A single-site owner patches one installation after a vulnerability surfaces. An agency operator discovers the same plugin running across thirty client sites and faces a triage and execution problem. This guide builds a repeatable fleet-level process: inventory every plugin across your entire client fleet, score each one against four risk signals, triage by exposure and business sensitivity, and act systematically without touching each site individually.
Monthly is a reasonable baseline for most agency fleets. Weekly scans are worth considering for sites that handle e-commerce, membership data, or financial transactions. Beyond a fixed cadence, run an unscheduled audit any time a significant vulnerability is publicly disclosed for a widely-used plugin, or when a batch of new sites joins the fleet.
Yes. Inactive plugins remain on the server. Depending on server configuration, deactivated code with a known vulnerability can still be exploited. A complete fleet audit includes inactive installations. The inactive status informs the remediation path, but it does not exempt the plugin from the audit scope or the risk score.
Most checklists stop at update status and miss installation density. Knowing a plugin is outdated is less useful than knowing it is outdated on nineteen of your forty client sites. Density determines the blast radius of any given risk and should drive triage order, not the risk signal alone.
Document the refusal in writing and reference the specific vulnerability. Include a clause in your service agreement that limits your liability for client-directed inaction on flagged security findings. Some agencies require written sign-off before deferring a flagged security update. The record protects the agency and creates a clear chain of accountability.
They share inventory and scoring infrastructure but serve different goals. An SEO audit focuses on configuration, crawlability, and performance signals. A plugin risk audit focuses on security exposure, abandonment, and update lag. Both can run off the same fleet plugin inventory. SEO plugins are often widely deployed across a fleet and should appear in both audit contexts, which makes running them from a shared inventory more efficient than separate per-site checks.
1,000 free credits. Just describe what you need.
See It In ActionNew to WPOS? Learn what WPOS is and how agencies use it to build and operate client WordPress sites with AI agents.
Part of our guide: WordPress Security for Agency Fleets.