{
 "generated": "2026-09-16T17:19:23",
 "inventory_date": "2026-09-16",
 "sites_with_work": 99,
 "priority_totals": {
  "P2": 446,
  "P0": 124,
  "P3": 102,
  "P1": 333,
  "P4": 621
 },
 "sites": {
  "wpengine:bpg1": {
   "platform": "wpengine",
   "install": "bpg1",
   "environment": "production",
   "domain": "investors.bpgr.com",
   "siteurl": "https://bpg1.wpengine.com",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "sage-foundation/resources",
   "updates": [
    {
     "plugin": "advanced-custom-fields-pro",
     "status": "active",
     "active": true,
     "installed": "6.1.6",
     "available": "6.8.10",
     "priority": "P0",
     "vulns": [
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.2.10",
       "cvss": "9.9",
       "severity": "CRITICAL",
       "cve": "CVE-2024-34762"
      },
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.2.10",
       "cvss": "8.5",
       "severity": "HIGH",
       "cve": "CVE-2024-34761"
      },
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.3.8",
       "cvss": "6.6",
       "severity": "MEDIUM",
       "cve": "CVE-2024-9529"
      },
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.3.0",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-4565"
      }
     ],
     "vuln_count": 14,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "multi-minor jump 6.1.6 -> 6.8.10 (skipped 7 minor releases)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "gravityforms",
     "status": "active",
     "active": true,
     "installed": "2.7.17",
     "available": "3.1.1",
     "priority": "P0",
     "vulns": [
      {
       "name": "Gravity Forms [gravityforms] < 2.9.21",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2025-12352"
      },
      {
       "name": "Gravity Forms [gravityforms] < 2.10.1",
       "cvss": "9.6",
       "severity": "CRITICAL",
       "cve": "CVE-2026-48866"
      },
      {
       "name": "Gravity Forms [gravityforms] < 2.9.22",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2025-12974"
      },
      {
       "name": "Gravity Forms [gravityforms] < 3.0.3",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2026-19513"
      }
     ],
     "vuln_count": 17,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.7.17 -> 3.1.1 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "wp-migrate-db-pro",
     "status": "active",
     "active": true,
     "installed": "2.6.6",
     "available": "2.7.11",
     "priority": "P0",
     "vulns": [
      {
       "name": "WP Migrate [wp-migrate-db-pro] < 2.6.11",
       "cvss": "10.0",
       "severity": "CRITICAL",
       "cve": "CVE-2024-30225"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.6.6 -> 2.7.11"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "post-duplicator",
     "status": "active",
     "active": true,
     "installed": "2.28",
     "available": "3.0.16",
     "priority": "P1",
     "vulns": [
      {
       "name": "Post Duplicator [post-duplicator] < 3.0.11",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-39474"
      },
      {
       "name": "Post Duplicator [post-duplicator] < 2.32",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2023-49835"
      },
      {
       "name": "Post Duplicator [post-duplicator] < 2.37",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2024-12472"
      },
      {
       "name": "Post Duplicator [post-duplicator] < 2.36",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-24736"
      }
     ],
     "vuln_count": 8,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.28 -> 3.0.16 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "wordpress-importer",
     "status": "active",
     "active": true,
     "installed": "0.8.1",
     "available": "0.9.6",
     "priority": "P1",
     "vulns": [
      {
       "name": "WordPress Importer [wordpress-importer] < 0.8.4",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2024-13889"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 0.8.1 -> 0.9.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "advanced-custom-fields-font-awesome",
     "status": "active",
     "active": true,
     "installed": "4.0.5",
     "available": "6.2.0",
     "priority": "P2",
     "vulns": [
      {
       "name": "Advanced Custom Fields: Font Awesome Field [advanced-custom-fields-font-awesome] < 6.0.0",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-49044"
      },
      {
       "name": "Advanced Custom Fields: Font Awesome Field [advanced-custom-fields-font-awesome] < 5.0.2",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-14983"
      },
      {
       "name": "Advanced Custom Fields: Font Awesome Field [advanced-custom-fields-font-awesome] < 6.0.0",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-6415"
      },
      {
       "name": "Advanced Custom Fields: Font Awesome Field [advanced-custom-fields-font-awesome] < 6.1.3",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-66678"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 4.0.5 -> 6.2.0 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "safe-svg",
     "status": "active",
     "active": true,
     "installed": "2.1.1",
     "available": "2.5.0",
     "priority": "P2",
     "vulns": [
      {
       "name": "Safe SVG [safe-svg] < 2.2.6",
       "cvss": "4.8",
       "severity": "MEDIUM",
       "cve": "CVE-2024-8378"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 2.1.1 -> 2.5.0 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "disable-gutenberg",
     "status": "active",
     "active": true,
     "installed": "2.9",
     "available": "3.3.2",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.9 -> 3.3.2 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "post-types-order",
     "status": "active",
     "active": true,
     "installed": "2.0.5",
     "available": "2.5.3",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 2.0.5 -> 2.5.3 (skipped 5 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    }
   ],
   "p0": 3,
   "p1": 2,
   "total_updates": 9
  },
  "wpengine:prod101": {
   "platform": "wpengine",
   "install": "prod101",
   "environment": "production",
   "domain": "101.us",
   "siteurl": "https://101.us",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "Impreza-child",
   "updates": [
    {
     "plugin": "elementor-pro",
     "status": "inactive",
     "active": false,
     "installed": "4.0.1",
     "available": null,
     "priority": "P0",
     "vulns": [
      {
       "name": "Elementor Pro [elementor-pro] < 4.2.2",
       "cvss": "9.0",
       "severity": "CRITICAL",
       "cve": "CVE-2026-32475"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "gravityforms",
     "status": "active",
     "active": true,
     "installed": "2.10.5",
     "available": "3.1.1",
     "priority": "P1",
     "vulns": [
      {
       "name": "Gravity Forms [gravityforms] < 3.0.3",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2026-19513"
      },
      {
       "name": "Gravity Forms [gravityforms] < 3.0.0",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-16649"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.10.5 -> 3.1.1 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "all-in-one-wp-migration",
     "status": "inactive",
     "active": false,
     "installed": "7.105",
     "available": "7.111",
     "priority": "P1",
     "vulns": [
      {
       "name": "All-in-One WP Migration and Backup [all-in-one-wp-migration] < 7.110",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-19949"
      },
      {
       "name": "All-in-One WP Migration and Backup [all-in-one-wp-migration] < 7.106",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-12898"
      },
      {
       "name": "All-in-One WP Migration and Backup [all-in-one-wp-migration] < 7.108",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-17533"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 7.105 -> 7.111 (skipped 6 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wp-smushit",
     "status": "inactive",
     "active": false,
     "installed": "4.0.3",
     "available": "4.3.3",
     "priority": "P1",
     "vulns": [
      {
       "name": "Smush \u2013 Image Optimization, Compression, Lazy Load, WebP &amp; CDN [wp-smushit] < 4.3.0",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-81285"
      },
      {
       "name": "Smush \u2013 Image Optimization, Compression, Lazy Load, WebP &amp; CDN [wp-smushit] < 4.3.2",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-19223"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 4.0.3 -> 4.3.3 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "insert-headers-and-footers",
     "status": "inactive",
     "active": false,
     "installed": "2.3.5",
     "available": "2.3.9",
     "priority": "P1",
     "vulns": [
      {
       "name": "WPCode &#8211; Insert Headers and Footers + Custom Code Snippets &#8211; WordPress Code Manager [insert-headers-and-footers] < 2.3.6",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-8832"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 2.3.5 -> 2.3.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wp-fastest-cache",
     "status": "inactive",
     "active": false,
     "installed": "1.4.8",
     "available": "1.5.2",
     "priority": "P1",
     "vulns": [
      {
       "name": "WP Fastest Cache &#8211; WordPress Cache Plugin [wp-fastest-cache] < 1.5.1",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-74932"
      },
      {
       "name": "WP Fastest Cache &#8211; WordPress Cache Plugin [wp-fastest-cache] < 1.5.1",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-19760"
      },
      {
       "name": "WP Fastest Cache &#8211; WordPress Cache Plugin [wp-fastest-cache] < 1.5.1",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-74916"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.4.8 -> 1.5.2"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "styles-and-layouts-for-gravity-forms",
     "status": "active",
     "active": true,
     "installed": "5.26",
     "available": "6.1",
     "priority": "P2",
     "vulns": [
      {
       "name": "Gravity Booster &#8211; Styles &amp; Layouts for Gravity Forms [styles-and-layouts-for-gravity-forms] <= 6.0 (unfixed)",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-74004"
      },
      {
       "name": "Gravity Booster &#8211; Styles &amp; Layouts for Gravity Forms [styles-and-layouts-for-gravity-forms] < 6.0",
       "cvss": "4.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-12477"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 5.26 -> 6.1 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "wordpress-seo",
     "status": "active",
     "active": true,
     "installed": "27.6",
     "available": "28.5",
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 28.1",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-15425"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 27.6 -> 28.5 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "advanced-custom-fields",
     "status": "inactive",
     "active": false,
     "installed": "6.8.0",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Advanced Custom Fields (ACF\u00ae) [advanced-custom-fields] < 6.8.2",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-8382"
      },
      {
       "name": "Advanced Custom Fields (ACF\u00ae) [advanced-custom-fields] < 6.8.2",
       "cvss": null,
       "severity": null,
       "cve": ""
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "all-in-one-wp-migration-unlimited-extension",
     "status": "inactive",
     "active": false,
     "installed": "2.84",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "All-in-One WP Migration Unlimited Extension [all-in-one-wp-migration-unlimited-extension] < 2.85",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-6128"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "elementor",
     "status": "inactive",
     "active": false,
     "installed": "4.0.8",
     "available": "4.2.4",
     "priority": "P2",
     "vulns": [
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 4.1.4",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-57619"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 4.1.1",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-49782"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 4.1.4",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-8825"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "minor version bump 4.0.8 -> 4.2.4",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "limit-login-attempts-reloaded",
     "status": "inactive",
     "active": false,
     "installed": "3.2.3",
     "available": "3.3.8",
     "priority": "P2",
     "vulns": [
      {
       "name": "Limit Login Attempts Security &#8211; Login Security, 2FA, Firewall, Brute Force Prevention [limit-login-attempts-reloaded] < 3.3.5",
       "cvss": "3.7",
       "severity": "LOW",
       "cve": "CVE-2026-18356"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 3.2.3 -> 3.3.8"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "svg-support",
     "status": "inactive",
     "active": false,
     "installed": "2.5.14",
     "available": "2.6.1",
     "priority": "P2",
     "vulns": [
      {
       "name": "SVG Support [svg-support] < 2.5.15",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-48973"
      },
      {
       "name": "SVG Support [svg-support] < 2.5.17",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-13340"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.5.14 -> 2.6.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "white-label-cms",
     "status": "inactive",
     "active": false,
     "installed": "2.7.12",
     "available": "2.7.14",
     "priority": "P2",
     "vulns": [
      {
       "name": "White Label CMS [white-label-cms] < 2.7.13",
       "cvss": "4.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-11898"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 2.7.12 -> 2.7.14"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wp-2fa",
     "status": "inactive",
     "active": false,
     "installed": "3.1.1.2",
     "available": "4.1.0",
     "priority": "P2",
     "vulns": [
      {
       "name": "WP 2FA &#8211; Two-factor authentication for WordPress [wp-2fa] < 4.1.0",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-15372"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.1.1.2 -> 4.1.0 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "hcaptcha-for-forms-and-more",
     "status": "active",
     "active": true,
     "installed": "4.26.0",
     "available": "5.3.0",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 4.26.0 -> 5.3.0 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "disable-wp-notification",
     "status": "inactive",
     "active": false,
     "installed": "3.4",
     "available": "4.3",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.4 -> 4.3 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "accessibility-widget",
     "status": "active",
     "active": true,
     "installed": "3.2.1",
     "available": "3.2.6",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 3.2.1 -> 3.2.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "contact-form-7",
     "status": "active",
     "active": true,
     "installed": "6.1.5",
     "available": "6.1.7",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 6.1.5 -> 6.1.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "cookie-law-info",
     "status": "active",
     "active": true,
     "installed": "3.4.2",
     "available": "3.5.6",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 3.4.2 -> 3.5.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "redirection",
     "status": "active",
     "active": true,
     "installed": "5.9.0",
     "available": "5.10.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 5.9.0 -> 5.10.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "safe-svg",
     "status": "active",
     "active": true,
     "installed": "2.4.0",
     "available": "2.5.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.4.0 -> 2.5.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wordpress-importer",
     "status": "active",
     "active": true,
     "installed": "0.9.5",
     "available": "0.9.6",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 0.9.5 -> 0.9.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wp-add-mime-types",
     "status": "active",
     "active": true,
     "installed": "3.1.2",
     "available": "3.2.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 3.1.2 -> 3.2.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "akismet",
     "status": "inactive",
     "active": false,
     "installed": "5.7",
     "available": "5.7.2",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 5.7 -> 5.7.2"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "pojo-accessibility",
     "status": "inactive",
     "active": false,
     "installed": "4.1.1",
     "available": "4.1.4",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 4.1.1 -> 4.1.4"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "custom-post-type-ui",
     "status": "inactive",
     "active": false,
     "installed": "1.19.2",
     "available": "1.19.3",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.19.2 -> 1.19.3"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "headers-security-advanced-hsts-wp",
     "status": "inactive",
     "active": false,
     "installed": "5.3.2",
     "available": "5.3.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 5.3.2 -> 5.3.5"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "post-types-order",
     "status": "inactive",
     "active": false,
     "installed": "2.4.6",
     "available": "2.5.3",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.4.6 -> 2.5.3"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "shortpixel-image-optimiser",
     "status": "inactive",
     "active": false,
     "installed": "6.5.1",
     "available": "6.5.6",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 6.5.1 -> 6.5.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wp-optimize",
     "status": "inactive",
     "active": false,
     "installed": "4.5.3",
     "available": "4.6.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "minor version bump 4.5.3 -> 4.6.1",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wp-mail-smtp",
     "status": "inactive",
     "active": false,
     "installed": "4.8.0",
     "available": "4.9.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 4.8.0 -> 4.9.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    }
   ],
   "p0": 1,
   "p1": 5,
   "total_updates": 29
  },
  "wpengine:ckuriakose": {
   "platform": "wpengine",
   "install": "ckuriakose",
   "environment": "production",
   "domain": "ckuriakose.wpengine.com",
   "siteurl": "https://ckuriakose.wpengine.com",
   "core": "7.0.3",
   "core_update": "7.0.4",
   "theme": "hello-elementor",
   "updates": [
    {
     "plugin": "elementor",
     "status": "active",
     "active": true,
     "installed": "3.11.0",
     "available": "4.2.4",
     "priority": "P0",
     "vulns": [
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.18.2",
       "cvss": "9.9",
       "severity": "CRITICAL",
       "cve": "CVE-2023-48777"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.19.1",
       "cvss": "8.5",
       "severity": "HIGH",
       "cve": "CVE-2024-24934"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.12.2",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2023-0329"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.16.5",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2023-47505"
      }
     ],
     "vuln_count": 34,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.11.0 -> 4.2.4 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "elementor-pro",
     "status": "active",
     "active": true,
     "installed": "3.11.0",
     "available": "3.11.1",
     "priority": "P0",
     "vulns": [
      {
       "name": "Elementor Pro [elementor-pro] < 4.2.2",
       "cvss": "9.0",
       "severity": "CRITICAL",
