{"id":364170,"date":"2026-09-10T20:32:50","date_gmt":"2026-09-10T20:32:50","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/igw-security-history\/"},"modified":"2026-09-10T20:32:33","modified_gmt":"2026-09-10T20:32:33","slug":"igw-security-history","status":"publish","type":"plugin","link":"https:\/\/lmo.wordpress.org\/plugins\/igw-security-history\/","author":165027,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"0.1.0","stable_tag":"0.1.0","tested":"7.1","requires":"6.2","requires_php":"7.4","requires_plugins":null,"header_name":"IGW Security History","header_author":"Francisco G\u00e1lvez","header_description":"Tracks the security history of installed plugins and checks whether their current versions are affected by known vulnerabilities.","assets_banners_color":"f9fcfb","last_updated":"2026-09-10 20:32:33","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/iguannawp.com\/igw-security-history\/","header_author_uri":"https:\/\/iguannawp.com\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":41,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"0.1.0":{"tag":"0.1.0","author":"crishnakh","date":"2026-09-10 20:32:33","revision":3690476}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-256x256.png":{"filename":"icon-256x256.png","revision":3690535,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3690535,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3690535,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["0.1.0"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3690479,"resolution":"1","location":"assets","locale":"","width":1853,"height":962},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3690479,"resolution":"2","location":"assets","locale":"","width":1849,"height":966},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3690479,"resolution":"3","location":"assets","locale":"","width":1866,"height":930},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3690479,"resolution":"4","location":"assets","locale":"","width":1859,"height":955}},"screenshots":{"1":"IGW Security History administration screen showing the local plugin inventory, plugin origin, WordPress.org availability and vulnerability information.","2":"Detailed security history for an individual plugin, including vulnerability summaries, installed-version status and the chronological vulnerability timeline.","3":"Security and vulnerability information integrated into the standard WordPress Plugins screen.","4":"Detailed plugin security history displayed in a modal window directly from the standard WordPress Plugins screen."}},"plugin_section":[],"plugin_tags":[23916,600,280139,41325,139069],"plugin_category":[54],"plugin_contributors":[160469],"plugin_business_model":[],"class_list":["post-364170","plugin","type-plugin","status-publish","hentry","plugin_tags-plugin-security","plugin_tags-security","plugin_tags-security-history","plugin_tags-vulnerabilities","plugin_tags-vulnerability-scanner","plugin_category-security-and-spam-protection","plugin_contributors-crishnakh","plugin_committers-crishnakh"],"banners":{"banner":"https:\/\/ps.w.org\/igw-security-history\/assets\/banner-772x250.png?rev=3690535","banner_2x":"https:\/\/ps.w.org\/igw-security-history\/assets\/banner-1544x500.png?rev=3690535","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/igw-security-history\/assets\/icon-256x256.png?rev=3690535","icon_2x":"https:\/\/ps.w.org\/igw-security-history\/assets\/icon-256x256.png?rev=3690535","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/igw-security-history\/assets\/screenshot-1.png?rev=3690479","caption":"IGW Security History administration screen showing the local plugin inventory, plugin origin, WordPress.org availability and vulnerability information."},{"src":"https:\/\/ps.w.org\/igw-security-history\/assets\/screenshot-2.png?rev=3690479","caption":"Detailed security history for an individual plugin, including vulnerability summaries, installed-version status and the chronological vulnerability timeline."},{"src":"https:\/\/ps.w.org\/igw-security-history\/assets\/screenshot-3.png?rev=3690479","caption":"Security and vulnerability information integrated into the standard WordPress Plugins screen."},{"src":"https:\/\/ps.w.org\/igw-security-history\/assets\/screenshot-4.png?rev=3690479","caption":"Detailed plugin security history displayed in a modal window directly from the standard WordPress Plugins screen."