Security is the product. Here's how we protect the data you trust us with.
WP Triage (wptriage.app) is operated by Mike Beck, an independent developer based in Whanganui, New Zealand. Site inventory is sent to the hosted service at wptriage.app. We do not collect site content, customer data, or credentials.
Installed plugins, themes, and WordPress core are matched against the public WPVulnerability database. PHP lifecycle risk uses published PHP support dates. Known-exploited (KEV) flags come from that source when they are present. The source is WPVulnerability. See the scoring methodology for how those signals become a score.
WP Triage collects only technical metadata from connected WordPress sites — plugin and theme names and versions, WordPress core version, and PHP version. We never collect your site's content, database, customer records, or credentials.
All traffic between your browser, our API, and connected WordPress sites is encrypted using TLS. Plain HTTP requests are redirected to HTTPS.
wpa_…) authorise a WordPress plugin to register sites against your account. They are stored as one-way hashes and shown to you only once.wpt_…) are issued per site and scope a site to submitting only its own snapshots.Your sites and data are scoped to your account. Ingest endpoints are rate limited, and snapshot submissions are restricted to the site that owns the token.
Payments are processed by Stripe, a PCI-DSS Level 1 certified provider. We do not store full payment card details on our servers.
If you believe you've found a security vulnerability in WP Triage, please report it to [email protected]. We ask that you give us a reasonable opportunity to investigate and remediate before any public disclosure, and that you avoid accessing or modifying data that isn't yours. We appreciate and acknowledge good-faith research.
For any security question, reach us at [email protected].