       "cve": "CVE-2026-32475"
      },
      {
       "name": "Elementor Pro [elementor-pro] < 3.11.7",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2023-3124"
      },
      {
       "name": "Elementor Pro [elementor-pro] < 3.19.3",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-23523"
      },
      {
       "name": "Elementor Pro [elementor-pro] < 3.25.11",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-8494"
      }
     ],
     "vuln_count": 15,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "patch bump 3.11.0 -> 3.11.1",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "advanced-custom-fields",
     "status": "active",
     "active": true,
     "installed": "6.0.7",
     "available": "6.8.10",
     "priority": "P1",
     "vulns": [
      {
       "name": "Advanced Custom Fields (ACF\u00ae) [advanced-custom-fields] < 6.1.6",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2023-30777"
      },
      {
       "name": "Advanced Custom Fields (ACF\u00ae) [advanced-custom-fields] < 6.3.8",
       "cvss": "6.6",
       "severity": "MEDIUM",
       "cve": "CVE-2024-9529"
      },
      {
       "name": "Advanced Custom Fields (ACF\u00ae) [advanced-custom-fields] < 6.3.0",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-4565"
      },
      {
       "name": "Advanced Custom Fields (ACF\u00ae) [advanced-custom-fields] < 6.3.6",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2024-45429"
      }
     ],
     "vuln_count": 13,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "multi-minor jump 6.0.7 -> 6.8.10 (skipped 8 minor releases)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "ewww-image-optimizer",
     "status": "active",
     "active": true,
     "installed": "6.9.3",
     "available": "8.7.7",
     "priority": "P1",
     "vulns": [
      {
       "name": "EWWW Image Optimizer [ewww-image-optimizer] < 8.7.7",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-84773"
      },
      {
       "name": "EWWW Image Optimizer [ewww-image-optimizer] < 8.7.4",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-15446"
      },
      {
       "name": "EWWW Image Optimizer [ewww-image-optimizer] < 7.2.1",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2023-40600"
      },
      {
       "name": "EWWW Image Optimizer [ewww-image-optimizer] < 7.3.0",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2024-31924"
      }
     ],
     "vuln_count": 6,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 6.9.3 -> 8.7.7 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "jet-tricks",
     "status": "active",
     "active": true,
     "installed": "1.4.3",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "JetTricks [jet-tricks] < 1.4.6.2",
       "cvss": "8.2",
       "severity": "HIGH",
       "cve": "CVE-2023-48760"
      },
      {
       "name": "JetTricks [jet-tricks] < 1.5.1.1",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2025-26942"
      },
      {
       "name": "JetTricks [jet-tricks] < 1.5.4.2",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-53992"
      },
      {
       "name": "JetTricks [jet-tricks] < 1.4.6.2",
       "cvss": "6.3",
       "severity": "MEDIUM",
       "cve": "CVE-2023-48762"
      }
     ],
     "vuln_count": 6,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "insert-headers-and-footers",
     "status": "active",
     "active": true,
     "installed": "2.0.7",
     "available": "2.3.9",
     "priority": "P1",
     "vulns": [
      {
       "name": "WPCode &#8211; Insert Headers and Footers + Custom Code Snippets &#8211; WordPress Code Manager [insert-headers-and-footers] < 2.3.6",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-8832"
      },
      {
       "name": "WPCode &#8211; Insert Headers and Footers + Custom Code Snippets &#8211; WordPress Code Manager [insert-headers-and-footers] < 2.0.9",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2023-1624"
      },
      {
       "name": "WPCode &#8211; Insert Headers and Footers + Custom Code Snippets &#8211; WordPress Code Manager [insert-headers-and-footers] < 2.0.13.1",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2023-3524"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 2.0.7 -> 2.3.9 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "custom-post-type-ui",
     "status": "active",
     "active": true,
     "installed": "1.13.4",
     "available": "1.19.3",
     "priority": "P2",
     "vulns": [
      {
       "name": "Custom Post Type UI [custom-post-type-ui] < 1.13.5",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2023-1623"
      },
      {
       "name": "Custom Post Type UI [custom-post-type-ui] < 1.18.1",
       "cvss": "4.8",
       "severity": "MEDIUM",
       "cve": "CVE-2025-12826"
      },
      {
       "name": "Custom Post Type UI [custom-post-type-ui] < 1.18.2",
       "cvss": "4.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-14056"
      },
      {
       "name": "Custom Post Type UI [custom-post-type-ui] < 1.13.5",
       "cvss": null,
       "severity": null,
       "cve": ""
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 1.13.4 -> 1.19.3 (skipped 6 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "limit-login-attempts-reloaded",
     "status": "active",
     "active": true,
     "installed": "2.25.12",
     "available": "3.3.8",
     "priority": "P2",
     "vulns": [
      {
       "name": "Limit Login Attempts Security &#8211; Login Security, 2FA, Firewall, Brute Force Prevention [limit-login-attempts-reloaded] < 2.25.27",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2023-6934"
      },
      {
       "name": "Limit Login Attempts Security &#8211; Login Security, 2FA, Firewall, Brute Force Prevention [limit-login-attempts-reloaded] < 2.25.26",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2023-5525"
      },
      {
       "name": "Limit Login Attempts Security &#8211; Login Security, 2FA, Firewall, Brute Force Prevention [limit-login-attempts-reloaded] < 3.3.5",
       "cvss": "3.7",
       "severity": "LOW",
       "cve": "CVE-2026-18356"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.25.12 -> 3.3.8 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "pojo-accessibility",
     "status": "active",
     "active": true,
     "installed": "2.1.0",
     "available": "4.1.4",
     "priority": "P2",
     "vulns": [
      {
       "name": "Web Accessibility (formally known as Ally) &#8211; WCAG Scanning, Guided Fixes, Usability Widget [pojo-accessibility] < 4.0.3",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-25386"
      },
      {
       "name": "Web Accessibility (formally known as Ally) &#8211; WCAG Scanning, Guided Fixes, Usability Widget [pojo-accessibility] < 3.8.1",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-10700"
      },
      {
       "name": "Web Accessibility (formally known as Ally) &#8211; WCAG Scanning, Guided Fixes, Usability Widget [pojo-accessibility] < 3.2.0",
       "cvss": "0.0",
       "severity": null,
       "cve": "CVE-2025-32640"
      },
      {
       "name": "Web Accessibility (formally known as Ally) &#8211; WCAG Scanning, Guided Fixes, Usability Widget [pojo-accessibility] < 4.1.0",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-2413"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.1.0 -> 4.1.4 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "svg-support",
     "status": "active",
     "active": true,
     "installed": "2.5.5",
     "available": "2.6.1",
     "priority": "P2",
     "vulns": [
      {
       "name": "SVG Support [svg-support] < 2.5.11",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-10222"
      },
      {
       "name": "SVG Support [svg-support] < 2.5.9",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2022-23638"
      },
      {
       "name": "SVG Support [svg-support] < 2.5.8",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2023-6708"
      },
      {
       "name": "SVG Support [svg-support] < 2.5.15",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-48973"
      }
     ],
     "vuln_count": 5,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.5.5 -> 2.6.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "genesis-blocks",
     "status": "inactive",
     "active": false,
     "installed": "1.5.4",
     "available": "3.1.11",
     "priority": "P2",
     "vulns": [
      {
       "name": "Genesis Blocks [genesis-blocks] < 3.1.3",
       "cvss": "6.8",
       "severity": "MEDIUM",
       "cve": "CVE-2024-2761"
      },
      {
       "name": "Genesis Blocks [genesis-blocks] < 3.1.4",
       "cvss": "6.8",
       "severity": "MEDIUM",
       "cve": "CVE-2024-3901"
      },
      {
       "name": "Genesis Blocks [genesis-blocks] < 3.1.3",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-1946"
      },
      {
       "name": "Genesis Blocks [genesis-blocks] < 3.1.4",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-3563"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 1.5.4 -> 3.1.11 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "disable-wp-notification",
     "status": "active",
     "active": true,
     "installed": "3.0",
     "available": "4.3",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.0 -> 4.3 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "dreamhost-automated-migration",
     "status": "active",
     "active": true,
     "installed": "4.78",
     "available": "6.72",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 4.78 -> 6.72 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "wp-widget-disable",
     "status": "active",
     "active": true,
     "installed": "2.1.0",
     "available": "3.0.1",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.1.0 -> 3.0.1 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "admin-taxonomy-filter",
     "status": "active",
     "active": true,
     "installed": "1.0.2",
     "available": "1.0.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.0.2 -> 1.0.5"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "classic-editor",
     "status": "active",
     "active": true,
     "installed": "1.6.2",
     "available": "1.7.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.6.2 -> 1.7.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "cookie-law-info",
     "status": "active",
     "active": true,
     "installed": "3.0.8",
     "available": "3.5.6",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.0.8 -> 3.5.6 (skipped 5 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "disable-json-api",
     "status": "active",
     "active": true,
     "installed": "1.7",
     "available": "1.8",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.7 -> 1.8"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "disable-xml-rpc-api",
     "status": "active",
     "active": true,
     "installed": "2.1.4.7",
     "available": "2.1.7",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 2.1.4.7 -> 2.1.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "duplicate-page",
     "status": "active",
     "active": true,
     "installed": "4.5.1",
     "available": "4.5.9",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 4.5.1 -> 4.5.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "headers-security-advanced-hsts-wp",
     "status": "active",
     "active": true,
     "installed": "5.0.20",
     "available": "5.3.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.0.20 -> 5.3.5 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wp-revisions-control",
     "status": "active",
     "active": true,
     "installed": "1.4.3",
     "available": "1.4.4",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.4.3 -> 1.4.4"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "akismet",
     "status": "inactive",
     "active": false,
     "installed": "5.0.1",
     "available": "5.7.2",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.0.1 -> 5.7.2 (skipped 7 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    }
   ],
   "p0": 2,
   "p1": 4,
   "total_updates": 22
  },
  "wpengine:norwestdev": {
   "platform": "wpengine",
   "install": "norwestdev",
   "environment": "development",
   "domain": "norwestdev.wpengine.com",
   "siteurl": "https://norwestdev.wpengine.com",
   "core": "7.0.3",
   "core_update": "7.0.4",
   "theme": "brand-nav-child-theme",
   "updates": [
    {
     "plugin": "advanced-custom-fields-pro",
     "status": "active",
     "active": true,
     "installed": "6.1.6",
     "available": "6.8.10",
     "priority": "P0",
     "vulns": [
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.2.10",
       "cvss": "9.9",
       "severity": "CRITICAL",
       "cve": "CVE-2024-34762"
      },
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.2.10",
       "cvss": "8.5",
       "severity": "HIGH",
       "cve": "CVE-2024-34761"
      },
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.3.8",
       "cvss": "6.6",
       "severity": "MEDIUM",
       "cve": "CVE-2024-9529"
      },
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.3.0",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-4565"
      }
     ],
     "vuln_count": 14,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "multi-minor jump 6.1.6 -> 6.8.10 (skipped 7 minor releases)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "elementor",
     "status": "active",
     "active": true,
     "installed": "3.13.3",
     "available": "4.2.4",
     "priority": "P0",
     "vulns": [
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.18.2",
       "cvss": "9.9",
       "severity": "CRITICAL",
       "cve": "CVE-2023-48777"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.19.1",
       "cvss": "8.5",
       "severity": "HIGH",
       "cve": "CVE-2024-24934"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.16.5",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2023-47505"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.16.5",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2023-47504"
      }
     ],
     "vuln_count": 28,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.13.3 -> 4.2.4 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "elementor-pro",
     "status": "active",
     "active": true,
     "installed": "3.13.2",
     "available": null,
     "priority": "P0",
     "vulns": [
      {
       "name": "Elementor Pro [elementor-pro] < 4.2.2",
       "cvss": "9.0",
       "severity": "CRITICAL",
       "cve": "CVE-2026-32475"
      },
      {
       "name": "Elementor Pro [elementor-pro] < 3.19.3",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-23523"
      },
      {
       "name": "Elementor Pro [elementor-pro] < 3.25.11",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-8494"
      },
      {
       "name": "Elementor Pro [elementor-pro] < 3.29.1",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-50555"
      }
     ],
     "vuln_count": 12,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "better-search-replace",
     "status": "inactive",
     "active": false,
     "installed": "1.4.2",
     "available": "1.4.11",
     "priority": "P0",
     "vulns": [
      {
       "name": "Better Search Replace [better-search-replace] < 1.4.5",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2023-6933"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.4.2 -> 1.4.11"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "jet-elements",
     "status": "inactive",
     "active": false,
     "installed": "2.6.9",
     "available": null,
     "priority": "P0",
     "vulns": [
      {
       "name": "JetElements For Elementor [jet-elements] < 2.6.11",
       "cvss": "9.0",
       "severity": "CRITICAL",
       "cve": "CVE-2023-39157"
      },
      {
       "name": "JetElements For Elementor [jet-elements] < 2.6.20.1",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2024-7145"
      },
      {
       "name": "JetElements For Elementor [jet-elements] < 2.6.13.1",
       "cvss": "8.2",
       "severity": "HIGH",
       "cve": "CVE-2023-48760"
      },
      {
       "name": "JetElements For Elementor [jet-elements] < 2.6.13.1",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2023-48759"
      }
     ],
     "vuln_count": 17,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "jet-smart-filters",
     "status": "inactive",
     "active": false,
     "installed": "3.1.1",
     "available": null,
     "priority": "P0",
     "vulns": [
      {
       "name": "JetSmartFilters [jet-smart-filters] < 3.8.1.1",
       "cvss": "9.3",
       "severity": "CRITICAL",
       "cve": "CVE-2026-48875"
      },
      {
       "name": "JetSmartFilters [jet-smart-filters] < 3.8.3.1",
       "cvss": "9.3",
       "severity": "CRITICAL",
       "cve": "CVE-2026-56067"
      },
      {
       "name": "JetSmartFilters [jet-smart-filters] < 3.2.2.1",
       "cvss": "8.2",
       "severity": "HIGH",
       "cve": "CVE-2023-48760"
      },
      {
       "name": "JetSmartFilters [jet-smart-filters] < 3.6.7.1",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-54008"
      }
     ],
     "vuln_count": 8,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "wp-file-manager",
     "status": "inactive",
     "active": false,
     "installed": "7.1.8",
     "available": "8.0.4",
     "priority": "P0",
     "vulns": [
      {
       "name": "File Manager [wp-file-manager] < 7.2.2",
       "cvss": "9.9",
       "severity": "CRITICAL",
       "cve": "CVE-2023-6825"
      },
      {
       "name": "File Manager [wp-file-manager] < 7.2.5",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2024-1538"
      },
      {
       "name": "File Manager [wp-file-manager] < 7.2.2",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2024-0761"
      },
      {
       "name": "File Manager [wp-file-manager] < 7.2.6",
       "cvss": "6.8",
       "severity": "MEDIUM",
       "cve": "CVE-2024-2654"
      }
     ],
     "vuln_count": 6,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 7.1.8 -> 8.0.4 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wp-server-stats",
     "status": "inactive",
     "active": false,
     "installed": "1.7.3",
     "available": "1.9.1",
     "priority": "P0",
     "vulns": [
      {
       "name": "WP Server Health Stats [wp-server-stats] < 1.7.7",
       "cvss": "10.0",
       "severity": "CRITICAL",
       "cve": "CVE-2024-6297"
      },
      {
       "name": "WP Server Health Stats [wp-server-stats] < 1.7.4",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2024-31250"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.7.3 -> 1.9.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "dynamic-content-for-elementor",
     "status": "active",
     "active": true,
     "installed": "2.9.4",
     "available": "2.10.6",
     "priority": "P1",
     "vulns": [
      {
       "name": "Dynamic Content for Elementor [dynamic-content-for-elementor] < 2.12.5",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2023-52150"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "minor version bump 2.9.4 -> 2.10.6",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "shortpixel-image-optimiser",
     "status": "active",
     "active": true,
     "installed": "5.2.1",
     "available": "6.5.6",
     "priority": "P1",
     "vulns": [
      {
       "name": "ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 5.6.4",
       "cvss": "7.6",
       "severity": "HIGH",
       "cve": "CVE-2024-48043"
      },
      {
       "name": "ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 6.4.4",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-39471"
      },
      {
       "name": "ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 5.6.4",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-48044"
      },
      {
       "name": "ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 6.3.5",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-11378"
      }
     ],
     "vuln_count": 9,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 5.2.1 -> 6.5.6 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "wp-2fa",
