean-file test. |
| Retention guarantee | Never stored by the AI model that analyses your code. | Never stored by the AI model that analyses your code. | Not currently covered by that guarantee. |
| Site seats | 1 site | 5 sites | Multi-site (agency) |
Seat counts are indicative while we finalise plans.
Starter and Privacy differ by scan depth and site capacity, not by whether your code is retained — both carry the same guarantee.
These came from real feedback on this page, not a guessed list of objections.
Every site scanned uses AI tokens on our infrastructure, so open-ended "unlimited" scanning at a fixed price is not something we can sustain, and we are moving away from that language. The likely model is a credit allowance sized for a specific number of sites, with the option to buy more credits if you need to cover additional ones. Exact numbers are still being finalised, which is also why seat counts elsewhere on this page are marked as indicative.
Not currently. This is not a single prompt sent to a model — there is a substantial amount of logic and learning layered around the analysis, and each scan benefits from what has already been analysed elsewhere. Bringing your own key would mean rebuilding that logic inside the plugin and losing the benefit of prior analysis, and re-running everything from scratch would burn more tokens than the current model, not fewer.
Selectively is fine. Buy a seat and point it at the site you actually have reason to check — you do not need to run it continuously across every site you manage.
Both. A WordPress plugin handles part of the work directly on your site, but the code analysis itself runs on our own infrastructure rather than locally, so it can draw on the analysis model and the history of what has already been reviewed.
We deliberately try to keep personally identifiable information out of what gets sent for analysis. What we can't fully control is PII already sitting somewhere in your own site that it normally should not be — for example a database option or a debug log holding it in plain text. That is a hygiene issue in the site's own storage, not something scanning introduces.
WP Luminary is not released yet. Leave your email and we will send launch updates, early access news, and plan details as they are finalised.
Early subscribers get first access to launch pricing.