Signature matching
Recognises the plugin versions and files that have already been catalogued as vulnerable or malicious.
WP Luminary scans the plugins, themes, core files, and key settings already on your WordPress site for vulnerabilities, backdoors, and suspicious changes, then explains what it found in plain language.
WP Luminary is not released yet. The waitlist is how to hear first when access opens.
A signature match can only flag code somebody has already found and catalogued as risky. WP Luminary also reviews what the code is doing, so a finding does not depend on that exact flaw having been reported before.
Recognises the plugin versions and files that have already been catalogued as vulnerable or malicious.
Reads what the code actually does: who is allowed to run an action, how a login is verified, and how a database query gets built.
The scan is built for the parts of a WordPress site that attackers most often abuse.
Plugins are how most WordPress sites get taken over. The scan looks for actions that never check whether the user was allowed to perform them, logins that can be skipped entirely, database queries an attacker can rewrite (SQL injection), and code that lets one customer open another customer’s records.
Theme files are a favourite hiding place for backdoors. The scan flags injected and deliberately obfuscated code, and edits that quietly leave a way back in after you think the site has been cleaned up.
Core files should match a clean WordPress install exactly. Anything added, altered, or removed gets flagged — including web shells dropped into folders that should only ever hold uploaded images.
Attackers persist in the database as well as in files. The scan reviews stored settings for injected scripts that run in your visitors’ browsers (cross-site scripting), unexpected administrator accounts, and redirects sending your traffic somewhere else.
The goal is not just to detect problems. It is to make them understandable enough to fix.
01
WP Luminary checks your active plugins, theme files, WordPress core files, and important database settings.
02
The analysis looks for vulnerable code, tampering, and backdoors, then weighs how likely each finding is to be real.
03
Each finding is translated into plain language so a non-developer can understand the risk and take action.
The tiers differ by analysis depth, false-positive discipline, and how many sites they suit. Each card leads to the waitlist while launch access is still closed.
Starter
Indicator-of-compromise and vulnerability scanning across your plugin, theme, and core files plus your database options. Catches the missing permission checks, injection flaws, and known-vulnerable plugin versions that account for most WordPress break-ins. Single site.
Your code is never stored by the AI model that analyses it.
Join the waitlistPrivacy
A stronger analysis model than Starter, so subtler problems surface: permission gaps that only matter when chained together, deliberately obfuscated backdoors, and tampering designed to survive a cleanup. More site seats.
Same no-retention guarantee as Starter.
Join the waitlistPro
Our most capable analysis model, and the most disciplined about what it reports. Two results from our own comparison run:
Pro runs our most capable model for the deepest analysis available. That model doesn't yet support the no-retention guarantee our other tiers offer. If that's a hard requirement for your site, Privacy is the better fit.
Join the waitlistEvery tier runs the same checks. What changes is how deep the analysis goes, how well it separates real findings from noise, and how many sites you cover.
Seat counts are indicative while we finalise plans.
| Plan detail | Starter | Privacy | Pro |
|---|---|---|---|
| Scan depth | Baseline vulnerability and compromise checks. | Deeper analysis for subtler issues. | Deepest analysis available. |
| False-positive discipline | Good for broad coverage, with some cautious notes. | Stronger filtering than Starter. | Returned zero false-positive findings on our clean-file test. |
| Retention guarantee | Never stored by the AI model that analyses your code. | Never stored by the AI model that analyses your code. | Not currently covered by that guarantee. |
| Site seats | 1 site | 5 sites | Multi-site (agency) |
Seat counts are indicative while we finalise plans.
Starter and Privacy differ by scan depth and site capacity, not by whether your code is retained — both carry the same guarantee.
WP Luminary is not released yet. Leave your email and we will send launch updates, early access news, and plan details as they are finalised.
Early subscribers get first access to launch pricing.