     "status": "active",
     "active": true,
     "installed": "2.4.1",
     "available": "4.1.0",
     "priority": "P1",
     "vulns": [
      {
       "name": "WP 2FA &#8211; Two-factor authentication for WordPress [wp-2fa] < 2.6.3",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2024-32568"
      },
      {
       "name": "WP 2FA &#8211; Two-factor authentication for WordPress [wp-2fa] < 3.0.0",
       "cvss": "6.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-12628"
      },
      {
       "name": "WP 2FA &#8211; Two-factor authentication for WordPress [wp-2fa] < 2.6.4",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2022-44587"
      },
      {
       "name": "WP 2FA &#8211; Two-factor authentication for WordPress [wp-2fa] < 2.6.0",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2023-6506"
      }
     ],
     "vuln_count": 7,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.4.1 -> 4.1.0 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "insert-headers-and-footers",
     "status": "active",
     "active": true,
     "installed": "2.0.11",
     "available": "2.3.9",
     "priority": "P1",
     "vulns": [
      {
       "name": "WPCode &#8211; Insert Headers and Footers + Custom Code Snippets &#8211; WordPress Code Manager [insert-headers-and-footers] < 2.3.6",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-8832"
      },
      {
       "name": "WPCode &#8211; Insert Headers and Footers + Custom Code Snippets &#8211; WordPress Code Manager [insert-headers-and-footers] < 2.0.13.1",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2023-3524"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 2.0.11 -> 2.3.9 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "woocommerce-ajax-filters",
     "status": "inactive",
     "active": false,
     "installed": "1.6.4.1",
     "available": "3.3",
     "priority": "P1",
     "vulns": [
      {
       "name": "Advanced AJAX Product Filters [woocommerce-ajax-filters] < 3.2.1",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-66439"
      },
      {
       "name": "Advanced AJAX Product Filters [woocommerce-ajax-filters] < 1.6.8.2",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2025-1505"
      },
      {
       "name": "Advanced AJAX Product Filters [woocommerce-ajax-filters] < 3.1.9.7",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-1426"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 1.6.4.1 -> 3.3 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "advanced-custom-fields",
     "status": "inactive",
     "active": false,
     "installed": "6.0.7",
     "available": "6.8.10",
     "priority": "P1",
     "vulns": [
      {
       "name": "Advanced Custom Fields (ACF\u00ae) [advanced-custom-fields] < 6.1.6",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2023-30777"
      },
      {
       "name": "Advanced Custom Fields (ACF\u00ae) [advanced-custom-fields] < 6.3.8",
       "cvss": "6.6",
       "severity": "MEDIUM",
       "cve": "CVE-2024-9529"
      },
      {
       "name": "Advanced Custom Fields (ACF\u00ae) [advanced-custom-fields] < 6.3.0",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-4565"
      },
      {
       "name": "Advanced Custom Fields (ACF\u00ae) [advanced-custom-fields] < 6.3.6",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2024-45429"
      }
     ],
     "vuln_count": 13,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "multi-minor jump 6.0.7 -> 6.8.10 (skipped 8 minor releases)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "advanced-database-cleaner",
     "status": "inactive",
     "active": false,
     "installed": "3.1.2",
     "available": "4.2.0",
     "priority": "P1",
     "vulns": [
      {
       "name": "Advanced Database Cleaner \u2013 Optimize &amp; Clean Database to Speed Up Site Performance [advanced-database-cleaner] < 3.1.3",
       "cvss": "7.6",
       "severity": "HIGH",
       "cve": "CVE-2023-49764"
      },
      {
       "name": "Advanced Database Cleaner \u2013 Optimize &amp; Clean Database to Speed Up Site Performance [advanced-database-cleaner] < 3.1.4",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2024-0668"
      },
      {
       "name": "Advanced Database Cleaner \u2013 Optimize &amp; Clean Database to Speed Up Site Performance [advanced-database-cleaner] < 3.1.7",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-11497"
      },
      {
       "name": "Advanced Database Cleaner \u2013 Optimize &amp; Clean Database to Speed Up Site Performance [advanced-database-cleaner] < 3.1.7",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-64357"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.1.2 -> 4.2.0 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "ewww-image-optimizer",
     "status": "inactive",
     "active": false,
     "installed": "7.0.0",
     "available": "8.7.7",
     "priority": "P1",
     "vulns": [
      {
       "name": "EWWW Image Optimizer [ewww-image-optimizer] < 8.7.7",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-84773"
      },
      {
       "name": "EWWW Image Optimizer [ewww-image-optimizer] < 8.7.4",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-15446"
      },
      {
       "name": "EWWW Image Optimizer [ewww-image-optimizer] < 7.2.1",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2023-40600"
      },
      {
       "name": "EWWW Image Optimizer [ewww-image-optimizer] < 7.3.0",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2024-31924"
      }
     ],
     "vuln_count": 6,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 7.0.0 -> 8.7.7 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "imagemagick-engine",
     "status": "inactive",
     "active": false,
     "installed": "1.7.7",
     "available": "2.0.0",
     "priority": "P1",
     "vulns": [
      {
       "name": "ImageMagick Engine [imagemagick-engine] < 1.7.11",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2024-6486"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 1.7.7 -> 2.0.0 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "users-customers-import-export-for-wp-woocommerce",
     "status": "inactive",
     "active": false,
     "installed": "2.3.9",
     "available": "2.7.5",
     "priority": "P1",
     "vulns": [
      {
       "name": "Export and Import Users and Customers [users-customers-import-export-for-wp-woocommerce] < 2.6.3",
       "cvss": "7.6",
       "severity": "HIGH",
       "cve": "CVE-2025-1970"
      },
      {
       "name": "Export and Import Users and Customers [users-customers-import-export-for-wp-woocommerce] < 2.4.2",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2023-3459"
      },
      {
       "name": "Export and Import Users and Customers [users-customers-import-export-for-wp-woocommerce] < 2.4.9",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2023-6558"
      },
      {
       "name": "Export and Import Users and Customers [users-customers-import-export-for-wp-woocommerce] < 2.6.3",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2025-1971"
      }
     ],
     "vuln_count": 8,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 2.3.9 -> 2.7.5 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "jetpack",
     "status": "inactive",
     "active": false,
     "installed": "12.0",
     "available": "16.2",
     "priority": "P1",
     "vulns": [
      {
       "name": "Jetpack &#8211; WP Security, Backup, Speed, &amp; Growth [jetpack] < 12.1.1",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2023-2996"
      },
      {
       "name": "Jetpack &#8211; WP Security, Backup, Speed, &amp; Growth [jetpack] < 12.8-a.3",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2023-45050"
      },
      {
       "name": "Jetpack &#8211; WP Security, Backup, Speed, &amp; Growth [jetpack] >= 3.2 - < 16.1.3",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2024-10858"
      },
      {
       "name": "Jetpack &#8211; WP Security, Backup, Speed, &amp; Growth [jetpack] == 11.4",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2023-54332"
      }
     ],
     "vuln_count": 12,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 12.0 -> 16.2 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "jet-tricks",
     "status": "inactive",
     "active": false,
     "installed": "1.4.3",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "JetTricks [jet-tricks] < 1.4.6.2",
       "cvss": "8.2",
       "severity": "HIGH",
       "cve": "CVE-2023-48760"
      },
      {
       "name": "JetTricks [jet-tricks] < 1.5.1.1",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2025-26942"
      },
      {
       "name": "JetTricks [jet-tricks] < 1.5.4.2",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-53992"
      },
      {
       "name": "JetTricks [jet-tricks] < 1.4.6.2",
       "cvss": "6.3",
       "severity": "MEDIUM",
       "cve": "CVE-2023-48762"
      }
     ],
     "vuln_count": 6,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "password-protect-page",
     "status": "inactive",
     "active": false,
     "installed": "1.8.8",
     "available": "1.9.24",
     "priority": "P1",
     "vulns": [
      {
       "name": "PPWP &#8211; Password Protect Pages [password-protect-page] < 1.9.19",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-0551"
      },
      {
       "name": "PPWP &#8211; Password Protect Pages [password-protect-page] < 1.9.11",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-5998"
      },
      {
       "name": "PPWP &#8211; Password Protect Pages [password-protect-page] <= 1.9.21 (unfixed)",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-3639"
      },
      {
       "name": "PPWP &#8211; Password Protect Pages [password-protect-page] <= 1.9.21 (unfixed)",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-9878"
      }
     ],
     "vuln_count": 10,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.8.8 -> 1.9.24"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "timber-library",
     "status": "inactive",
     "active": false,
     "installed": "1.22.1",
     "available": "1.23.4",
     "priority": "P1",
     "vulns": [
      {
       "name": "Timber [timber-library] < 1.23.3 (closed)",
       "cvss": "8.6",
       "severity": "HIGH",
       "cve": "CVE-2024-45411"
      },
      {
       "name": "Timber [timber-library] < 1.23.1 (closed)",
       "cvss": "8.0",
       "severity": "HIGH",
       "cve": "CVE-2024-29800"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.22.1 -> 1.23.4"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "white-label-cms",
     "status": "inactive",
     "active": false,
     "installed": "2.5",
     "available": "2.7.14",
     "priority": "P1",
     "vulns": [
      {
       "name": "White Label CMS [white-label-cms] < 2.7.5",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2024-43303"
      },
      {
       "name": "White Label CMS [white-label-cms] < 2.7.4",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2024-4280"
      },
      {
       "name": "White Label CMS [white-label-cms] < 2.7.13",
       "cvss": "4.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-11898"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.5 -> 2.7.14"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wordpress-importer",
     "status": "inactive",
     "active": false,
     "installed": "0.8",
     "available": "0.9.6",
     "priority": "P1",
     "vulns": [
      {
       "name": "WordPress Importer [wordpress-importer] < 0.8.4",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2024-13889"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 0.8 -> 0.9.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wp-all-import-pro",
     "status": "inactive",
     "active": false,
     "installed": "4.7.8",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "WP All Import Pro [wp-all-import-pro] < 4.9.4",
       "cvss": "7.6",
       "severity": "HIGH",
       "cve": "CVE-2024-9624"
      },
      {
       "name": "WP All Import Pro [wp-all-import-pro] < 4.9.8",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2024-9664"
      },
      {
       "name": "WP All Import Pro [wp-all-import-pro] < 4.9.8",
       "cvss": "5.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-8722"
      },
      {
       "name": "WP All Import Pro [wp-all-import-pro] < 4.9.8",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2024-9661"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "wp-bulk-delete",
     "status": "inactive",
     "active": false,
     "installed": "1.2.4",
     "available": "1.4.4",
     "priority": "P1",
     "vulns": [
      {
       "name": "WP Bulk Delete [wp-bulk-delete] < 1.3.2",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2024-47352"
      },
      {
       "name": "WP Bulk Delete [wp-bulk-delete] < 1.4.3",
       "cvss": "4.9",
       "severity": "MEDIUM",
       "cve": "CVE-2026-15727"
      },
      {
       "name": "WP Bulk Delete [wp-bulk-delete] < 1.3.7",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-58192"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.2.4 -> 1.4.4"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "query-monitor",
     "status": "active",
     "active": true,
     "installed": "3.12.3",
     "available": "4.0.7",
     "priority": "P2",
     "vulns": [
      {
       "name": "Query Monitor [query-monitor] < 3.20.4",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-4267"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.12.3 -> 4.0.7 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "search-filter-pro",
     "status": "active",
     "active": true,
     "installed": "2.5.14",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Search & Filter Pro [search-filter-pro] < 2.5.18",
       "cvss": "4.8",
       "severity": "MEDIUM",
       "cve": "CVE-2024-6481"
      },
      {
       "name": "Search & Filter Pro [search-filter-pro] < 2.5.20",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-1528"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "sticky-header-effects-for-elementor",
     "status": "active",
     "active": true,
     "installed": "1.6.5",
     "available": "2.2.2",
     "priority": "P2",
     "vulns": [
      {
       "name": "Sticky Header Effects for Elementor [sticky-header-effects-for-elementor] < 2.1.3",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-58251"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 1.6.5 -> 2.2.2 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "svg-support",
     "status": "active",
     "active": true,
     "installed": "2.5.5",
     "available": "2.6.1",
     "priority": "P2",
     "vulns": [
      {
       "name": "SVG Support [svg-support] < 2.5.11",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-10222"
      },
      {
       "name": "SVG Support [svg-support] < 2.5.9",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2022-23638"
      },
      {
       "name": "SVG Support [svg-support] < 2.5.8",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2023-6708"
      },
      {
       "name": "SVG Support [svg-support] < 2.5.15",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-48973"
      }
     ],
     "vuln_count": 5,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.5.5 -> 2.6.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "wp-custom-taxonomy-image",
     "status": "inactive",
     "active": false,
     "installed": "1.0.0",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Category and Taxonomy Image [wp-custom-taxonomy-image] <= 1.0.0 (unfixed + closed)",
       "cvss": "4.8",
       "severity": "MEDIUM",
       "cve": "CVE-2024-9591"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "custom-post-type-ui",
     "status": "inactive",
     "active": false,
     "installed": "1.13.4",
     "available": "1.19.3",
     "priority": "P2",
     "vulns": [
      {
       "name": "Custom Post Type UI [custom-post-type-ui] < 1.13.5",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2023-1623"
      },
      {
       "name": "Custom Post Type UI [custom-post-type-ui] < 1.18.1",
       "cvss": "4.8",
       "severity": "MEDIUM",
       "cve": "CVE-2025-12826"
      },
      {
       "name": "Custom Post Type UI [custom-post-type-ui] < 1.18.2",
       "cvss": "4.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-14056"
      },
      {
       "name": "Custom Post Type UI [custom-post-type-ui] < 1.13.5",
       "cvss": null,
       "severity": null,
       "cve": ""
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 1.13.4 -> 1.19.3 (skipped 6 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "dashboard-welcome-for-elementor",
     "status": "inactive",
     "active": false,
     "installed": "1.0.7",
     "available": "1.0.11",
     "priority": "P2",
     "vulns": [
      {
       "name": "Dashboard Welcome for Elementor [dashboard-welcome-for-elementor] < 1.0.8",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2024-32110"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.0.7 -> 1.0.11"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "genesis-blocks",
     "status": "inactive",
     "active": false,
     "installed": "1.5.4",
     "available": "3.1.11",
     "priority": "P2",
     "vulns": [
      {
       "name": "Genesis Blocks [genesis-blocks] < 3.1.3",
       "cvss": "6.8",
       "severity": "MEDIUM",
       "cve": "CVE-2024-2761"
      },
      {
       "name": "Genesis Blocks [genesis-blocks] < 3.1.4",
       "cvss": "6.8",
       "severity": "MEDIUM",
       "cve": "CVE-2024-3901"
      },
      {
       "name": "Genesis Blocks [genesis-blocks] < 3.1.3",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-1946"
      },
      {
       "name": "Genesis Blocks [genesis-blocks] < 3.1.4",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-3563"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 1.5.4 -> 3.1.11 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "limit-login-attempts-reloaded",
     "status": "inactive",
     "active": false,
     "installed": "2.25.13",
     "available": "3.3.8",
     "priority": "P2",
     "vulns": [
      {
       "name": "Limit Login Attempts Security &#8211; Login Security, 2FA, Firewall, Brute Force Prevention [limit-login-attempts-reloaded] < 2.25.27",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2023-6934"
      },
      {
       "name": "Limit Login Attempts Security &#8211; Login Security, 2FA, Firewall, Brute Force Prevention [limit-login-attempts-reloaded] < 2.25.26",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2023-5525"
      },
      {
       "name": "Limit Login Attempts Security &#8211; Login Security, 2FA, Firewall, Brute Force Prevention [limit-login-attempts-reloaded] < 3.3.5",
       "cvss": "3.7",
       "severity": "LOW",
       "cve": "CVE-2026-18356"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.25.13 -> 3.3.8 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "make-column-clickable-elementor",
     "status": "inactive",
     "active": false,
     "installed": "1.4.0",
     "available": "1.6.2",
     "priority": "P2",
     "vulns": [
      {
       "name": "Make Column Clickable for Elementor [make-column-clickable-elementor] < 1.6.1",
       "cvss": "0.0",
       "severity": null,
       "cve": "CVE-2025-59592"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.4.0 -> 1.6.2"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "pojo-accessibility",
     "status": "inactive",
     "active": false,
     "installed": "2.1.0",
     "available": "4.1.4",
     "priority": "P2",
     "vulns": [
      {
       "name": "Web Accessibility (formally known as Ally) &#8211; WCAG Scanning, Guided Fixes, Usability Widget [pojo-accessibility] < 4.0.3",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-25386"
      },
      {
       "name": "Web Accessibility (formally known as Ally) &#8211; WCAG Scanning, Guided Fixes, Usability Widget [pojo-accessibility] < 3.8.1",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-10700"
      },
      {