}],"raw_content":"<!--section=description-->\n<p>IGW Security History provides information about the security history of the plugins installed on your WordPress site.<\/p>\n\n<p>The plugin builds a local inventory of installed plugins and combines this information with known vulnerability data.<\/p>\n\n<p>For each plugin, it can show:<\/p>\n\n<ul>\n<li>Plugin name and installed version.<\/li>\n<li>Whether the plugin is active or inactive.<\/li>\n<li>Whether the plugin is available on WordPress.org.<\/li>\n<li>Whether the plugin appears to be commercial or external.<\/li>\n<li>Total number of known historical vulnerabilities.<\/li>\n<li>Vulnerabilities grouped by severity: critical, high, medium, low or unknown.<\/li>\n<li>Date of the most recently known vulnerability.<\/li>\n<li>Whether the currently installed version is affected by known vulnerabilities.<\/li>\n<\/ul>\n\n<p>This makes it possible to distinguish between a plugin that has had security issues in the past and a plugin whose currently installed version is actually affected by a known vulnerability.<\/p>\n\n<p>For example, a plugin may have dozens of historical vulnerabilities while its current version has no known vulnerabilities affecting it.<\/p>\n\n<h4>Plugin inventory<\/h4>\n\n<p>IGW Security History maintains a local inventory containing information about the plugins detected on the WordPress installation.<\/p>\n\n<p>The inventory includes information such as the plugin slug, main file, installed version, activation status, detected source and the dates when the plugin was first and last detected.<\/p>\n\n<p>This information is stored in custom WordPress database tables.<\/p>\n\n<h4>WordPress.org availability<\/h4>\n\n<p>The plugin checks whether installed plugins are currently available from the official WordPress.org plugin directory.<\/p>\n\n<p>It can distinguish between plugins found on WordPress.org and plugins detected as commercial or external.<\/p>\n\n<p>A plugin not currently found on WordPress.org is reported as unavailable. This does not necessarily mean that the plugin was removed from the directory, since it may be a commercial, private or custom plugin that was never hosted there.<\/p>\n\n<h4>Vulnerability history<\/h4>\n\n<p>IGW Security History retrieves a summarized vulnerability history for detected plugins.<\/p>\n\n<p>The information includes:<\/p>\n\n<ul>\n<li>Total known vulnerabilities.<\/li>\n<li>Critical vulnerabilities.<\/li>\n<li>High severity vulnerabilities.<\/li>\n<li>Medium severity vulnerabilities.<\/li>\n<li>Low severity vulnerabilities.<\/li>\n<li>Vulnerabilities without a known severity.<\/li>\n<li>Most recently published known vulnerability.<\/li>\n<\/ul>\n\n<p>Historical vulnerability information does not mean that the currently installed version is vulnerable.<\/p>\n\n<h4>Installed version check<\/h4>\n\n<p>In addition to the historical information, IGW Security History compares the currently installed plugin version against the affected version ranges contained in the vulnerability database.<\/p>\n\n<p>This allows the plugin to report separately whether known vulnerabilities affect the version currently running on the site.<\/p>\n\n<p>When no matching vulnerability is found, the plugin reports that there are no known vulnerabilities affecting that version according to the currently available vulnerability data.<\/p>\n\n<h4>Detailed security history<\/h4>\n\n<p>Each detected plugin can be reviewed individually from the IGW Security History administration screen.<\/p>\n\n<p>The detailed view provides a complete overview of the known vulnerability history for that plugin, including:<\/p>\n\n<ul>\n<li>Historical vulnerability totals grouped by severity.<\/li>\n<li>Security status of the currently installed version.<\/li>\n<li>A chronological vulnerability timeline.<\/li>\n<li>Individual vulnerability details, including CVE identifiers when available, severity, CVSS score, publication date and affected version ranges.<\/li>\n<li>Information about patched versions when available.<\/li>\n<\/ul>\n\n<p>The vulnerability timeline provides a visual representation of the plugin's security history over time. Each point represents a known vulnerability and its position indicates its publication date and severity.