{"id":260439,"date":"2025-11-18T18:41:15","date_gmt":"2025-11-18T18:41:15","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/vulndex-beacon\/"},"modified":"2026-08-17T10:56:52","modified_gmt":"2026-08-17T10:56:52","slug":"vulndex-beacon","status":"publish","type":"plugin","link":"https:\/\/ko.wordpress.org\/plugins\/vulndex-beacon\/","author":23394422,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.0","stable_tag":"1.0.3","tested":"7.1","requires":"5.8","requires_php":"7.4","requires_plugins":null,"header_name":"VulnDex Beacon","header_author":"VulnDex","header_description":"Automatically sync your WordPress versions, plugins, and themes with VulnDex for continuous vulnerability insights.","assets_banners_color":"d8e0f4","last_updated":"2026-08-17 10:56:52","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"","rating":0,"author_block_rating":0,"active_installs":0,"downloads":1061,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"vulndex","date":"2025-11-18 18:40:59"},"1.0.1":{"tag":"1.0.1","author":"vulndex","date":"2026-03-25 21:06:22"},"1.0.2":{"tag":"1.0.2","author":"vulndex","date":"2026-05-26 21:53:08"},"1.0.3":{"tag":"1.0.3","author":"vulndex","date":"2026-08-17 10:56:52"}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3398290,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3398290,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3398290,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3398290,"resolution":"772x250","location":"assets","locale":"","width":722,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0","1.0.1","1.0.2","1.0.3"],"block_files":[],"assets_screenshots":[],"screenshots":[]},"plugin_section":[],"plugin_tags":[6601,5603,600,6460],"plugin_category":[54],"plugin_contributors":[250860],"plugin_business_model":[],"class_list":["post-260439","plugin","type-plugin","status-publish","hentry","plugin_tags-inventory","plugin_tags-monitoring","plugin_tags-security","plugin_tags-vulnerability","plugin_category-security-and-spam-protection","plugin_contributors-vulndex","plugin_committers-vulndex"],"banners":{"banner":"https:\/\/ps.w.org\/vulndex-beacon\/assets\/banner-772x250.png?rev=3398290","banner_2x":"https:\/\/ps.w.org\/vulndex-beacon\/assets\/banner-1544x500.png?rev=3398290","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/vulndex-beacon\/assets\/icon-128x128.png?rev=3398290","icon_2x":"https:\/\/ps.w.org\/vulndex-beacon\/assets\/icon-256x256.png?rev=3398290","generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>VulnDex Beacon connects your WordPress site to an existing <a href=\"https:\/\/vulndex.at\/\">VulnDex<\/a> account. It reports the installed WordPress core, plugin, and theme versions so VulnDex can identify relevant known vulnerabilities and keep the site's component inventory current.<\/p>\n\n<p><a href=\"https:\/\/vulndex.at\/\">VulnDex<\/a> is a team-oriented vulnerability management platform. It brings vulnerability and inventory data into a shared view where affected components can be assigned to responsible teams and remediation progress can be coordinated.<\/p>\n\n<p>The Beacon is an inventory connector. It does not scan files, database content, or traffic; patch vulnerable components; block attacks; or replace a vulnerability scanner, firewall, or other security controls.<\/p>\n\n<h4>Features<\/h4>\n\n<ul>\n<li>Reports the WordPress core version and installed plugins and themes, including their versions and activation status.<\/li>\n<li>Schedules synchronization every two hours through WP-Cron.<\/li>\n<li>Schedules additional reports after plugin or theme changes and WordPress update operations.<\/li>\n<li>Provides a manual send action and the latest connection status under Settings &gt; VulnDex Beacon.<\/li>\n<li>Uses a unique Node ID to identify the WordPress site in VulnDex.<\/li>\n<li>Sends authenticated requests to a fixed VulnDex API endpoint over HTTPS.<\/li>\n<li>Enables reported versions to be viewed with relevant vulnerability information, team assignments, and version history in VulnDex.