       "name": "Web Accessibility (formally known as Ally) &#8211; WCAG Scanning, Guided Fixes, Usability Widget [pojo-accessibility] < 3.2.0",
       "cvss": "0.0",
       "severity": null,
       "cve": "CVE-2025-32640"
      },
      {
       "name": "Web Accessibility (formally known as Ally) &#8211; WCAG Scanning, Guided Fixes, Usability Widget [pojo-accessibility] < 4.1.0",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-2413"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.1.0 -> 4.1.4 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "post-type-switcher",
     "status": "inactive",
     "active": false,
     "installed": "3.2.1",
     "available": "4.0.1",
     "priority": "P2",
     "vulns": [
      {
       "name": "Post Type Switcher [post-type-switcher] < 4.0.1",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-12524"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.2.1 -> 4.0.1 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "shortpixel-adaptive-images",
     "status": "inactive",
     "active": false,
     "installed": "3.7.1",
     "available": "3.11.6",
     "priority": "P2",
     "vulns": [
      {
       "name": "ShortPixel Adaptive Images &#8211; WebP, AVIF, CDN, Image Optimization [shortpixel-adaptive-images] < 3.11.4",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-57342"
      },
      {
       "name": "ShortPixel Adaptive Images &#8211; WebP, AVIF, CDN, Image Optimization [shortpixel-adaptive-images] < 3.11.5",
       "cvss": "5.8",
       "severity": "MEDIUM",
       "cve": "CVE-2026-56066"
      },
      {
       "name": "ShortPixel Adaptive Images &#8211; WebP, AVIF, CDN, Image Optimization [shortpixel-adaptive-images] < 3.8.3",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2024-31230"
      },
      {
       "name": "ShortPixel Adaptive Images &#8211; WebP, AVIF, CDN, Image Optimization [shortpixel-adaptive-images] < 3.8.4",
       "cvss": "4.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-35172"
      }
     ],
     "vuln_count": 9,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.7.1 -> 3.11.6 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "remove-old-slugspermalinks",
     "status": "inactive",
     "active": false,
     "installed": "2.6.2",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Slugs Manager: Delete Old Permalinks from WordPress Database [remove-old-slugspermalinks] < 2.7.0",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2024-30536"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "white-label",
     "status": "inactive",
     "active": false,
     "installed": "2.8.0",
     "available": "2.16.9",
     "priority": "P2",
     "vulns": [
      {
       "name": "White Label &#8211; WordPress Custom Admin, Custom Login Page, and Custom Dashboard [white-label] < 2.9.1",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2023-52128"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 2.8.0 -> 2.16.9 (skipped 8 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wp-migrate-db",
     "status": "inactive",
     "active": false,
     "installed": "2.6.5",
     "available": "2.7.11",
     "priority": "P2",
     "vulns": [
      {
       "name": "WP Migrate Lite &#8211; Migration Made Easy [wp-migrate-db] < 2.7.7",
       "cvss": "5.8",
       "severity": "MEDIUM",
       "cve": "CVE-2025-11427"
      },
      {
       "name": "WP Migrate Lite &#8211; Migration Made Easy [wp-migrate-db] < 2.7.9",
       "cvss": "4.7",
       "severity": "MEDIUM",
       "cve": "CVE-2026-49043"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.6.5 -> 2.7.11"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "https-redirection",
     "status": "inactive",
     "active": false,
     "installed": "1.9.1",
     "available": "2.0.1",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 1.9.1 -> 2.0.1 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "online-active-users",
     "status": "inactive",
     "active": false,
     "installed": "1.2",
     "available": "3.4.4",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 1.2 -> 3.4.4 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "admin-taxonomy-filter",
     "status": "active",
     "active": true,
     "installed": "1.0.2",
     "available": "1.0.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.0.2 -> 1.0.5"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "child-theme-configurator",
     "status": "active",
     "active": true,
     "installed": "2.6.2",
     "available": "2.6.7",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 2.6.2 -> 2.6.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "classic-editor",
     "status": "active",
     "active": true,
     "installed": "1.6.3",
     "available": "1.7.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.6.3 -> 1.7.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "disable-json-api",
     "status": "active",
     "active": true,
     "installed": "1.7",
     "available": "1.8",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.7 -> 1.8"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "duplicate-page",
     "status": "active",
     "active": true,
     "installed": "4.5.2",
     "available": "4.5.9",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 4.5.2 -> 4.5.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "flying-pages",
     "status": "active",
     "active": true,
     "installed": "2.4.6",
     "available": "2.4.7",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 2.4.6 -> 2.4.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "simple-website-redirect",
     "status": "active",
     "active": true,
     "installed": "1.2.8",
     "available": "1.3.2",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.2.8 -> 1.3.2"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wp-revisions-control",
     "status": "active",
     "active": true,
     "installed": "1.4.3",
     "available": "1.4.4",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.4.3 -> 1.4.4"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "admin-css-mu",
     "status": "inactive",
     "active": false,
     "installed": "2.8",
     "available": "2.10",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.8 -> 2.10"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "advanced-post-queries",
     "status": "inactive",
     "active": false,
     "installed": "1.1.0",
     "available": "1.1.4",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.1.0 -> 1.1.4"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "akismet",
     "status": "inactive",
     "active": false,
     "installed": "5.0.1",
     "available": "5.7.2",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.0.1 -> 5.7.2 (skipped 7 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "bulk-delete",
     "status": "inactive",
     "active": false,
     "installed": "6.0.2",
     "available": "6.12",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 6.0.2 -> 6.12 (skipped 12 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "cookie-law-info",
     "status": "inactive",
     "active": false,
     "installed": "3.0.8",
     "available": "3.5.6",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.0.8 -> 3.5.6 (skipped 5 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "headers-security-advanced-hsts-wp",
     "status": "inactive",
     "active": false,
     "installed": "5.0.21",
     "available": "5.3.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.0.21 -> 5.3.5 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "regenerate-thumbnails",
     "status": "inactive",
     "active": false,
     "installed": "3.1.5",
     "available": "3.1.6",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 3.1.5 -> 3.1.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wp-widget-disable",
     "status": "inactive",
     "active": false,
     "installed": "3.0.0",
     "available": "3.0.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 3.0.0 -> 3.0.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wp-smartcrop",
     "status": "inactive",
     "active": false,
     "installed": "2.0.6",
     "available": "2.0.10",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 2.0.6 -> 2.0.10"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    }
   ],
   "p0": 8,
   "p1": 18,
   "total_updates": 53
  },
  "wpengine:norwestventure": {
   "platform": "wpengine",
   "install": "norwestventure",
   "environment": "production",
   "domain": "www.norwest.com",
   "siteurl": "https://www.norwest.com",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "brand-nav-child-theme",
   "updates": [
    {
     "plugin": "elementor-pro",
     "status": "active",
     "active": true,
     "installed": "3.23.3",
     "available": null,
     "priority": "P0",
     "vulns": [
      {
       "name": "Elementor Pro [elementor-pro] < 4.2.2",
       "cvss": "9.0",
       "severity": "CRITICAL",
       "cve": "CVE-2026-32475"
      },
      {
       "name": "Elementor Pro [elementor-pro] < 3.25.11",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-8494"
      },
      {
       "name": "Elementor Pro [elementor-pro] < 3.29.1",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-50555"
      },
      {
       "name": "Elementor Pro [elementor-pro] < 3.29.1",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-3076"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "ewww-image-optimizer",
     "status": "active",
     "active": true,
     "installed": "8.7.1",
     "available": "8.7.7",
     "priority": "P1",
     "vulns": [
      {
       "name": "EWWW Image Optimizer [ewww-image-optimizer] < 8.7.7",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-84773"
      },
      {
       "name": "EWWW Image Optimizer [ewww-image-optimizer] < 8.7.4",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-15446"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 8.7.1 -> 8.7.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "mainwp-child",
     "status": "active",
     "active": true,
     "installed": "6.1.1",
     "available": "6.2",
     "priority": "P1",
     "vulns": [
      {
       "name": "MainWP Child &#8211; Securely Connects to the MainWP Dashboard to Manage Multiple Sites [mainwp-child] < 6.1.2",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-27366"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 6.1.1 -> 6.2"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "one-user-avatar",
     "status": "active",
     "active": true,
     "installed": "2.5.4",
     "available": "2.5.6",
     "priority": "P1",
     "vulns": [
      {
       "name": "One User Avatar | User Profile Picture [one-user-avatar] < 2.5.5",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-18983"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 2.5.4 -> 2.5.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "revslider",
     "status": "active",
     "active": true,
     "installed": "6.7.18",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "Slider Revolution [revslider] < 7.0.11",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-6692"
      },
      {
       "name": "Slider Revolution [revslider] < 7.1.0",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-57678"
      },
      {
       "name": "Slider Revolution [revslider] < 6.7.37",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-9217"
      },
      {
       "name": "Slider Revolution [revslider] < 6.7.38",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-10249"
      }
     ],
     "vuln_count": 9,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "admin-site-enhancements",
     "status": "active",
     "active": true,
     "installed": "8.8.3",
     "available": "9.1.2",
     "priority": "P2",
     "vulns": [
      {
       "name": "Admin and Site Enhancements (ASE) [admin-site-enhancements] < 8.8.4",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-12083"
      },
      {
       "name": "Admin and Site Enhancements (ASE) [admin-site-enhancements] < 9.0.1",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-19615"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 8.8.3 -> 9.1.2 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "elementor",
     "status": "active",
     "active": true,
     "installed": "3.23.4",
     "available": "4.2.4",
     "priority": "P2",
     "vulns": [
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.25.11",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-54444"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.29.1",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-50555"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.35.6",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-32352"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 4.1.4",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-57619"
      }
     ],
     "vuln_count": 20,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.23.4 -> 4.2.4 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "search-filter-pro",
     "status": "active",
     "active": true,
     "installed": "2.5.14",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Search & Filter Pro [search-filter-pro] < 2.5.18",
       "cvss": "4.8",
       "severity": "MEDIUM",
       "cve": "CVE-2024-6481"
      },
      {
       "name": "Search & Filter Pro [search-filter-pro] < 2.5.20",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-1528"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "simple-cloudflare-turnstile",
     "status": "active",
     "active": true,
     "installed": "1.41.1",
     "available": "1.43.1",
     "priority": "P2",
     "vulns": [
      {
       "name": "Simple CAPTCHA with Cloudflare Turnstile [simple-cloudflare-turnstile] < 1.42.3",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-66632"
      },
      {
       "name": "Simple CAPTCHA with Cloudflare Turnstile [simple-cloudflare-turnstile] < 1.42.3",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-85116"
      },
      {
       "name": "Simple CAPTCHA with Cloudflare Turnstile [simple-cloudflare-turnstile] < 1.42.3",
       "cvss": "5.6",
       "severity": "MEDIUM",
       "cve": "CVE-2026-66674"
      },
      {
       "name": "Simple CAPTCHA with Cloudflare Turnstile [simple-cloudflare-turnstile] < 1.42.0",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-15239"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.41.1 -> 1.43.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "wp-security-audit-log",
     "status": "active",
     "active": true,
     "installed": "5.6.4",
     "available": "5.6.6",
     "priority": "P2",
     "vulns": [
      {
       "name": "WP Activity Log [wp-security-audit-log] < 5.6.5",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-65512"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 5.6.4 -> 5.6.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "wordpress-seo-premium",
     "status": "active",
     "active": true,
     "installed": "24.8",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast SEO Premium [wordpress-seo-premium] < 27.6.1",
       "cvss": "6.6",
       "severity": "MEDIUM",
       "cve": "CVE-2026-10821"
      },
      {
       "name": "Yoast SEO Premium [wordpress-seo-premium] < 26.7",
       "cvss": "5.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-40722"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "metasync",
     "status": "inactive",
     "active": false,
     "installed": "2.6.10",
     "available": "2.6.26",
     "priority": "P2",
     "vulns": [
      {
       "name": "Search Atlas SEO &#8211; OTTO AI SEO Automation for WordPress [metasync] < 2.6.12",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-15252"
      },
      {
       "name": "Search Atlas SEO &#8211; OTTO AI SEO Automation for WordPress [metasync] < 2.6.24",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-15247"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 2.6.10 -> 2.6.26"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "am-lottieplayer",
     "status": "active",
     "active": true,
     "installed": "3.7.1",
     "available": "4.1.1",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.7.1 -> 4.1.1 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "prevent-browser-caching",
     "status": "active",
     "active": true,
     "installed": "2.3.6",
     "available": "3.2.1",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.3.6 -> 3.2.1 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "wp-2fa-premium",
     "status": "active",
     "active": true,
     "installed": "3.1.1.2",
     "available": "4.1.0",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.1.1.2 -> 4.1.0 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "eps-301-redirects",
     "status": "active",
     "active": true,
     "installed": "2.84",
     "available": "2.85",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.84 -> 2.85"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "advanced-custom-fields-pro",
     "status": "active",
     "active": true,
     "installed": "6.8.3",
     "available": "6.8.10",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "patch bump 6.8.3 -> 6.8.10",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE WITH CAPTURE \u2014 routine bump but on a sitewide-impact plugin; watch the diff closely."
    },
    {
     "plugin": "tinymce-advanced",
     "status": "active",
     "active": true,
     "installed": "5.9.2",
     "available": "5.10.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 5.9.2 -> 5.10.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "amplifi-plugins",
     "status": "active",
     "active": true,
     "installed": "3.0.9",
     "available": "3.3.7",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.0.9 -> 3.3.7 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "cookie-law-info",
     "status": "active",
     "active": true,
     "installed": "3.5.1",
     "available": "3.5.6",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 3.5.1 -> 3.5.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "dynamic-content-for-elementor",
     "status": "active",
     "active": true,
     "installed": "3.3.3",
     "available": "3.4.13",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "minor version bump 3.3.3 -> 3.4.13",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE WITH CAPTURE \u2014 routine bump but on a sitewide-impact plugin; watch the diff closely."
    },
    {
     "plugin": "headers-security-advanced-hsts-wp",
     "status": "active",
     "active": true,
     "installed": "5.3.2",
     "available": "5.3.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 5.3.2 -> 5.3.5"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "search-exclude",
     "status": "active",
     "active": true,
     "installed": "2.6.5",
     "available": "2.6.6",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 2.6.5 -> 2.6.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "smtp2go",
     "status": "active",
     "active": true,
     "installed": "1.17.0",
     "available": "1.17.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.17.0 -> 1.17.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "insert-headers-and-footers",
     "status": "active",
     "active": true,
     "installed": "2.3.6",
     "available": "2.3.9",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 2.3.6 -> 2.3.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wp-search-with-algolia",
     "status": "active",
     "active": true,
     "installed": "2.11.3",
     "available": "2.14.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 2.11.3 -> 2.14.1 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wordpress-seo",
     "status": "active",
     "active": true,
     "installed": "28.1",
     "available": "28.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "multi-minor jump 28.1 -> 28.5 (skipped 4 minor releases)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE WITH CAPTURE \u2014 routine bump but on a sitewide-impact plugin; watch the diff closely."