<\/p>\n\n<p>Points can be selected to navigate directly to the corresponding vulnerability information.<\/p>\n\n<p>When an installed version is being evaluated, the detailed view distinguishes vulnerabilities that affect that specific version from vulnerabilities that only form part of the plugin's historical record.<\/p>\n\n<h4>Plugins screen integration<\/h4>\n\n<p>Security information is also displayed directly on the standard WordPress Plugins screen.<\/p>\n\n<p>Depending on the available information, IGW Security History can display:<\/p>\n\n<ul>\n<li>WordPress.org availability or detected external\/commercial origin.<\/li>\n<li>Whether the installed version has known vulnerabilities.<\/li>\n<li>A summary of the plugin's historical vulnerabilities.<\/li>\n<\/ul>\n\n<p>A security history link provides access to the detailed plugin information directly from the Plugins screen.<\/p>\n\n<p>The detailed security history can be displayed in a modal window without leaving the standard WordPress Plugins screen.<\/p>\n\n<h4>Manual updates<\/h4>\n\n<p>The administration screen provides controls to refresh the plugin inventory and vulnerability information.<\/p>\n\n<p>Vulnerability checks are performed in batches to reduce the number of external requests.<\/p>\n\n<h3>External services<\/h3>\n\n<p>IGW Security History connects to an external API operated by IguannaWeb in order to retrieve vulnerability information.<\/p>\n\n<p>The service is required to provide the vulnerability history and installed-version vulnerability checks offered by the plugin.<\/p>\n\n<p>When a vulnerability update is requested, the plugin sends information about installed plugins to:<\/p>\n\n<p>https:\/\/api.iguannawp.com\/<\/p>\n\n<p>The information sent may include:<\/p>\n\n<ul>\n<li>Plugin slugs.<\/li>\n<li>Installed plugin versions.<\/li>\n<\/ul>\n\n<p>This information is used to identify known vulnerabilities associated with the installed plugins and to determine whether specific installed versions fall within known affected version ranges.<\/p>\n\n<p>The plugin does not need to send WordPress user accounts, passwords, post content or other site content to perform these checks.<\/p>\n\n<p>The vulnerability database used by the IGW API is currently built using vulnerability information from Wordfence Intelligence. WordPress installations using IGW Security History do not connect directly to the Wordfence Intelligence API and do not require a Wordfence Intelligence API key.<\/p>\n\n<p>The external service is operated by IguannaWeb.<\/p>\n\n<ul>\n<li>Service website: https:\/\/iguannawp.com\/<\/li>\n<li>Terms and legal information: https:\/\/iguannawp.com\/politica-de-privacidad\/<\/li>\n<\/ul>\n\n<p>Because vulnerability information is provided through an external service, availability and results depend on the availability and current data of that service.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>igw-security-history<\/code> folder to the <code>\/wp-content\/plugins\/<\/code> directory, or install the plugin through the WordPress Plugins screen.<\/li>\n<li>Activate IGW Security History from the Plugins screen.<\/li>\n<li>Open the IGW Security History administration screen.<\/li>\n<li>Run the plugin analysis to build the local plugin inventory.<\/li>\n<li>Update the vulnerability information to retrieve the current security history.<\/li>\n<\/ol>\n\n<p>No external account or API key is required.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20having%20historical%20vulnerabilities%20mean%20that%20my%20installed%20plugin%20is%20vulnerable%3F\"><h3>Does having historical vulnerabilities mean that my installed plugin is vulnerable?<\/h3><\/dt>\n<dd><p>No.<\/p>\n\n<p>IGW Security History separates the historical vulnerability count from vulnerabilities known to affect the version currently installed on your site.<\/p>\n\n<p>A plugin can have many historical vulnerabilities while the currently installed version is not affected by any of them.<\/p><\/dd>\n<dt id=\"what%20information%20is%20sent%20to%20the%20igw%20api%3F\"><h3>What information is sent to the IGW API?<\/h3><\/dt>\n<dd><p>Vulnerability checks may send plugin slugs and installed plugin versions.<\/p>\n\n<p>This information is required to identify the plugin and compare its installed version with known affected version ranges.