<\/li>\n<\/ul>\n\n<h4>Requirements<\/h4>\n\n<ul>\n<li>WordPress 5.8 or later.<\/li>\n<li>PHP 7.4 or later.<\/li>\n<li>A VulnDex account with a Beacon integration and API key.<\/li>\n<li>Outbound HTTPS access to <code>api.vulndex.at<\/code>.<\/li>\n<li>A working WP-Cron setup for scheduled reports.<\/li>\n<\/ul>\n\n<h3>External Service and Privacy<\/h3>\n\n<p>This plugin connects to VulnDex, an external vulnerability management service. The service is required to receive the reported inventory, correlate versions with known vulnerability information, and display the results in VulnDex. A VulnDex account and API key are required to use these features.<\/p>\n\n<p>No request is sent to VulnDex until a non-empty API key has been saved. Once configured, the plugin sends reports:<\/p>\n\n<ul>\n<li>On the recurring two-hour WP-Cron schedule. Actual timing depends on WordPress cron execution and site traffic.<\/li>\n<li>Shortly after an API key is added or changed.<\/li>\n<li>After plugin activation or deactivation, a theme switch, or a WordPress update operation.<\/li>\n<li>When an administrator manually starts a report.<\/li>\n<\/ul>\n\n<p>Reports are sent by HTTPS POST to <code>https:\/\/api.vulndex.at\/beacon\/wordpress<\/code>. The API key is included as a Bearer credential in the Authorization header.<\/p>\n\n<p>The report payload contains:<\/p>\n\n<ul>\n<li>A randomly generated Node ID that identifies the site in VulnDex.<\/li>\n<li>WordPress and PHP versions.<\/li>\n<li>Site URL and home URL.<\/li>\n<li>Installed plugin path, slug\/text domain, name, version, and activation status.<\/li>\n<li>Installed theme stylesheet identifier, name, version, and activation status.<\/li>\n<li>Operating-system and host\/kernel information returned by PHP's <code>php_uname()<\/code> function, when available.<\/li>\n<\/ul>\n\n<p>The report payload does not include WordPress user accounts, posts, pages, comments, media, passwords, database content, or file contents. As with any HTTPS request, the receiving server may also process connection metadata such as the server's public IP address and request time.<\/p>\n\n<p>Learn more about the <a href=\"https:\/\/vulndex.at\/de\/platform\/beacon\">VulnDex Beacon service<\/a>, the <a href=\"https:\/\/vulndex.at\/privacy\">VulnDex Privacy Policy<\/a>, and the <a href=\"https:\/\/vulndex.at\/imprint\">provider details<\/a>.<\/p>\n\n<h3>License<\/h3>\n\n<p>VulnDex Beacon is free software licensed under GPLv2 or later. You may redistribute or modify it under the terms of the GNU General Public License as published by the Free Software Foundation.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Install VulnDex Beacon from the WordPress plugin directory, or upload it to <code>\/wp-content\/plugins\/vulndex-beacon<\/code>.<\/li>\n<li>Activate the plugin. Activation creates a unique Node ID and schedules the recurring WP-Cron event; it does not send data without an API key.<\/li>\n<li>Create a WordPress Beacon integration in VulnDex and obtain its API key. See the <a href=\"https:\/\/vulndex.at\/docs\/10-vulndex-docs\/127-beacon\">VulnDex Beacon documentation<\/a>.<\/li>\n<li>In WordPress, go to Settings &gt; VulnDex Beacon, enter the API key, and save the settings.<\/li>\n<li>Check the latest API status or use Send data manually to verify the connection.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"is%20a%20vulndex%20account%20required%3F\"><h3>Is a VulnDex account required?<\/h3><\/dt>\n<dd><p>Yes. The plugin requires an API key for a WordPress Beacon integration in VulnDex. Without an API key, the plugin stores its local Node ID and schedule but does not contact the VulnDex API.<\/p><\/dd>\n<dt id=\"does%20the%20plugin%20scan%20or%20protect%20my%20site%3F\"><h3>Does the plugin scan or protect my site?<\/h3><\/dt>\n<dd><p>No. VulnDex Beacon reports component and system inventory. It does not inspect files or traffic, detect malware, apply updates, block attacks, or replace other security controls.<\/p><\/dd>\n<dt id=\"what%20happens%20to%20the%20reported%20versions%3F\"><h3>What happens to the reported versions?