    },
    {
     "plugin": "simple-banner",
     "status": "inactive",
     "active": false,
     "installed": "3.3.0",
     "available": "3.3.2",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 3.3.0 -> 3.3.2"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wp-optimize",
     "status": "inactive",
     "active": false,
     "installed": "4.5.5",
     "available": "4.6.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "minor version bump 4.5.5 -> 4.6.1",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    }
   ],
   "p0": 1,
   "p1": 4,
   "total_updates": 25
  },
  "wpengine:nvpstg": {
   "platform": "wpengine",
   "install": "nvpstg",
   "environment": "staging",
   "domain": "nvpstg.wpengine.com",
   "siteurl": "https://nvpstg.wpengine.com",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "brand-nav-child-theme",
   "updates": [
    {
     "plugin": "elementor-pro",
     "status": "active",
     "active": true,
     "installed": "3.23.3",
     "available": null,
     "priority": "P0",
     "vulns": [
      {
       "name": "Elementor Pro [elementor-pro] < 4.2.2",
       "cvss": "9.0",
       "severity": "CRITICAL",
       "cve": "CVE-2026-32475"
      },
      {
       "name": "Elementor Pro [elementor-pro] < 3.25.11",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-8494"
      },
      {
       "name": "Elementor Pro [elementor-pro] < 3.29.1",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-50555"
      },
      {
       "name": "Elementor Pro [elementor-pro] < 3.29.1",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-3076"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "ewww-image-optimizer",
     "status": "active",
     "active": true,
     "installed": "8.7.1",
     "available": "8.7.7",
     "priority": "P1",
     "vulns": [
      {
       "name": "EWWW Image Optimizer [ewww-image-optimizer] < 8.7.7",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-84773"
      },
      {
       "name": "EWWW Image Optimizer [ewww-image-optimizer] < 8.7.4",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-15446"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 8.7.1 -> 8.7.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "mainwp-child",
     "status": "active",
     "active": true,
     "installed": "6.1.1",
     "available": "6.2",
     "priority": "P1",
     "vulns": [
      {
       "name": "MainWP Child &#8211; Securely Connects to the MainWP Dashboard to Manage Multiple Sites [mainwp-child] < 6.1.2",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-27366"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 6.1.1 -> 6.2"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "one-user-avatar",
     "status": "active",
     "active": true,
     "installed": "2.5.4",
     "available": "2.5.6",
     "priority": "P1",
     "vulns": [
      {
       "name": "One User Avatar | User Profile Picture [one-user-avatar] < 2.5.5",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-18983"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 2.5.4 -> 2.5.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "revslider",
     "status": "active",
     "active": true,
     "installed": "6.7.18",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "Slider Revolution [revslider] < 7.0.11",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-6692"
      },
      {
       "name": "Slider Revolution [revslider] < 7.1.0",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-57678"
      },
      {
       "name": "Slider Revolution [revslider] < 6.7.37",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-9217"
      },
      {
       "name": "Slider Revolution [revslider] < 6.7.38",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-10249"
      }
     ],
     "vuln_count": 9,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "admin-site-enhancements",
     "status": "active",
     "active": true,
     "installed": "8.8.3",
     "available": "9.1.2",
     "priority": "P2",
     "vulns": [
      {
       "name": "Admin and Site Enhancements (ASE) [admin-site-enhancements] < 8.8.4",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-12083"
      },
      {
       "name": "Admin and Site Enhancements (ASE) [admin-site-enhancements] < 9.0.1",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-19615"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 8.8.3 -> 9.1.2 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "elementor",
     "status": "active",
     "active": true,
     "installed": "3.23.4",
     "available": "4.2.4",
     "priority": "P2",
     "vulns": [
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.25.11",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-54444"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.29.1",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-50555"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.35.6",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-32352"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 4.1.4",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-57619"
      }
     ],
     "vuln_count": 20,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.23.4 -> 4.2.4 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "search-filter-pro",
     "status": "active",
     "active": true,
     "installed": "2.5.14",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Search & Filter Pro [search-filter-pro] < 2.5.18",
       "cvss": "4.8",
       "severity": "MEDIUM",
       "cve": "CVE-2024-6481"
      },
      {
       "name": "Search & Filter Pro [search-filter-pro] < 2.5.20",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-1528"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "simple-cloudflare-turnstile",
     "status": "active",
     "active": true,
     "installed": "1.41.1",
     "available": "1.43.1",
     "priority": "P2",
     "vulns": [
      {
       "name": "Simple CAPTCHA with Cloudflare Turnstile [simple-cloudflare-turnstile] < 1.42.3",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-66632"
      },
      {
       "name": "Simple CAPTCHA with Cloudflare Turnstile [simple-cloudflare-turnstile] < 1.42.3",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-85116"
      },
      {
       "name": "Simple CAPTCHA with Cloudflare Turnstile [simple-cloudflare-turnstile] < 1.42.3",
       "cvss": "5.6",
       "severity": "MEDIUM",
       "cve": "CVE-2026-66674"
      },
      {
       "name": "Simple CAPTCHA with Cloudflare Turnstile [simple-cloudflare-turnstile] < 1.42.0",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-15239"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.41.1 -> 1.43.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "wp-security-audit-log",
     "status": "active",
     "active": true,
     "installed": "5.6.4",
     "available": "5.6.6",
     "priority": "P2",
     "vulns": [
      {
       "name": "WP Activity Log [wp-security-audit-log] < 5.6.5",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-65512"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 5.6.4 -> 5.6.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "wordpress-seo-premium",
     "status": "active",
     "active": true,
     "installed": "24.8",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast SEO Premium [wordpress-seo-premium] < 27.6.1",
       "cvss": "6.6",
       "severity": "MEDIUM",
       "cve": "CVE-2026-10821"
      },
      {
       "name": "Yoast SEO Premium [wordpress-seo-premium] < 26.7",
       "cvss": "5.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-40722"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "metasync",
     "status": "inactive",
     "active": false,
     "installed": "2.6.10",
     "available": "2.6.26",
     "priority": "P2",
     "vulns": [
      {
       "name": "Search Atlas SEO &#8211; OTTO AI SEO Automation for WordPress [metasync] < 2.6.12",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-15252"
      },
      {
       "name": "Search Atlas SEO &#8211; OTTO AI SEO Automation for WordPress [metasync] < 2.6.24",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-15247"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 2.6.10 -> 2.6.26"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "am-lottieplayer",
     "status": "active",
     "active": true,
     "installed": "3.7.1",
     "available": "4.1.1",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.7.1 -> 4.1.1 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "prevent-browser-caching",
     "status": "active",
     "active": true,
     "installed": "2.3.6",
     "available": "3.2.1",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.3.6 -> 3.2.1 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "wp-2fa-premium",
     "status": "active",
     "active": true,
     "installed": "3.1.1.2",
     "available": "4.1.0",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.1.1.2 -> 4.1.0 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "eps-301-redirects",
     "status": "active",
     "active": true,
     "installed": "2.84",
     "available": "2.85",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.84 -> 2.85"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "advanced-custom-fields-pro",
     "status": "active",
     "active": true,
     "installed": "6.8.3",
     "available": "6.8.10",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "patch bump 6.8.3 -> 6.8.10",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE WITH CAPTURE \u2014 routine bump but on a sitewide-impact plugin; watch the diff closely."
    },
    {
     "plugin": "tinymce-advanced",
     "status": "active",
     "active": true,
     "installed": "5.9.2",
     "available": "5.10.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 5.9.2 -> 5.10.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "amplifi-plugins",
     "status": "active",
     "active": true,
     "installed": "3.0.9",
     "available": "3.3.7",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.0.9 -> 3.3.7 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "cookie-law-info",
     "status": "active",
     "active": true,
     "installed": "3.5.1",
     "available": "3.5.6",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 3.5.1 -> 3.5.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "dynamic-content-for-elementor",
     "status": "active",
     "active": true,
     "installed": "3.3.3",
     "available": "3.4.13",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "minor version bump 3.3.3 -> 3.4.13",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE WITH CAPTURE \u2014 routine bump but on a sitewide-impact plugin; watch the diff closely."
    },
    {
     "plugin": "headers-security-advanced-hsts-wp",
     "status": "active",
     "active": true,
     "installed": "5.3.2",
     "available": "5.3.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 5.3.2 -> 5.3.5"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "search-exclude",
     "status": "active",
     "active": true,
     "installed": "2.6.5",
     "available": "2.6.6",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 2.6.5 -> 2.6.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "smtp2go",
     "status": "active",
     "active": true,
     "installed": "1.17.0",
     "available": "1.17.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.17.0 -> 1.17.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "insert-headers-and-footers",
     "status": "active",
     "active": true,
     "installed": "2.3.6",
     "available": "2.3.9",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 2.3.6 -> 2.3.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wp-search-with-algolia",
     "status": "active",
     "active": true,
     "installed": "2.11.3",
     "available": "2.14.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 2.11.3 -> 2.14.1 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wordpress-seo",
     "status": "active",
     "active": true,
     "installed": "28.1",
     "available": "28.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "multi-minor jump 28.1 -> 28.5 (skipped 4 minor releases)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE WITH CAPTURE \u2014 routine bump but on a sitewide-impact plugin; watch the diff closely."
    },
    {
     "plugin": "simple-banner",
     "status": "inactive",
     "active": false,
     "installed": "3.3.0",
     "available": "3.3.2",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 3.3.0 -> 3.3.2"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wp-optimize",
     "status": "inactive",
     "active": false,
     "installed": "4.5.5",
     "available": "4.6.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "minor version bump 4.5.5 -> 4.6.1",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    }
   ],
   "p0": 1,
   "p1": 4,
   "total_updates": 25
  },
  "wpengine:dev101inc": {
   "platform": "wpengine",
   "install": "dev101inc",
   "environment": "development",
   "domain": "dev101inc.wpengine.com",
   "siteurl": "https://dev101inc.wpengine.com",
   "core": "7.0.3",
   "core_update": "7.0.4",
   "theme": "hello-elementor",
   "updates": [
    {
     "plugin": "elementor",
     "status": "active",
     "active": true,
     "installed": "3.13.0",
     "available": "4.2.4",
     "priority": "P0",
     "vulns": [
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.18.2",
       "cvss": "9.9",
       "severity": "CRITICAL",
       "cve": "CVE-2023-48777"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.19.1",
       "cvss": "8.5",
       "severity": "HIGH",
       "cve": "CVE-2024-24934"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.16.5",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2023-47505"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.16.5",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2023-47504"
      }
     ],
     "vuln_count": 32,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.13.0 -> 4.2.4 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "elementor-pro",
     "status": "active",
     "active": true,
     "installed": "3.12.3",
     "available": "3.13.1",
     "priority": "P0",
     "vulns": [
      {
       "name": "Elementor Pro [elementor-pro] < 4.2.2",
       "cvss": "9.0",
       "severity": "CRITICAL",
       "cve": "CVE-2026-32475"
      },
      {
       "name": "Elementor Pro [elementor-pro] < 3.19.3",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-23523"
      },
      {
       "name": "Elementor Pro [elementor-pro] < 3.25.11",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-8494"
      },
      {
       "name": "Elementor Pro [elementor-pro] < 3.29.1",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-50555"
      }
     ],
     "vuln_count": 13,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "minor version bump 3.12.3 -> 3.13.1",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "white-label-cms",
     "status": "active",
     "active": true,
     "installed": "2.5",
     "available": "2.7.14",
     "priority": "P1",
     "vulns": [
      {
       "name": "White Label CMS [white-label-cms] < 2.7.5",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2024-43303"
      },
      {
       "name": "White Label CMS [white-label-cms] < 2.7.4",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2024-4280"
      },
      {
       "name": "White Label CMS [white-label-cms] < 2.7.13",
       "cvss": "4.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-11898"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.5 -> 2.7.14"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "wp-2fa",
     "status": "active",
     "active": true,
     "installed": "2.4.1",
     "available": "4.1.0",
     "priority": "P1",
     "vulns": [
      {
       "name": "WP 2FA &#8211; Two-factor authentication for WordPress [wp-2fa] < 2.6.3",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2024-32568"
      },
      {
       "name": "WP 2FA &#8211; Two-factor authentication for WordPress [wp-2fa] < 3.0.0",
       "cvss": "6.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-12628"
      },
      {
       "name": "WP 2FA &#8211; Two-factor authentication for WordPress [wp-2fa] < 2.6.4",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2022-44587"
      },
      {
       "name": "WP 2FA &#8211; Two-factor authentication for WordPress [wp-2fa] < 2.6.0",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2023-6506"
      }
     ],
     "vuln_count": 7,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.4.1 -> 4.1.0 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "insert-headers-and-footers",
     "status": "active",
     "active": true,
     "installed": "2.0.11",
     "available": "2.3.9",
     "priority": "P1",
     "vulns": [
      {
       "name": "WPCode &#8211; Insert Headers and Footers + Custom Code Snippets &#8211; WordPress Code Manager [insert-headers-and-footers] < 2.3.6",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-8832"
      },
      {
       "name": "WPCode &#8211; Insert Headers and Footers + Custom Code Snippets &#8211; WordPress Code Manager [insert-headers-and-footers] < 2.0.13.1",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2023-3524"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 2.0.11 -> 2.3.9 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "wp-fastest-cache",
     "status": "active",
     "active": true,
     "installed": "1.1.5",
     "available": "1.5.2",
     "priority": "P1",
     "vulns": [
      {
       "name": "WP Fastest Cache &#8211; WordPress Cache Plugin [wp-fastest-cache] < 1.2.2",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2023-6063"
      },
      {
       "name": "WP Fastest Cache &#8211; WordPress Cache Plugin [wp-fastest-cache] < 1.5.1",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-74932"
      },
      {
       "name": "WP Fastest Cache &#8211; WordPress Cache Plugin [wp-fastest-cache] < 1.2.7",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2024-4347"
      },
      {
       "name": "WP Fastest Cache &#8211; WordPress Cache Plugin [wp-fastest-cache] < 1.5.1",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-19760"
      }
     ],
     "vuln_count": 6,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 1.1.5 -> 1.5.2 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "shortpixel-image-optimiser",
     "status": "inactive",
     "active": false,
     "installed": "5.2.1",
     "available": "6.5.6",
     "priority": "P1",
     "vulns": [
      {
       "name": "ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 5.6.4",
       "cvss": "7.6",
       "severity": "HIGH",
       "cve": "CVE-2024-48043"
      },
      {
       "name": "ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 6.4.4",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-39471"
      },
      {
       "name": "ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 5.6.4",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-48044"
      },
      {
       "name": "ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 6.3.5",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-11378"
      }
     ],
     "vuln_count": 9,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 5.2.1 -> 6.5.6 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "advanced-custom-fields",
     "status": "active",
     "active": true,
     "installed": "6.1.6",
     "available": "6.8.10",
     "priority": "P2",
     "vulns": [
      {
       "name": "Advanced Custom Fields (ACF\u00ae) [advanced-custom-fields] < 6.3.8",
       "cvss": "6.6",
       "severity": "MEDIUM",
       "cve": "CVE-2024-9529"
      },
      {
       "name": "Advanced Custom Fields (ACF\u00ae) [advanced-custom-fields] < 6.3.0",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-4565"
      },
      {
       "name": "Advanced Custom Fields (ACF\u00ae) [advanced-custom-fields] < 6.3.6",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2024-45429"
      },
      {
       "name": "Advanced Custom Fields (ACF\u00ae) [advanced-custom-fields] >= 6.1.0 - <= 6.1.7",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2023-40068"
      }
     ],
     "vuln_count": 13,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "multi-minor jump 6.1.6 -> 6.8.10 (skipped 7 minor releases)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "limit-login-attempts-reloaded",
     "status": "active",
     "active": true,
     "installed": "2.25.16",
     "available": "3.3.8",
     "priority": "P2",
     "vulns": [
      {
       "name": "Limit Login Attempts Security &#8211; Login Security, 2FA, Firewall, Brute Force Prevention [limit-login-attempts-reloaded] < 2.25.27",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2023-6934"
      },
      {
       "name": "Limit Login Attempts Security &#8211; Login Security, 2FA, Firewall, Brute Force Prevention [limit-login-attempts-reloaded] < 2.25.26",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2023-5525"
      },
      {
       "name": "Limit Login Attempts Security &#8211; Login Security, 2FA, Firewall, Brute Force Prevention [limit-login-attempts-reloaded] < 3.3.5",
       "cvss": "3.7",
       "severity": "LOW",
       "cve": "CVE-2026-18356"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.25.16 -> 3.3.8 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "pojo-accessibility",
     "status": "active",
     "active": true,
     "installed": "2.1.0",
     "available": "4.1.4",
     "priority": "P2",
     "vulns": [
      {
       "name": "Web Accessibility (formally known as Ally) &#8211; WCAG Scanning, Guided Fixes, Usability Widget [pojo-accessibility] < 4.0.3",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-25386"
      },
      {
       "name": "Web Accessibility (formally known as Ally) &#8211; WCAG Scanning, Guided Fixes, Usability Widget [pojo-accessibility] < 3.8.1",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-10700"
      },
      {
       "name": "Web Accessibility (formally known as Ally) &#8211; WCAG Scanning, Guided Fixes, Usability Widget [pojo-accessibility] < 3.2.0",