<\/p><\/dd>\n<dt id=\"do%20i%20need%20a%20wordfence%20api%20key%3F\"><h3>Do I need a Wordfence API key?<\/h3><\/dt>\n<dd><p>No.<\/p>\n\n<p>The WordPress plugin communicates with the IGW API. It does not communicate directly with the Wordfence Intelligence API and does not require a Wordfence API key.<\/p><\/dd>\n<dt id=\"does%20the%20plugin%20guarantee%20that%20my%20plugins%20are%20secure%3F\"><h3>Does the plugin guarantee that my plugins are secure?<\/h3><\/dt>\n<dd><p>No.<\/p>\n\n<p>IGW Security History reports known vulnerability information available to its data source. The absence of a known vulnerability does not guarantee that a plugin is free from security issues.<\/p>\n\n<p>The plugin is intended to provide additional security information and should not replace regular updates, backups and other WordPress security practices.<\/p><\/dd>\n<dt id=\"what%20does%20%22not%20available%20on%20wordpress.org%22%20mean%3F\"><h3>What does \"Not available on WordPress.org\" mean?<\/h3><\/dt>\n<dd><p>It means that the plugin was not found in the WordPress.org plugin directory during the most recent check.<\/p>\n\n<p>This does not necessarily mean that WordPress.org removed the plugin. Commercial, private and custom plugins may never have been published in the directory.<\/p><\/dd>\n<dt id=\"are%20vulnerability%20checks%20performed%20automatically%3F\"><h3>Are vulnerability checks performed automatically?<\/h3><\/dt>\n<dd><p>The current version provides manual controls for refreshing plugin and vulnerability information from the administration screen.<\/p><\/dd>\n<dt id=\"what%20happens%20to%20the%20stored%20information%20when%20the%20plugin%20is%20uninstalled%3F\"><h3>What happens to the stored information when the plugin is uninstalled?<\/h3><\/dt>\n<dd><p>IGW Security History deletes its stored data when the plugin is uninstalled.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>0.1.0<\/h4>\n\n<ul>\n<li>Initial release.<\/li>\n<li>Added local inventory of installed plugins.<\/li>\n<li>Added plugin activation and installation status tracking.<\/li>\n<li>Added WordPress.org availability checks.<\/li>\n<li>Added detection of WordPress.org, commercial and external plugin sources.<\/li>\n<li>Added historical vulnerability information.<\/li>\n<li>Added vulnerability severity classification.<\/li>\n<li>Added checks against the currently installed plugin version.<\/li>\n<li>Added batch vulnerability queries.<\/li>\n<li>Added detailed security history for individual plugins.<\/li>\n<li>Added chronological vulnerability timeline.<\/li>\n<li>Added navigation between timeline events and vulnerability details.<\/li>\n<li>Added vulnerability information to the standard WordPress Plugins screen.<\/li>\n<li>Added detailed security history modal to the standard WordPress Plugins screen.<\/li>\n<li>Added administration interface for reviewing plugin security information.<\/li>\n<li>Added cleanup of plugin data on uninstall.<\/li>\n<\/ul>","raw_excerpt":"Review the security history of your installed plugins and check whether their current versions are affected by known vulnerabilities.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/lmo.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/364170","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lmo.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/lmo.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/lmo.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=364170"}],"author":[{"embeddable":true,"href":"https:\/\/lmo.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/crishnakh"}],"wp:attachment":[{"href":"https:\/\/lmo.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=364170"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/lmo.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=364170"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/lmo.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=364170"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/lmo.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=364170"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/lmo.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=364170"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/lmo.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=364170"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}