<\/h3><\/dt>\n<dd><p>VulnDex uses the inventory to show relevant known vulnerabilities and maintain the current version state. Within VulnDex, Beacon data can be assigned to teams or products and version changes can be reviewed over time.<\/p><\/dd>\n<dt id=\"how%20often%20does%20synchronization%20run%3F\"><h3>How often does synchronization run?<\/h3><\/dt>\n<dd><p>The recurring report is scheduled every two hours with WP-Cron. Reports are also scheduled after relevant plugin, theme, or update events, and administrators can start one manually. Because WP-Cron is traffic-driven by default, the exact time may vary on low-traffic sites.<\/p><\/dd>\n<dt id=\"does%20the%20plugin%20send%20wordpress%20content%20or%20user%20data%3F\"><h3>Does the plugin send WordPress content or user data?<\/h3><\/dt>\n<dd><p>The application payload does not include WordPress user accounts, posts, pages, comments, media, database content, or file contents. It does include the technical inventory, URLs, identifiers, and system information listed in the External Service and Privacy section.<\/p><\/dd>\n<dt id=\"what%20happens%20when%20i%20deactivate%20or%20uninstall%20the%20plugin%3F\"><h3>What happens when I deactivate or uninstall the plugin?<\/h3><\/dt>\n<dd><p>Deactivation removes the plugin's scheduled events but retains its local configuration. Uninstallation deletes the locally stored API key, Node ID, and latest connection status. Data already stored by VulnDex is not deleted automatically; contact your organization's VulnDex administrator to remove it.<\/p><\/dd>\n<dt id=\"where%20can%20i%20get%20help%3F\"><h3>Where can I get help?<\/h3><\/dt>\n<dd><p>See the <a href=\"https:\/\/vulndex.at\/docs\/\">VulnDex documentation<\/a> or use the <a href=\"https:\/\/wordpress.org\/support\/plugin\/vulndex-beacon\/\">WordPress.org support forum<\/a>.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.3<\/h4>\n\n<ul>\n<li>Updated the WordPress compatibility declaration to 7.1.<\/li>\n<li>Expanded the plugin documentation, FAQ, and external-service disclosure.<\/li>\n<\/ul>\n\n<h4>1.0.2<\/h4>\n\n<ul>\n<li>Updated the WordPress compatibility declaration to 7.0.<\/li>\n<li>Adjusted the recurring two-hour schedule definition.<\/li>\n<\/ul>\n\n<h4>1.0.1<\/h4>\n\n<ul>\n<li>Updated the WordPress compatibility declaration to 6.9.<\/li>\n<li>Updated the official VulnDex website and privacy links.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release.<\/li>\n<li>Added automatic reporting for WordPress core, plugins, and themes.<\/li>\n<li>Added the two-hour sync schedule.<\/li>\n<li>Added the connection status and manual send action.<\/li>\n<\/ul>","raw_excerpt":"Keep WordPress core, plugin, and theme inventory current in VulnDex for coordinated vulnerability management.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ko.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/260439","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ko.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/ko.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/ko.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=260439"}],"author":[{"embeddable":true,"href":"https:\/\/ko.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/vulndex"}],"wp:attachment":[{"href":"https:\/\/ko.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=260439"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/ko.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=260439"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/ko.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=260439"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/ko.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=260439"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/ko.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=260439"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/ko.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=260439"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}