       "cvss": "0.0",
       "severity": null,
       "cve": "CVE-2025-32640"
      },
      {
       "name": "Web Accessibility (formally known as Ally) &#8211; WCAG Scanning, Guided Fixes, Usability Widget [pojo-accessibility] < 4.1.0",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-2413"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.1.0 -> 4.1.4 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "sticky-header-effects-for-elementor",
     "status": "active",
     "active": true,
     "installed": "1.6.5",
     "available": "2.2.2",
     "priority": "P2",
     "vulns": [
      {
       "name": "Sticky Header Effects for Elementor [sticky-header-effects-for-elementor] < 2.1.3",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-58251"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 1.6.5 -> 2.2.2 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "svg-support",
     "status": "active",
     "active": true,
     "installed": "2.5.5",
     "available": "2.6.1",
     "priority": "P2",
     "vulns": [
      {
       "name": "SVG Support [svg-support] < 2.5.11",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-10222"
      },
      {
       "name": "SVG Support [svg-support] < 2.5.9",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2022-23638"
      },
      {
       "name": "SVG Support [svg-support] < 2.5.8",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2023-6708"
      },
      {
       "name": "SVG Support [svg-support] < 2.5.15",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-48973"
      }
     ],
     "vuln_count": 5,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.5.5 -> 2.6.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "genesis-blocks",
     "status": "inactive",
     "active": false,
     "installed": "1.5.4",
     "available": "3.1.11",
     "priority": "P2",
     "vulns": [
      {
       "name": "Genesis Blocks [genesis-blocks] < 3.1.3",
       "cvss": "6.8",
       "severity": "MEDIUM",
       "cve": "CVE-2024-2761"
      },
      {
       "name": "Genesis Blocks [genesis-blocks] < 3.1.4",
       "cvss": "6.8",
       "severity": "MEDIUM",
       "cve": "CVE-2024-3901"
      },
      {
       "name": "Genesis Blocks [genesis-blocks] < 3.1.3",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-1946"
      },
      {
       "name": "Genesis Blocks [genesis-blocks] < 3.1.4",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-3563"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 1.5.4 -> 3.1.11 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wp-mail-smtp",
     "status": "inactive",
     "active": false,
     "installed": "3.8.0",
     "available": "4.9.0",
     "priority": "P2",
     "vulns": [
      {
       "name": "WP Mail SMTP by WPForms &#8211; The Most Popular SMTP and Email Log Plugin [wp-mail-smtp] < 4.1.0",
       "cvss": "2.7",
       "severity": "LOW",
       "cve": "CVE-2024-6694"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.8.0 -> 4.9.0 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "disable-wp-notification",
     "status": "active",
     "active": true,
     "installed": "3.0",
     "available": "4.3",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.0 -> 4.3 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "admin-taxonomy-filter",
     "status": "active",
     "active": true,
     "installed": "1.0.2",
     "available": "1.0.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.0.2 -> 1.0.5"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "cookie-law-info",
     "status": "active",
     "active": true,
     "installed": "3.0.9",
     "available": "3.5.6",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.0.9 -> 3.5.6 (skipped 5 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "disable-json-api",
     "status": "active",
     "active": true,
     "installed": "1.7",
     "available": "1.8",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.7 -> 1.8"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "disable-xml-rpc-api",
     "status": "active",
     "active": true,
     "installed": "2.1.4.8",
     "available": "2.1.7",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 2.1.4.8 -> 2.1.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "duplicate-page",
     "status": "active",
     "active": true,
     "installed": "4.5.2",
     "available": "4.5.9",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 4.5.2 -> 4.5.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "headers-security-advanced-hsts-wp",
     "status": "active",
     "active": true,
     "installed": "5.0.21",
     "available": "5.3.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.0.21 -> 5.3.5 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wp-widget-disable",
     "status": "active",
     "active": true,
     "installed": "3.0.0",
     "available": "3.0.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 3.0.0 -> 3.0.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wp-revisions-control",
     "status": "active",
     "active": true,
     "installed": "1.4.3",
     "available": "1.4.4",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.4.3 -> 1.4.4"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    }
   ],
   "p0": 2,
   "p1": 5,
   "total_updates": 23
  },
  "wpengine:revieweoy": {
   "platform": "wpengine",
   "install": "revieweoy",
   "environment": "production",
   "domain": "review.nvp.com",
   "siteurl": "https://review.nvp.com",
   "core": "6.8.8",
   "core_update": "7.1",
   "theme": "nvp-eoy2022",
   "updates": [
    {
     "plugin": "advanced-custom-fields-pro",
     "status": "active",
     "active": true,
     "installed": "6.0.5",
     "available": "6.8.10",
     "priority": "P0",
     "vulns": [
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.2.10",
       "cvss": "9.9",
       "severity": "CRITICAL",
       "cve": "CVE-2024-34762"
      },
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.2.10",
       "cvss": "8.5",
       "severity": "HIGH",
       "cve": "CVE-2024-34761"
      },
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.1.6",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2023-30777"
      },
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.3.8",
       "cvss": "6.6",
       "severity": "MEDIUM",
       "cve": "CVE-2024-9529"
      }
     ],
     "vuln_count": 14,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "multi-minor jump 6.0.5 -> 6.8.10 (skipped 8 minor releases)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "aryo-activity-log",
     "status": "active",
     "active": true,
     "installed": "2.9.0",
     "available": "2.15.0",
     "priority": "P1",
     "vulns": [
      {
       "name": "Activity Log \u2013 Monitor User and Agent Changes [aryo-activity-log] < 2.11.2",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2024-10788"
      },
      {
       "name": "Activity Log \u2013 Monitor User and Agent Changes [aryo-activity-log] < 2.14.0",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-84759"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 2.9.0 -> 2.15.0 (skipped 6 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "safe-svg",
     "status": "active",
     "active": true,
     "installed": "2.2.2",
     "available": "2.5.0",
     "priority": "P2",
     "vulns": [
      {
       "name": "Safe SVG [safe-svg] < 2.2.6",
       "cvss": "4.8",
       "severity": "MEDIUM",
       "cve": "CVE-2024-8378"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 2.2.2 -> 2.5.0 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "wordpress-seo",
     "status": "active",
     "active": true,
     "installed": "21.5",
     "available": "28.5",
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 22.7",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-4984"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 22.6",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2024-4041"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 26.6",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-14481"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 27.2",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-3427"
      }
     ],
     "vuln_count": 6,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 21.5 -> 28.5 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "all-404-pages-redirect-to-homepage",
     "status": "inactive",
     "active": false,
     "installed": "1.9",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "All 404 Pages Redirect to Homepage [all-404-pages-redirect-to-homepage] < 2.0 (closed)",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2024-24889"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "acf-content-analysis-for-yoast-seo",
     "status": "active",
     "active": true,
     "installed": "3.1",
     "available": "3.2",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 3.1 -> 3.2"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "classic-editor",
     "status": "active",
     "active": true,
     "installed": "1.6.3",
     "available": "1.7.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.6.3 -> 1.7.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "redirection",
     "status": "active",
     "active": true,
     "installed": "5.3.10",
     "available": "5.10.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.3.10 -> 5.10.0 (skipped 7 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    }
   ],
   "p0": 1,
   "p1": 1,
   "total_updates": 7
  },
  "wpengine:yearinreviestg": {
   "platform": "wpengine",
   "install": "yearinreviestg",
   "environment": "staging",
   "domain": "yearinreviestg.wpengine.com",
   "siteurl": "https://revieweoy.wpengine.com",
   "core": "6.8.8",
   "core_update": "7.1",
   "theme": "nvp-eoy2022",
   "updates": [
    {
     "plugin": "advanced-custom-fields-pro",
     "status": "active",
     "active": true,
     "installed": "6.0.5",
     "available": "6.8.10",
     "priority": "P0",
     "vulns": [
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.2.10",
       "cvss": "9.9",
       "severity": "CRITICAL",
       "cve": "CVE-2024-34762"
      },
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.2.10",
       "cvss": "8.5",
       "severity": "HIGH",
       "cve": "CVE-2024-34761"
      },
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.1.6",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2023-30777"
      },
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.3.8",
       "cvss": "6.6",
       "severity": "MEDIUM",
       "cve": "CVE-2024-9529"
      }
     ],
     "vuln_count": 14,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "multi-minor jump 6.0.5 -> 6.8.10 (skipped 8 minor releases)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "aryo-activity-log",
     "status": "active",
     "active": true,
     "installed": "2.8.5",
     "available": "2.15.0",
     "priority": "P1",
     "vulns": [
      {
       "name": "Activity Log \u2013 Monitor User and Agent Changes [aryo-activity-log] < 2.11.2",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2024-10788"
      },
      {
       "name": "Activity Log \u2013 Monitor User and Agent Changes [aryo-activity-log] < 2.14.0",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-84759"
      },
      {
       "name": "Activity Log \u2013 Monitor User and Agent Changes [aryo-activity-log] < 2.8.8",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2023-4281"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 2.8.5 -> 2.15.0 (skipped 7 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "all-404-pages-redirect-to-homepage",
     "status": "active",
     "active": true,
     "installed": "1.7",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "All 404 Pages Redirect to Homepage [all-404-pages-redirect-to-homepage] < 2.0 (closed)",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2024-24889"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "genesis-blocks",
     "status": "active",
     "active": true,
     "installed": "1.5.3",
     "available": "3.1.11",
     "priority": "P2",
     "vulns": [
      {
       "name": "Genesis Blocks [genesis-blocks] < 3.1.3",
       "cvss": "6.8",
       "severity": "MEDIUM",
       "cve": "CVE-2024-2761"
      },
      {
       "name": "Genesis Blocks [genesis-blocks] < 3.1.4",
       "cvss": "6.8",
       "severity": "MEDIUM",
       "cve": "CVE-2024-3901"
      },
      {
       "name": "Genesis Blocks [genesis-blocks] < 3.1.3",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-1946"
      },
      {
       "name": "Genesis Blocks [genesis-blocks] < 3.1.4",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-3563"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 1.5.3 -> 3.1.11 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "safe-svg",
     "status": "active",
     "active": true,
     "installed": "2.0.3",
     "available": "2.5.0",
     "priority": "P2",
     "vulns": [
      {
       "name": "Safe SVG [safe-svg] < 2.2.6",
       "cvss": "4.8",
       "severity": "MEDIUM",
       "cve": "CVE-2024-8378"
      },
      {
       "name": "Safe SVG [safe-svg] < 2.1.0",
       "cvss": "0.0",
       "severity": null,
       "cve": "CVE-2023-28426"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 2.0.3 -> 2.5.0 (skipped 5 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "wordpress-seo",
     "status": "active",
     "active": true,
     "installed": "19.11",
     "available": "28.5",
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 22.7",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-4984"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 22.6",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2024-4041"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 21.1",
       "cvss": "5.9",
       "severity": "MEDIUM",
       "cve": "CVE-2023-40680"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 26.6",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-14481"
      }
     ],
     "vuln_count": 9,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 19.11 -> 28.5 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "acf-content-analysis-for-yoast-seo",
     "status": "active",
     "active": true,
     "installed": "3.0.1",
     "available": "3.2",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 3.0.1 -> 3.2"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "classic-editor",
     "status": "active",
     "active": true,
     "installed": "1.6.2",
     "available": "1.7.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.6.2 -> 1.7.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    }
   ],
   "p0": 1,
   "p1": 1,
   "total_updates": 7
  },
  "wpengine:bpgrdev": {
   "platform": "wpengine",
   "install": "bpgrdev",
   "environment": "development",
   "domain": "bpgrdev.wpengine.com",
   "siteurl": "http://bpgrdev.wpengine.com",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "hello-ascential",
   "updates": [
    {
     "plugin": "advanced-custom-fields-pro",
     "status": "active",
     "active": true,
     "installed": "6.2.0",
     "available": "6.8.10",
     "priority": "P0",
     "vulns": [
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.2.10",
       "cvss": "9.9",
       "severity": "CRITICAL",
       "cve": "CVE-2024-34762"
      },
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.2.10",
       "cvss": "8.5",
       "severity": "HIGH",
       "cve": "CVE-2024-34761"
      },
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.3.8",
       "cvss": "6.6",
       "severity": "MEDIUM",
       "cve": "CVE-2024-9529"
      },
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.3.0",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-4565"
      }
     ],
     "vuln_count": 12,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "multi-minor jump 6.2.0 -> 6.8.10 (skipped 6 minor releases)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "elementor",
     "status": "active",
     "active": true,
     "installed": "3.15.3",
     "available": "4.2.4",
     "priority": "P0",
     "vulns": [
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.18.2",
       "cvss": "9.9",
       "severity": "CRITICAL",
       "cve": "CVE-2023-48777"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.19.1",
       "cvss": "8.5",
       "severity": "HIGH",
       "cve": "CVE-2024-24934"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.16.5",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2023-47505"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.16.5",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2023-47504"
      }
     ],
     "vuln_count": 28,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.15.3 -> 4.2.4 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "elementor-pro",
     "status": "active",
     "active": true,
     "installed": "3.15.1",
     "available": "3.16.0",
     "priority": "P0",
     "vulns": [
      {
       "name": "Elementor Pro [elementor-pro] < 4.2.2",
       "cvss": "9.0",
       "severity": "CRITICAL",
       "cve": "CVE-2026-32475"
      },
      {
       "name": "Elementor Pro [elementor-pro] < 3.19.3",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-23523"
      },
      {
       "name": "Elementor Pro [elementor-pro] < 3.25.11",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-8494"
      },
      {
       "name": "Elementor Pro [elementor-pro] < 3.29.1",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-50555"
      }
     ],
     "vuln_count": 12,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "minor version bump 3.15.1 -> 3.16.0",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "alttext-ai",
     "status": "active",
     "active": true,
     "installed": "1.0.47",
     "available": "1.10.38",
     "priority": "P1",
     "vulns": [
      {
       "name": "Alt Text AI &#8211; Automatically generate image alt text for SEO and accessibility [alttext-ai] < 1.5.0",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2024-4847"
      },
      {
       "name": "Alt Text AI &#8211; Automatically generate image alt text for SEO and accessibility [alttext-ai] < 1.9.94",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2025-46232"
      },
      {
       "name": "Alt Text AI &#8211; Automatically generate image alt text for SEO and accessibility [alttext-ai] < 1.3.5",
       "cvss": "5.9",
       "severity": "MEDIUM",
       "cve": "CVE-2024-34366"
      },
      {
       "name": "Alt Text AI &#8211; Automatically generate image alt text for SEO and accessibility [alttext-ai] < 1.10.18",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-25348"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 1.0.47 -> 1.10.38 (skipped 10 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "jet-menu",
     "status": "active",
     "active": true,
     "installed": "2.4.0",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "JetMenu [jet-menu] < 2.4.2",
       "cvss": "8.2",
       "severity": "HIGH",
       "cve": "CVE-2023-48760"
      },
      {
       "name": "JetMenu [jet-menu] < 2.4.9.1",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2025-26953"
      },
      {
       "name": "JetMenu [jet-menu] < 2.4.11.2",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-53987"
      },
      {
       "name": "JetMenu [jet-menu] < 2.4.2",
       "cvss": "6.3",
       "severity": "MEDIUM",
       "cve": "CVE-2023-48762"
      }
     ],
     "vuln_count": 5,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "shortpixel-image-optimiser",
     "status": "active",
     "active": true,
     "installed": "5.4.1",
     "available": "6.5.6",
     "priority": "P1",
     "vulns": [
      {
       "name": "ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 5.6.4",
       "cvss": "7.6",
       "severity": "HIGH",
       "cve": "CVE-2024-48043"
      },
      {
       "name": "ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 6.4.4",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-39471"
      },
      {
       "name": "ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 5.6.4",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-48044"
      },
      {
       "name": "ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 6.3.5",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-11378"
      }
     ],
     "vuln_count": 9,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 5.4.1 -> 6.5.6 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "wp-optimize",
     "status": "active",
     "active": true,
     "installed": "3.2.18",
     "available": "4.6.1",
     "priority": "P1",
     "vulns": [
      {
       "name": "WP-Optimize \u2013 Cache, Compress images, Minify &amp; Clean database to boost page speed &amp; performance [wp-optimize] < 4.5.3",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2026-7252"
      },
      {
       "name": "WP-Optimize \u2013 Cache, Compress images, Minify &amp; Clean database to boost page speed &amp; performance [wp-optimize] < 4.2.0",
       "cvss": "4.1",
       "severity": "MEDIUM",
       "cve": "CVE-2025-3951"
      },
      {
       "name": "WP-Optimize \u2013 Cache, Compress images, Minify &amp; Clean database to boost page speed &amp; performance [wp-optimize] < 4.5.1",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-2712"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.2.18 -> 4.6.1 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "insert-headers-and-footers",
     "status": "active",
     "active": true,
     "installed": "2.1.1",
     "available": "2.3.9",
     "priority": "P1",
     "vulns": [
      {
       "name": "WPCode &#8211; Insert Headers and Footers + Custom Code Snippets &#8211; WordPress Code Manager [insert-headers-and-footers] < 2.3.6",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-8832"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.1.1 -> 2.3.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "ewww-image-optimizer",
     "status": "inactive",
     "active": false,
     "installed": "7.2.0",
     "available": "8.7.7",
     "priority": "P1",
     "vulns": [
      {
