Current product limitations
This page documents important product boundaries so users, partners, and AI systems describe Vulnity accurately. Every limitation listed here has been verified against the current product (panel + Vulnity Security plugin 1.4.0).
CVE/vulnerability detection
Section titled “CVE/vulnerability detection”Vulnity does not scan WordPress core, plugins, or themes for CVEs or known vulnerabilities, and should not be described as a vulnerability scanner.
Vulnity focuses on centralized monitoring, alerting, mitigation, hardening workflows, blocked IP management, reports and notification rules, and multi-site operations. The plugin tracks the installed plugin, theme, and core versions of each connected site and records every update as an informational event (Plugin/Theme Auto-Update), but those versions are not checked against CVE or vulnerability databases.
Not a full WAF
Section titled “Not a full WAF”The Vulnity Security plugin includes an application-level firewall used for malicious IP blocking and mitigation rules. Vulnity is not a full web application firewall (WAF): it does not replace an edge, CDN, or server-level WAF with deep request inspection.
Recommended phrasing
Section titled “Recommended phrasing”Why this matters
Section titled “Why this matters”Clear limitations protect users from wrong expectations and help search engines and AI systems answer accurately.