Day Zero Guides

WordPress Plugins

Haq Security CVE Monitor: A Free CVE-Matching Watchdog for WordPress, Not Another Firewall Plugin

By Day Zero Guides Editorial · How we produce guides

Some links in this guide are affiliate links. If you sign up through them, Day Zero Guides may earn a commission at no extra cost to you. This never affects which products we cover or what we say about them. See our affiliate disclosure for details.

Screenshot of Haq Security CVE Monitor
Visit Haq Security CVE Monitor →

Where This Actually Fits Against Wordfence, Sucuri, and iThemes Security

If you've run a WordPress site for more than a year, you've probably already got one of the big three security plugins installed: Wordfence, Sucuri Security, or iThemes Security (now rebranded SolidWP Security). Haq Security CVE Monitor is not trying to replace any of them, and that matters for how you should evaluate it.

Those three products are built around firewalling and malware cleanup — Wordfence runs a web application firewall and live traffic monitoring, Sucuri layers in a CDN and DNS-level filtering plus a remediation service, and iThemes focuses on hardening (login lockdown, file change detection, two-factor auth). None of them are primarily designed to answer one narrow but critical question: which specific CVEs have been published against the exact plugins and themes I have installed right now, and is any of them on CISA's Known Exploited Vulnerabilities list?

That's the gap Haq Security CVE Monitor fills. It doesn't inspect traffic, it doesn't block requests, and it doesn't scan files for malware signatures. Instead it builds an inventory of your installed themes, plugins, and core version, sends that fingerprint to the Haq Security API, and matches it against CVE databases and the CISA KEV catalog daily. The output is a risk score and security grade you can act on — telling you "plugin X version Y has a published RCE, patched in version Z, and it's actively being exploited in the wild per CISA" — rather than a generic "your firewall blocked 40 requests today" report.

If you already run Wordfence or Sucuri for perimeter defense, running Haq Security CVE Monitor alongside it isn't redundant — it's covering a blind spot. Wordfence's premium tier does include a vulnerability database lookup, but it's bundled behind the $119/year (single site) Wordfence Premium plan. Haq gives you a comparable CVE cross-reference for free, without needing to upgrade anything.

What It Actually Does

Once activated, the plugin builds a live inventory of every theme, plugin, and WordPress core version on the install. That inventory is checked against CVE feeds through the Haq Security API, and matches are cross-referenced specifically against CISA's Known Exploited Vulnerabilities (KEV) list — the subset of vulnerabilities confirmed to be actively exploited, not just theoretically dangerous. This is the detail that separates it from a plain CVE lookup tool: it flags what's actually being used in attacks right now versus what's a low-priority CVE with no known exploitation.

The dashboard shows:

  • A single security grade (A–F style) for the site
  • A numeric risk score
  • A list of detected technologies (theme/plugin/core versions) with matched CVEs
  • CISA KEV flags on anything actively exploited
  • A history of daily automated scans, run on a WP-Cron schedule

There's no manual scan-and-wait workflow required day to day — it checks itself daily and updates the dashboard, so the expected use pattern is: install once, then check the dashboard weekly or whenever you get an alert email (if configured) rather than babysitting it.

Pricing: Actually Free, No Catch

This is worth stating plainly because it's unusual in this category: Haq Security CVE Monitor is completely free. There's no premium tier, no feature gating, no trial period that reverts to a paywall, and no upsell nagging inside the dashboard. Compare that to the competitive set:

  • Wordfence: Free core firewall and scanner; Premium is $119/year per site for real-time rule updates and the vulnerability database feature this plugin's CVE matching most resembles.
  • Sucuri Security: The plugin itself is free, but meaningful protection (WAF, CDN, blacklist removal, malware cleanup) lives behind Sucuri's paid platform, starting around $199.99/year per site (Basic) and up to $499.99/year+ (Business/Pro tiers) depending on traffic and cleanup needs.
  • iThemes/SolidWP Security: Free version covers basic hardening; Pro starts at $99/year for one site and scales up with bundled backup and Solid Central management for multi-site agencies.

Haq undercuts all three by simply not charging for the CVE-matching function at all.

Comparison Table

Haq Security CVE MonitorWordfence SecuritySucuri SecurityiThemes (SolidWP) Security
PriceFree, no paid tierFree / Premium $119/year/siteFree plugin / Paid platform from $199.99/yearFree / Pro from $99/year/site
Core focusCVE + CISA KEV matching on installed tech stackFirewall (WAF) + malware scanningPerimeter firewall, CDN, malware cleanup serviceHardening: login limits, 2FA, file change detection
CVE/vulnerability databaseYes, daily automated matching, CISA KEV cross-referenceYes, in Premium tier onlyLimited, focused more on signature-based malware detectionNo dedicated CVE feed
Best forKnowing exactly which installed plugin/theme has a live, exploited CVESites needing active request-level blockingSites wanting a managed WAF + cleanup guaranteeAgencies standardizing login/hardening policy across many sites
Setup effortInstall, let it scan daily, check dashboardInstall, configure firewall rules, tune false positivesInstall plugin, separately configure DNS/CDN proxyInstall, walk through hardening checklist

Concrete Use Cases

  • A site running 15+ plugins across multiple contributors: You inherited a site where nobody's tracked plugin versions closely. Instead of manually checking each plugin's changelog for security fixes, Haq's daily scan surfaces which specific ones have unpatched CVEs, ranked by whether they're on the CISA KEV list.
  • Agencies doing pre-handoff audits: Before handing a client site back after a build, running Haq gives you a defensible "security grade" snapshot and a CVE list to include in the handoff report, without paying per-site licensing like Sucuri's Business tier requires.
  • Sites already paying for Wordfence's firewall but not Premium: You get the perimeter protection from Wordfence free tier, and layer Haq on top specifically for the CVE/KEV matching Wordfence Premium normally charges $119/year to unlock.
  • Compliance-adjacent reporting: If you need to show a client or auditor that you're actively checking for known-exploited vulnerabilities (not just "a firewall is installed"), the CISA KEV cross-reference gives you a specific, named federal data source to point to.

Who Should Skip It (For Now)

If you need active request blocking, rate limiting, or malware file remediation, this plugin does none of that — you still need Wordfence, Sucuri, or iThemes for the firewall/cleanup side. Haq is a detection and awareness layer, not a defense layer. Treat it as the smoke detector, not the fire extinguisher.

Bottom Line

Install it today if you want a free, specific answer to "do I have a plugin with an actively exploited CVE right now," cross-referenced against CISA's real KEV list, without touching your existing firewall setup or paying anything. It's a narrow tool that does one job well, and the price of admission — zero — makes it low-risk to try alongside whatever you're already running.

See it on Pinterest →

We use cookies for ads (Google AdSense) and basic analytics. See our privacy policy.