       "name": "EWWW Image Optimizer [ewww-image-optimizer] < 8.7.7",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-84773"
      },
      {
       "name": "EWWW Image Optimizer [ewww-image-optimizer] < 8.7.4",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-15446"
      },
      {
       "name": "EWWW Image Optimizer [ewww-image-optimizer] < 7.2.1",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2023-40600"
      },
      {
       "name": "EWWW Image Optimizer [ewww-image-optimizer] < 7.3.0",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2024-31924"
      }
     ],
     "vuln_count": 6,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 7.2.0 -> 8.7.7 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "svg-support",
     "status": "active",
     "active": true,
     "installed": "2.5.5",
     "available": "2.6.1",
     "priority": "P2",
     "vulns": [
      {
       "name": "SVG Support [svg-support] < 2.5.11",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-10222"
      },
      {
       "name": "SVG Support [svg-support] < 2.5.9",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2022-23638"
      },
      {
       "name": "SVG Support [svg-support] < 2.5.8",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2023-6708"
      },
      {
       "name": "SVG Support [svg-support] < 2.5.15",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-48973"
      }
     ],
     "vuln_count": 5,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.5.5 -> 2.6.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "wordpress-seo",
     "status": "active",
     "active": true,
     "installed": "21.1",
     "available": "28.5",
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 22.7",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-4984"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 22.6",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2024-4041"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 26.6",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-14481"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 27.2",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-3427"
      }
     ],
     "vuln_count": 6,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 21.1 -> 28.5 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "limit-login-attempts-reloaded",
     "status": "inactive",
     "active": false,
     "installed": "2.25.22",
     "available": "3.3.8",
     "priority": "P2",
     "vulns": [
      {
       "name": "Limit Login Attempts Security &#8211; Login Security, 2FA, Firewall, Brute Force Prevention [limit-login-attempts-reloaded] < 2.25.27",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2023-6934"
      },
      {
       "name": "Limit Login Attempts Security &#8211; Login Security, 2FA, Firewall, Brute Force Prevention [limit-login-attempts-reloaded] < 2.25.26",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2023-5525"
      },
      {
       "name": "Limit Login Attempts Security &#8211; Login Security, 2FA, Firewall, Brute Force Prevention [limit-login-attempts-reloaded] < 3.3.5",
       "cvss": "3.7",
       "severity": "LOW",
       "cve": "CVE-2026-18356"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.25.22 -> 3.3.8 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "megamenu",
     "status": "inactive",
     "active": false,
     "installed": "3.2.2",
     "available": "3.10.8",
     "priority": "P2",
     "vulns": [
      {
       "name": "Max Mega Menu [megamenu] < 3.3.1",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-28003"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.2.2 -> 3.10.8 (skipped 8 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "search-filter-pro",
     "status": "inactive",
     "active": false,
     "installed": "2.5.16",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Search & Filter Pro [search-filter-pro] < 2.5.18",
       "cvss": "4.8",
       "severity": "MEDIUM",
       "cve": "CVE-2024-6481"
      },
      {
       "name": "Search & Filter Pro [search-filter-pro] < 2.5.20",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-1528"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "simple-banner",
     "status": "inactive",
     "active": false,
     "installed": "2.15.3",
     "available": "3.3.2",
     "priority": "P2",
     "vulns": [
      {
       "name": "Simple Banner &#8211; Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website [simple-banner] < 3.0.5",
       "cvss": "4.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-13898"
      },
      {
       "name": "Simple Banner &#8211; Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website [simple-banner] < 3.1.0",
       "cvss": "4.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-12033"
      },
      {
       "name": "Simple Banner &#8211; Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website [simple-banner] < 3.0.4",
       "cvss": "3.5",
       "severity": "LOW",
       "cve": "CVE-2024-12769"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.15.3 -> 3.3.2 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "eps-301-redirects",
     "status": "active",
     "active": true,
     "installed": "2.73",
     "available": "2.85",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 2.73 -> 2.85 (skipped 12 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "admin-taxonomy-filter",
     "status": "active",
     "active": true,
     "installed": "1.0.2",
     "available": "1.0.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.0.2 -> 1.0.5"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "child-theme-configurator",
     "status": "active",
     "active": true,
     "installed": "2.6.2",
     "available": "2.6.7",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 2.6.2 -> 2.6.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "cookie-law-info",
     "status": "active",
     "active": true,
     "installed": "3.1.2",
     "available": "3.5.6",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.1.2 -> 3.5.6 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "disable-json-api",
     "status": "active",
     "active": true,
     "installed": "1.7",
     "available": "1.8",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.7 -> 1.8"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "disable-xml-rpc-api",
     "status": "active",
     "active": true,
     "installed": "2.1.5",
     "available": "2.1.7",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 2.1.5 -> 2.1.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "duplicate-page",
     "status": "active",
     "active": true,
     "installed": "4.5.2",
     "available": "4.5.9",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 4.5.2 -> 4.5.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wp-revisions-control",
     "status": "active",
     "active": true,
     "installed": "1.4.3",
     "available": "1.4.4",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.4.3 -> 1.4.4"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "headers-security-advanced-hsts-wp",
     "status": "inactive",
     "active": false,
     "installed": "5.0.28",
     "available": "5.3.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.0.28 -> 5.3.5 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "redirection",
     "status": "inactive",
     "active": false,
     "installed": "5.3.10",
     "available": "5.10.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.3.10 -> 5.10.0 (skipped 7 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wp-widget-disable",
     "status": "inactive",
     "active": false,
     "installed": "3.0.0",
     "available": "3.0.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 3.0.0 -> 3.0.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    }
   ],
   "p0": 3,
   "p1": 6,
   "total_updates": 24
  },
  "wpengine:bpgsandbox": {
   "platform": "wpengine",
   "install": "bpgsandbox",
   "environment": "staging",
   "domain": "bpgsandbox.wpengine.com",
   "siteurl": "http://bpgsandbox.wpengine.com",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "hello-ascential",
   "updates": [
    {
     "plugin": "advanced-custom-fields-pro",
     "status": "active",
     "active": true,
     "installed": "6.2.0",
     "available": "6.8.10",
     "priority": "P0",
     "vulns": [
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.2.10",
       "cvss": "9.9",
       "severity": "CRITICAL",
       "cve": "CVE-2024-34762"
      },
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.2.10",
       "cvss": "8.5",
       "severity": "HIGH",
       "cve": "CVE-2024-34761"
      },
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.3.8",
       "cvss": "6.6",
       "severity": "MEDIUM",
       "cve": "CVE-2024-9529"
      },
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.3.0",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-4565"
      }
     ],
     "vuln_count": 12,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "multi-minor jump 6.2.0 -> 6.8.10 (skipped 6 minor releases)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "elementor",
     "status": "active",
     "active": true,
     "installed": "3.15.3",
     "available": "4.2.4",
     "priority": "P0",
     "vulns": [
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.18.2",
       "cvss": "9.9",
       "severity": "CRITICAL",
       "cve": "CVE-2023-48777"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.19.1",
       "cvss": "8.5",
       "severity": "HIGH",
       "cve": "CVE-2024-24934"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.16.5",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2023-47505"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.16.5",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2023-47504"
      }
     ],
     "vuln_count": 28,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.15.3 -> 4.2.4 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "elementor-pro",
     "status": "active",
     "active": true,
     "installed": "3.15.1",
     "available": null,
     "priority": "P0",
     "vulns": [
      {
       "name": "Elementor Pro [elementor-pro] < 4.2.2",
       "cvss": "9.0",
       "severity": "CRITICAL",
       "cve": "CVE-2026-32475"
      },
      {
       "name": "Elementor Pro [elementor-pro] < 3.19.3",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-23523"
      },
      {
       "name": "Elementor Pro [elementor-pro] < 3.25.11",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-8494"
      },
      {
       "name": "Elementor Pro [elementor-pro] < 3.29.1",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-50555"
      }
     ],
     "vuln_count": 12,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "ewww-image-optimizer",
     "status": "active",
     "active": true,
     "installed": "7.2.0",
     "available": "8.7.7",
     "priority": "P1",
     "vulns": [
      {
       "name": "EWWW Image Optimizer [ewww-image-optimizer] < 8.7.7",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-84773"
      },
      {
       "name": "EWWW Image Optimizer [ewww-image-optimizer] < 8.7.4",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-15446"
      },
      {
       "name": "EWWW Image Optimizer [ewww-image-optimizer] < 7.2.1",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2023-40600"
      },
      {
       "name": "EWWW Image Optimizer [ewww-image-optimizer] < 7.3.0",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2024-31924"
      }
     ],
     "vuln_count": 6,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 7.2.0 -> 8.7.7 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "jet-menu",
     "status": "active",
     "active": true,
     "installed": "2.4.0",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "JetMenu [jet-menu] < 2.4.2",
       "cvss": "8.2",
       "severity": "HIGH",
       "cve": "CVE-2023-48760"
      },
      {
       "name": "JetMenu [jet-menu] < 2.4.9.1",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2025-26953"
      },
      {
       "name": "JetMenu [jet-menu] < 2.4.11.2",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-53987"
      },
      {
       "name": "JetMenu [jet-menu] < 2.4.2",
       "cvss": "6.3",
       "severity": "MEDIUM",
       "cve": "CVE-2023-48762"
      }
     ],
     "vuln_count": 5,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "insert-headers-and-footers",
     "status": "active",
     "active": true,
     "installed": "2.1.1",
     "available": "2.3.9",
     "priority": "P1",
     "vulns": [
      {
       "name": "WPCode &#8211; Insert Headers and Footers + Custom Code Snippets &#8211; WordPress Code Manager [insert-headers-and-footers] < 2.3.6",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-8832"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.1.1 -> 2.3.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "wp-optimize",
     "status": "inactive",
     "active": false,
     "installed": "3.2.18",
     "available": "4.6.1",
     "priority": "P1",
     "vulns": [
      {
       "name": "WP-Optimize \u2013 Cache, Compress images, Minify &amp; Clean database to boost page speed &amp; performance [wp-optimize] < 4.5.3",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2026-7252"
      },
      {
       "name": "WP-Optimize \u2013 Cache, Compress images, Minify &amp; Clean database to boost page speed &amp; performance [wp-optimize] < 4.2.0",
       "cvss": "4.1",
       "severity": "MEDIUM",
       "cve": "CVE-2025-3951"
      },
      {
       "name": "WP-Optimize \u2013 Cache, Compress images, Minify &amp; Clean database to boost page speed &amp; performance [wp-optimize] < 4.5.1",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-2712"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.2.18 -> 4.6.1 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "limit-login-attempts-reloaded",
     "status": "active",
     "active": true,
     "installed": "2.25.22",
     "available": "3.3.8",
     "priority": "P2",
     "vulns": [
      {
       "name": "Limit Login Attempts Security &#8211; Login Security, 2FA, Firewall, Brute Force Prevention [limit-login-attempts-reloaded] < 2.25.27",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2023-6934"
      },
      {
       "name": "Limit Login Attempts Security &#8211; Login Security, 2FA, Firewall, Brute Force Prevention [limit-login-attempts-reloaded] < 2.25.26",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2023-5525"
      },
      {
       "name": "Limit Login Attempts Security &#8211; Login Security, 2FA, Firewall, Brute Force Prevention [limit-login-attempts-reloaded] < 3.3.5",
       "cvss": "3.7",
       "severity": "LOW",
       "cve": "CVE-2026-18356"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.25.22 -> 3.3.8 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "megamenu",
     "status": "active",
     "active": true,
     "installed": "3.2.2",
     "available": "3.10.8",
     "priority": "P2",
     "vulns": [
      {
       "name": "Max Mega Menu [megamenu] < 3.3.1",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-28003"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.2.2 -> 3.10.8 (skipped 8 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "svg-support",
     "status": "active",
     "active": true,
     "installed": "2.5.5",
     "available": "2.6.1",
     "priority": "P2",
     "vulns": [
      {
       "name": "SVG Support [svg-support] < 2.5.11",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-10222"
      },
      {
       "name": "SVG Support [svg-support] < 2.5.9",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2022-23638"
      },
      {
       "name": "SVG Support [svg-support] < 2.5.8",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2023-6708"
      },
      {
       "name": "SVG Support [svg-support] < 2.5.15",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-48973"
      }
     ],
     "vuln_count": 5,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.5.5 -> 2.6.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "admin-taxonomy-filter",
     "status": "active",
     "active": true,
     "installed": "1.0.2",
     "available": "1.0.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.0.2 -> 1.0.5"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "child-theme-configurator",
     "status": "active",
     "active": true,
     "installed": "2.6.2",
     "available": "2.6.7",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 2.6.2 -> 2.6.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "cookie-law-info",
     "status": "active",
     "active": true,
     "installed": "3.1.2",
     "available": "3.5.6",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.1.2 -> 3.5.6 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "disable-json-api",
     "status": "active",
     "active": true,
     "installed": "1.7",
     "available": "1.8",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.7 -> 1.8"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "disable-xml-rpc-api",
     "status": "active",
     "active": true,
     "installed": "2.1.5",
     "available": "2.1.7",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 2.1.5 -> 2.1.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "duplicate-page",
     "status": "active",
     "active": true,
     "installed": "4.5.2",
     "available": "4.5.9",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 4.5.2 -> 4.5.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wp-widget-disable",
     "status": "active",
     "active": true,
     "installed": "3.0.0",
     "available": "3.0.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 3.0.0 -> 3.0.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wp-revisions-control",
     "status": "active",
     "active": true,
     "installed": "1.4.3",
     "available": "1.4.4",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.4.3 -> 1.4.4"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "headers-security-advanced-hsts-wp",
     "status": "inactive",
     "active": false,
     "installed": "5.0.28",
     "available": "5.3.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.0.28 -> 5.3.5 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    }
   ],
   "p0": 3,
   "p1": 4,
   "total_updates": 17
  },
  "wpengine:norweststg": {
   "platform": "wpengine",
   "install": "norweststg",
   "environment": "staging",
   "domain": "norweststg.wpengine.com",
   "siteurl": "https://norweststg.wpengine.com",
   "core": "7.0.3",
   "core_update": "7.0.4",
   "theme": "brand-nav-child-theme",
   "updates": [
    {
     "plugin": "advanced-custom-fields-pro",
     "status": "active",
     "active": true,
     "installed": "6.1.6",
     "available": "6.8.10",
     "priority": "P0",
     "vulns": [
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.2.10",
       "cvss": "9.9",
       "severity": "CRITICAL",
       "cve": "CVE-2024-34762"
      },
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.2.10",
       "cvss": "8.5",
       "severity": "HIGH",
       "cve": "CVE-2024-34761"
      },
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.3.8",
       "cvss": "6.6",
       "severity": "MEDIUM",
       "cve": "CVE-2024-9529"
      },
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.3.0",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-4565"
      }
     ],
     "vuln_count": 14,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "multi-minor jump 6.1.6 -> 6.8.10 (skipped 7 minor releases)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "elementor",
     "status": "active",
     "active": true,
     "installed": "3.13.3",
     "available": "4.2.4",
     "priority": "P0",
     "vulns": [
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.18.2",
       "cvss": "9.9",
       "severity": "CRITICAL",
       "cve": "CVE-2023-48777"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.19.1",
       "cvss": "8.5",
       "severity": "HIGH",
       "cve": "CVE-2024-24934"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.16.5",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2023-47505"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.16.5",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2023-47504"
      }
     ],
     "vuln_count": 28,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.13.3 -> 4.2.4 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "elementor-pro",
     "status": "active",
     "active": true,
     "installed": "3.13.2",
     "available": null,
     "priority": "P0",
     "vulns": [
      {
       "name": "Elementor Pro [elementor-pro] < 4.2.2",
       "cvss": "9.0",
       "severity": "CRITICAL",
       "cve": "CVE-2026-32475"
      },
      {
       "name": "Elementor Pro [elementor-pro] < 3.19.3",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-23523"
      },
      {
       "name": "Elementor Pro [elementor-pro] < 3.25.11",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-8494"
      },
      {
       "name": "Elementor Pro [elementor-pro] < 3.29.1",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-50555"
      }
     ],
     "vuln_count": 12,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "better-search-replace",
     "status": "inactive",
     "active": false,
     "installed": "1.4.2",
     "available": "1.4.11",
     "priority": "P0",
     "vulns": [
      {
       "name": "Better Search Replace [better-search-replace] < 1.4.5",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2023-6933"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.4.2 -> 1.4.11"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "jet-elements",
     "status": "inactive",
     "active": false,
     "installed": "2.6.9",
     "available": null,
     "priority": "P0",
     "vulns": [
      {
       "name": "JetElements For Elementor [jet-elements] < 2.6.11",
       "cvss": "9.0",
       "severity": "CRITICAL",
       "cve": "CVE-2023-39157"
      },
      {
       "name": "JetElements For Elementor [jet-elements] < 2.6.20.1",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2024-7145"
      },
      {
