Haq Security CVE Monitor: A Free CVE-Matching Watchdog for WordPress, Not Another Firewall Plugin
By Day Zero Guides Editorial · How we produce guides
Some links in this guide are affiliate links. If you sign up through them, Day Zero Guides may earn a commission at no extra cost to you. This never affects which products we cover or what we say about them. See our affiliate disclosure for details.

Where This Actually Fits Against Wordfence, Sucuri, and iThemes Security
If you've run a WordPress site for more than a year, you've probably already got one of the big three security plugins installed: Wordfence, Sucuri Security, or iThemes Security (now rebranded SolidWP Security). Haq Security CVE Monitor is not trying to replace any of them, and that matters for how you should evaluate it.
Those three products are built around firewalling and malware cleanup — Wordfence runs a web application firewall and live traffic monitoring, Sucuri layers in a CDN and DNS-level filtering plus a remediation service, and iThemes focuses on hardening (login lockdown, file change detection, two-factor auth). None of them are primarily designed to answer one narrow but critical question: which specific CVEs have been published against the exact plugins and themes I have installed right now, and is any of them on CISA's Known Exploited Vulnerabilities list?
That's the gap Haq Security CVE Monitor fills. It doesn't inspect traffic, it doesn't block requests, and it doesn't scan files for malware signatures. Instead it builds an inventory of your installed themes, plugins, and core version, sends that fingerprint to the Haq Security API, and matches it against CVE databases and the CISA KEV catalog daily. The output is a risk score and security grade you can act on — telling you "plugin X version Y has a published RCE, patched in version Z, and it's actively being exploited in the wild per CISA" — rather than a generic "your firewall blocked 40 requests today" report.
If you already run Wordfence or Sucuri for perimeter defense, running Haq Security CVE Monitor alongside it isn't redundant — it's covering a blind spot. Wordfence's premium tier does include a vulnerability database lookup, but it's bundled behind the $119/year (single site) Wordfence Premium plan. Haq gives you a comparable CVE cross-reference for free, without needing to upgrade anything.
What It Actually Does
Once activated, the plugin builds a live inventory of every theme, plugin, and WordPress core version on the install. That inventory is checked against CVE feeds through the Haq Security API, and matches are cross-referenced specifically against CISA's Known Exploited Vulnerabilities (KEV) list — the subset of vulnerabilities confirmed to be actively exploited, not just theoretically dangerous. This is the detail that separates it from a plain CVE lookup tool: it flags what's actually being used in attacks right now versus what's a low-priority CVE with no known exploitation.
The dashboard shows:
- A single security grade (A–F style) for the site
- A numeric risk score
- A list of detected technologies (theme/plugin/core versions) with matched CVEs
- CISA KEV flags on anything actively exploited
- A history of daily automated scans, run on a WP-Cron schedule
There's no manual scan-and-wait workflow required day to day — it checks itself daily and updates the dashboard, so the expected use pattern is: install once, then check the dashboard weekly or whenever you get an alert email (if configured) rather than babysitting it.
Pricing: Actually Free, No Catch
This is worth stating plainly because it's unusual in this category: Haq Security CVE Monitor is completely free. There's no premium tier, no feature gating, no trial period that reverts to a paywall, and no upsell nagging inside the dashboard. Compare that to the competitive set:
- Wordfence: Free core firewall and scanner; Premium is $119/year per site for real-time rule updates and the vulnerability database feature this plugin's CVE matching most resembles.
- Sucuri Security: The plugin itself is free, but meaningful protection (WAF, CDN, blacklist removal, malware cleanup) lives behind Sucuri's paid platform, starting around $199.99/year per site (Basic) and up to $499.99/year+ (Business/Pro tiers) depending on traffic and cleanup needs.
- iThemes/SolidWP Security: Free version covers basic hardening; Pro starts at $99/year for one site and scales up with bundled backup and Solid Central management for multi-site agencies.
Haq undercuts all three by simply not charging for the CVE-matching function at all.
Comparison Table
| Haq Security CVE Monitor | Wordfence Security | Sucuri Security | iThemes (SolidWP) Security | |
|---|---|---|---|---|
| Price | Free, no paid tier | Free / Premium $119/year/site | Free plugin / Paid platform from $199.99/year | Free / Pro from $99/year/site |
| Core focus | CVE + CISA KEV matching on installed tech stack | Firewall (WAF) + malware scanning | Perimeter firewall, CDN, malware cleanup service | Hardening: login limits, 2FA, file change detection |
| CVE/vulnerability database | Yes, daily automated matching, CISA KEV cross-reference | Yes, in Premium tier only | Limited, focused more on signature-based malware detection | No dedicated CVE feed |
| Best for | Knowing exactly which installed plugin/theme has a live, exploited CVE | Sites needing active request-level blocking | Sites wanting a managed WAF + cleanup guarantee | Agencies standardizing login/hardening policy across many sites |
| Setup effort | Install, let it scan daily, check dashboard | Install, configure firewall rules, tune false positives | Install plugin, separately configure DNS/CDN proxy | Install, walk through hardening checklist |
Concrete Use Cases
- A site running 15+ plugins across multiple contributors: You inherited a site where nobody's tracked plugin versions closely. Instead of manually checking each plugin's changelog for security fixes, Haq's daily scan surfaces which specific ones have unpatched CVEs, ranked by whether they're on the CISA KEV list.
- Agencies doing pre-handoff audits: Before handing a client site back after a build, running Haq gives you a defensible "security grade" snapshot and a CVE list to include in the handoff report, without paying per-site licensing like Sucuri's Business tier requires.
- Sites already paying for Wordfence's firewall but not Premium: You get the perimeter protection from Wordfence free tier, and layer Haq on top specifically for the CVE/KEV matching Wordfence Premium normally charges $119/year to unlock.
- Compliance-adjacent reporting: If you need to show a client or auditor that you're actively checking for known-exploited vulnerabilities (not just "a firewall is installed"), the CISA KEV cross-reference gives you a specific, named federal data source to point to.
Who Should Skip It (For Now)
If you need active request blocking, rate limiting, or malware file remediation, this plugin does none of that — you still need Wordfence, Sucuri, or iThemes for the firewall/cleanup side. Haq is a detection and awareness layer, not a defense layer. Treat it as the smoke detector, not the fire extinguisher.
Bottom Line
Install it today if you want a free, specific answer to "do I have a plugin with an actively exploited CVE right now," cross-referenced against CISA's real KEV list, without touching your existing firewall setup or paying anything. It's a narrow tool that does one job well, and the price of admission — zero — makes it low-risk to try alongside whatever you're already running.
Related guides
- iLang Readable Slugs: A WordPress Plugin That Finally Fixes Percent-Encoded URLs for Non-Latin Content
- AcceGuru First Look: A WordPress-Native Accessibility Scanner That Tries to Fix What It Finds
- Auditwright WCAG Accessibility Scanner: First Look at the New WordPress Plugin That Scans Rendered Pages, Not Raw HTML