Transparent research methods
Vulnerability Intelligence Methodology
How 3Zero Digital imports, normalizes, interprets, attributes, and presents Wordfence Intelligence vulnerability data.
Production last synchronized: 2026-08-02 09:41:47 UTC. Scanner last synchronized: not yet UTC.
Data source
The system uses the authenticated Wordfence Intelligence V3 Production and Scanner feeds. Production records are the authoritative public research source. Scanner records are stored separately for detection-oriented comparison and are not presented as full public research records.
3Zero Digital is not affiliated with Wordfence. 3Zero Digital did not discover the imported vulnerabilities and does not claim to be their researcher. Wordfence provides the source vulnerability data; 3Zero Digital provides historical aggregation, software-level timelines, interpretation and practical guidance.
Synchronization and duplicates
Wordfence UUIDs are the canonical identifiers. Complete feeds are downloaded to protected temporary storage, validated, hashed, and imported in resumable batches. Unchanged records are not rewritten. If a Production record disappears during a later complete reconciliation, it is archived as source-removed rather than erased.
Patch status and versions
Patch status is reproduced for each affected software entry as supplied in the dataset. A patched label does not mean every installed version is safe; the installed version must be compared with the affected ranges and patched versions. An unpatched label is not evidence that a site is compromised.
CVSS interpretation
CVSS scores, ratings, and vector metrics are supplied by the source and normalized for filtering. They describe technical severity and preconditions, not the business impact of a particular website in isolation. Missing scores remain unknown.
Counts and software quality
A record count is not a direct measure of software quality. Counts can reflect popularity, scrutiny, age, disclosure practices, maintenance history, and dataset coverage. Profiles use neutral statistical wording and require a minimum evidence threshold before indexing.
Research snapshots and reproducibility
Data-driven reports use precomputed snapshots built from active Production Feed records. Each approved snapshot records its source synchronization, dataset cutoff, active-record total, calculation version, methodology version and checksum. A report continues to read one complete approved snapshot while a replacement is being calculated, so visitors never receive a mixture of old and new aggregates.
Records, associations, and complete-year comparisons
A unique vulnerability record is identified by its Wordfence UUID. A software association is one affected plugin, theme, or Core entry attached to a record. One record can therefore create more than one software association, and software-type record totals can overlap. Trend reports identify their denominator explicitly and use complete calendar years unless a result is clearly labelled year to date.
Why update time is not treated as patch time
The source updated timestamp can describe any record revision and is not a reliable patch-publication timestamp. 3Zero therefore does not calculate historical time to patch by subtracting published time from updated time. The research engine now preserves first-observed patch-status timestamps; any future patch-timing report will describe observation time rather than claiming to measure a vendor’s private response time.
Exploitation, infection, and limitations
The presence of a vulnerability record does not prove exploitation or infection. The dataset cannot establish whether a specific website runs the affected software, uses a matching version, exposes the vulnerable path, has compensating controls, or has been attacked. Records may be corrected, updated, or removed by the source.
Public history pages reflect the latest successful Production Feed synchronization shown on each page. Scanner-only records are excluded from public history summaries by default.
Attribution and licence
Public records link to their original Wordfence source. Applicable Defiant/Wordfence and MITRE/CVE notices and licence terms included in each feed record are preserved and displayed with that record. Users should review the linked terms before redistributing data.