       "name": "JetElements For Elementor [jet-elements] < 2.6.13.1",
       "cvss": "8.2",
       "severity": "HIGH",
       "cve": "CVE-2023-48760"
      },
      {
       "name": "JetElements For Elementor [jet-elements] < 2.6.13.1",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2023-48759"
      }
     ],
     "vuln_count": 17,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "jet-smart-filters",
     "status": "inactive",
     "active": false,
     "installed": "3.1.1",
     "available": null,
     "priority": "P0",
     "vulns": [
      {
       "name": "JetSmartFilters [jet-smart-filters] < 3.8.1.1",
       "cvss": "9.3",
       "severity": "CRITICAL",
       "cve": "CVE-2026-48875"
      },
      {
       "name": "JetSmartFilters [jet-smart-filters] < 3.8.3.1",
       "cvss": "9.3",
       "severity": "CRITICAL",
       "cve": "CVE-2026-56067"
      },
      {
       "name": "JetSmartFilters [jet-smart-filters] < 3.2.2.1",
       "cvss": "8.2",
       "severity": "HIGH",
       "cve": "CVE-2023-48760"
      },
      {
       "name": "JetSmartFilters [jet-smart-filters] < 3.6.7.1",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-54008"
      }
     ],
     "vuln_count": 8,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "wp-file-manager",
     "status": "inactive",
     "active": false,
     "installed": "7.1.8",
     "available": "8.0.4",
     "priority": "P0",
     "vulns": [
      {
       "name": "File Manager [wp-file-manager] < 7.2.2",
       "cvss": "9.9",
       "severity": "CRITICAL",
       "cve": "CVE-2023-6825"
      },
      {
       "name": "File Manager [wp-file-manager] < 7.2.5",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2024-1538"
      },
      {
       "name": "File Manager [wp-file-manager] < 7.2.2",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2024-0761"
      },
      {
       "name": "File Manager [wp-file-manager] < 7.2.6",
       "cvss": "6.8",
       "severity": "MEDIUM",
       "cve": "CVE-2024-2654"
      }
     ],
     "vuln_count": 6,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 7.1.8 -> 8.0.4 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wp-server-stats",
     "status": "inactive",
     "active": false,
     "installed": "1.7.3",
     "available": "1.9.1",
     "priority": "P0",
     "vulns": [
      {
       "name": "WP Server Health Stats [wp-server-stats] < 1.7.7",
       "cvss": "10.0",
       "severity": "CRITICAL",
       "cve": "CVE-2024-6297"
      },
      {
       "name": "WP Server Health Stats [wp-server-stats] < 1.7.4",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2024-31250"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.7.3 -> 1.9.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "dynamic-content-for-elementor",
     "status": "active",
     "active": true,
     "installed": "2.9.4",
     "available": "2.10.6",
     "priority": "P1",
     "vulns": [
      {
       "name": "Dynamic Content for Elementor [dynamic-content-for-elementor] < 2.12.5",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2023-52150"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "minor version bump 2.9.4 -> 2.10.6",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "ewww-image-optimizer",
     "status": "active",
     "active": true,
     "installed": "7.0.0",
     "available": "8.7.7",
     "priority": "P1",
     "vulns": [
      {
       "name": "EWWW Image Optimizer [ewww-image-optimizer] < 8.7.7",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-84773"
      },
      {
       "name": "EWWW Image Optimizer [ewww-image-optimizer] < 8.7.4",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-15446"
      },
      {
       "name": "EWWW Image Optimizer [ewww-image-optimizer] < 7.2.1",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2023-40600"
      },
      {
       "name": "EWWW Image Optimizer [ewww-image-optimizer] < 7.3.0",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2024-31924"
      }
     ],
     "vuln_count": 6,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 7.0.0 -> 8.7.7 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "wp-2fa",
     "status": "active",
     "active": true,
     "installed": "2.4.1",
     "available": "4.1.0",
     "priority": "P1",
     "vulns": [
      {
       "name": "WP 2FA &#8211; Two-factor authentication for WordPress [wp-2fa] < 2.6.3",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2024-32568"
      },
      {
       "name": "WP 2FA &#8211; Two-factor authentication for WordPress [wp-2fa] < 3.0.0",
       "cvss": "6.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-12628"
      },
      {
       "name": "WP 2FA &#8211; Two-factor authentication for WordPress [wp-2fa] < 2.6.4",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2022-44587"
      },
      {
       "name": "WP 2FA &#8211; Two-factor authentication for WordPress [wp-2fa] < 2.6.0",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2023-6506"
      }
     ],
     "vuln_count": 7,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.4.1 -> 4.1.0 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "insert-headers-and-footers",
     "status": "active",
     "active": true,
     "installed": "2.0.11",
     "available": "2.3.9",
     "priority": "P1",
     "vulns": [
      {
       "name": "WPCode &#8211; Insert Headers and Footers + Custom Code Snippets &#8211; WordPress Code Manager [insert-headers-and-footers] < 2.3.6",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-8832"
      },
      {
       "name": "WPCode &#8211; Insert Headers and Footers + Custom Code Snippets &#8211; WordPress Code Manager [insert-headers-and-footers] < 2.0.13.1",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2023-3524"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 2.0.11 -> 2.3.9 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "woocommerce-ajax-filters",
     "status": "inactive",
     "active": false,
     "installed": "1.6.4.1",
     "available": "3.3",
     "priority": "P1",
     "vulns": [
      {
       "name": "Advanced AJAX Product Filters [woocommerce-ajax-filters] < 3.2.1",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-66439"
      },
      {
       "name": "Advanced AJAX Product Filters [woocommerce-ajax-filters] < 1.6.8.2",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2025-1505"
      },
      {
       "name": "Advanced AJAX Product Filters [woocommerce-ajax-filters] < 3.1.9.7",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-1426"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 1.6.4.1 -> 3.3 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "advanced-custom-fields",
     "status": "inactive",
     "active": false,
     "installed": "6.0.7",
     "available": "6.8.10",
     "priority": "P1",
     "vulns": [
      {
       "name": "Advanced Custom Fields (ACF\u00ae) [advanced-custom-fields] < 6.1.6",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2023-30777"
      },
      {
       "name": "Advanced Custom Fields (ACF\u00ae) [advanced-custom-fields] < 6.3.8",
       "cvss": "6.6",
       "severity": "MEDIUM",
       "cve": "CVE-2024-9529"
      },
      {
       "name": "Advanced Custom Fields (ACF\u00ae) [advanced-custom-fields] < 6.3.0",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-4565"
      },
      {
       "name": "Advanced Custom Fields (ACF\u00ae) [advanced-custom-fields] < 6.3.6",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2024-45429"
      }
     ],
     "vuln_count": 13,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "multi-minor jump 6.0.7 -> 6.8.10 (skipped 8 minor releases)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "advanced-database-cleaner",
     "status": "inactive",
     "active": false,
     "installed": "3.1.2",
     "available": "4.2.0",
     "priority": "P1",
     "vulns": [
      {
       "name": "Advanced Database Cleaner \u2013 Optimize &amp; Clean Database to Speed Up Site Performance [advanced-database-cleaner] < 3.1.3",
       "cvss": "7.6",
       "severity": "HIGH",
       "cve": "CVE-2023-49764"
      },
      {
       "name": "Advanced Database Cleaner \u2013 Optimize &amp; Clean Database to Speed Up Site Performance [advanced-database-cleaner] < 3.1.4",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2024-0668"
      },
      {
       "name": "Advanced Database Cleaner \u2013 Optimize &amp; Clean Database to Speed Up Site Performance [advanced-database-cleaner] < 3.1.7",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-11497"
      },
      {
       "name": "Advanced Database Cleaner \u2013 Optimize &amp; Clean Database to Speed Up Site Performance [advanced-database-cleaner] < 3.1.7",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-64357"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.1.2 -> 4.2.0 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "imagemagick-engine",
     "status": "inactive",
     "active": false,
     "installed": "1.7.7",
     "available": "2.0.0",
     "priority": "P1",
     "vulns": [
      {
       "name": "ImageMagick Engine [imagemagick-engine] < 1.7.11",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2024-6486"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 1.7.7 -> 2.0.0 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "users-customers-import-export-for-wp-woocommerce",
     "status": "inactive",
     "active": false,
     "installed": "2.3.9",
     "available": "2.7.5",
     "priority": "P1",
     "vulns": [
      {
       "name": "Export and Import Users and Customers [users-customers-import-export-for-wp-woocommerce] < 2.6.3",
       "cvss": "7.6",
       "severity": "HIGH",
       "cve": "CVE-2025-1970"
      },
      {
       "name": "Export and Import Users and Customers [users-customers-import-export-for-wp-woocommerce] < 2.4.2",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2023-3459"
      },
      {
       "name": "Export and Import Users and Customers [users-customers-import-export-for-wp-woocommerce] < 2.4.9",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2023-6558"
      },
      {
       "name": "Export and Import Users and Customers [users-customers-import-export-for-wp-woocommerce] < 2.6.3",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2025-1971"
      }
     ],
     "vuln_count": 8,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 2.3.9 -> 2.7.5 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "jetpack",
     "status": "inactive",
     "active": false,
     "installed": "12.0.1",
     "available": "16.2",
     "priority": "P1",
     "vulns": [
      {
       "name": "Jetpack &#8211; WP Security, Backup, Speed, &amp; Growth [jetpack] < 12.1.1",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2023-2996"
      },
      {
       "name": "Jetpack &#8211; WP Security, Backup, Speed, &amp; Growth [jetpack] < 12.8-a.3",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2023-45050"
      },
      {
       "name": "Jetpack &#8211; WP Security, Backup, Speed, &amp; Growth [jetpack] >= 3.2 - < 16.1.3",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2024-10858"
      },
      {
       "name": "Jetpack &#8211; WP Security, Backup, Speed, &amp; Growth [jetpack] == 11.4",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2023-54332"
      }
     ],
     "vuln_count": 12,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 12.0.1 -> 16.2 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "jet-tricks",
     "status": "inactive",
     "active": false,
     "installed": "1.4.3",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "JetTricks [jet-tricks] < 1.4.6.2",
       "cvss": "8.2",
       "severity": "HIGH",
       "cve": "CVE-2023-48760"
      },
      {
       "name": "JetTricks [jet-tricks] < 1.5.1.1",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2025-26942"
      },
      {
       "name": "JetTricks [jet-tricks] < 1.5.4.2",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-53992"
      },
      {
       "name": "JetTricks [jet-tricks] < 1.4.6.2",
       "cvss": "6.3",
       "severity": "MEDIUM",
       "cve": "CVE-2023-48762"
      }
     ],
     "vuln_count": 6,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "password-protect-page",
     "status": "inactive",
     "active": false,
     "installed": "1.8.8",
     "available": "1.9.24",
     "priority": "P1",
     "vulns": [
      {
       "name": "PPWP &#8211; Password Protect Pages [password-protect-page] < 1.9.19",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-0551"
      },
      {
       "name": "PPWP &#8211; Password Protect Pages [password-protect-page] < 1.9.11",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-5998"
      },
      {
       "name": "PPWP &#8211; Password Protect Pages [password-protect-page] <= 1.9.21 (unfixed)",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-3639"
      },
      {
       "name": "PPWP &#8211; Password Protect Pages [password-protect-page] <= 1.9.21 (unfixed)",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-9878"
      }
     ],
     "vuln_count": 10,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.8.8 -> 1.9.24"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "shortpixel-image-optimiser",
     "status": "inactive",
     "active": false,
     "installed": "5.2.1",
     "available": "6.5.6",
     "priority": "P1",
     "vulns": [
      {
       "name": "ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 5.6.4",
       "cvss": "7.6",
       "severity": "HIGH",
       "cve": "CVE-2024-48043"
      },
      {
       "name": "ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 6.4.4",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-39471"
      },
      {
       "name": "ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 5.6.4",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-48044"
      },
      {
       "name": "ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 6.3.5",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-11378"
      }
     ],
     "vuln_count": 9,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 5.2.1 -> 6.5.6 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "timber-library",
     "status": "inactive",
     "active": false,
     "installed": "1.22.1",
     "available": "1.23.4",
     "priority": "P1",
     "vulns": [
      {
       "name": "Timber [timber-library] < 1.23.3 (closed)",
       "cvss": "8.6",
       "severity": "HIGH",
       "cve": "CVE-2024-45411"
      },
      {
       "name": "Timber [timber-library] < 1.23.1 (closed)",
       "cvss": "8.0",
       "severity": "HIGH",
       "cve": "CVE-2024-29800"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.22.1 -> 1.23.4"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "white-label-cms",
     "status": "inactive",
     "active": false,
     "installed": "2.5",
     "available": "2.7.14",
     "priority": "P1",
     "vulns": [
      {
       "name": "White Label CMS [white-label-cms] < 2.7.5",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2024-43303"
      },
      {
       "name": "White Label CMS [white-label-cms] < 2.7.4",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2024-4280"
      },
      {
       "name": "White Label CMS [white-label-cms] < 2.7.13",
       "cvss": "4.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-11898"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.5 -> 2.7.14"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wordpress-importer",
     "status": "inactive",
     "active": false,
     "installed": "0.8",
     "available": "0.9.6",
     "priority": "P1",
     "vulns": [
      {
       "name": "WordPress Importer [wordpress-importer] < 0.8.4",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2024-13889"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 0.8 -> 0.9.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wp-all-import-pro",
     "status": "inactive",
     "active": false,
     "installed": "4.7.8",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "WP All Import Pro [wp-all-import-pro] < 4.9.4",
       "cvss": "7.6",
       "severity": "HIGH",
       "cve": "CVE-2024-9624"
      },
      {
       "name": "WP All Import Pro [wp-all-import-pro] < 4.9.8",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2024-9664"
      },
      {
       "name": "WP All Import Pro [wp-all-import-pro] < 4.9.8",
       "cvss": "5.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-8722"
      },
      {
       "name": "WP All Import Pro [wp-all-import-pro] < 4.9.8",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2024-9661"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "wp-bulk-delete",
     "status": "inactive",
     "active": false,
     "installed": "1.2.4",
     "available": "1.4.4",
     "priority": "P1",
     "vulns": [
      {
       "name": "WP Bulk Delete [wp-bulk-delete] < 1.3.2",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2024-47352"
      },
      {
       "name": "WP Bulk Delete [wp-bulk-delete] < 1.4.3",
       "cvss": "4.9",
       "severity": "MEDIUM",
       "cve": "CVE-2026-15727"
      },
      {
       "name": "WP Bulk Delete [wp-bulk-delete] < 1.3.7",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-58192"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.2.4 -> 1.4.4"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "query-monitor",
     "status": "active",
     "active": true,
     "installed": "3.12.3",
     "available": "4.0.7",
     "priority": "P2",
     "vulns": [
      {
       "name": "Query Monitor [query-monitor] < 3.20.4",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-4267"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.12.3 -> 4.0.7 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "search-filter-pro",
     "status": "active",
     "active": true,
     "installed": "2.5.14",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Search & Filter Pro [search-filter-pro] < 2.5.18",
       "cvss": "4.8",
       "severity": "MEDIUM",
       "cve": "CVE-2024-6481"
      },
      {
       "name": "Search & Filter Pro [search-filter-pro] < 2.5.20",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-1528"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "sticky-header-effects-for-elementor",
     "status": "active",
     "active": true,
     "installed": "1.6.5",
     "available": "2.2.2",
     "priority": "P2",
     "vulns": [
      {
       "name": "Sticky Header Effects for Elementor [sticky-header-effects-for-elementor] < 2.1.3",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-58251"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 1.6.5 -> 2.2.2 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "svg-support",
     "status": "active",
     "active": true,
     "installed": "2.5.5",
     "available": "2.6.1",
     "priority": "P2",
     "vulns": [
      {
       "name": "SVG Support [svg-support] < 2.5.11",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-10222"
      },
      {
       "name": "SVG Support [svg-support] < 2.5.9",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2022-23638"
      },
      {
       "name": "SVG Support [svg-support] < 2.5.8",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2023-6708"
      },
      {
       "name": "SVG Support [svg-support] < 2.5.15",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-48973"
      }
     ],
     "vuln_count": 5,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.5.5 -> 2.6.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "wp-custom-taxonomy-image",
     "status": "inactive",
     "active": false,
     "installed": "1.0.0",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Category and Taxonomy Image [wp-custom-taxonomy-image] <= 1.0.0 (unfixed + closed)",
       "cvss": "4.8",
       "severity": "MEDIUM",
       "cve": "CVE-2024-9591"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "custom-post-type-ui",
     "status": "inactive",
     "active": false,
     "installed": "1.13.4",
     "available": "1.19.3",
     "priority": "P2",
     "vulns": [
      {
       "name": "Custom Post Type UI [custom-post-type-ui] < 1.13.5",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2023-1623"
      },
      {
       "name": "Custom Post Type UI [custom-post-type-ui] < 1.18.1",
       "cvss": "4.8",
       "severity": "MEDIUM",
       "cve": "CVE-2025-12826"
      },
      {
       "name": "Custom Post Type UI [custom-post-type-ui] < 1.18.2",
       "cvss": "4.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-14056"
      },
      {
       "name": "Custom Post Type UI [custom-post-type-ui] < 1.13.5",
       "cvss": null,
       "severity": null,
       "cve": ""
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 1.13.4 -> 1.19.3 (skipped 6 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "dashboard-welcome-for-elementor",
     "status": "inactive",
     "active": false,
     "installed": "1.0.7",
     "available": "1.0.11",
     "priority": "P2",
     "vulns": [
      {
       "name": "Dashboard Welcome for Elementor [dashboard-welcome-for-elementor] < 1.0.8",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2024-32110"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.0.7 -> 1.0.11"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "genesis-blocks",
     "status": "inactive",
     "active": false,
     "installed": "1.5.4",
     "available": "3.1.11",
     "priority": "P2",
     "vulns": [
      {
       "name": "Genesis Blocks [genesis-blocks] < 3.1.3",
       "cvss": "6.8",
       "severity": "MEDIUM",
       "cve": "CVE-2024-2761"
      },
      {
       "name": "Genesis Blocks [genesis-blocks] < 3.1.4",
       "cvss": "6.8",
       "severity": "MEDIUM",
       "cve": "CVE-2024-3901"
      },
      {
       "name": "Genesis Blocks [genesis-blocks] < 3.1.3",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-1946"
      },
      {
       "name": "Genesis Blocks [genesis-blocks] < 3.1.4",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-3563"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 1.5.4 -> 3.1.11 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "limit-login-attempts-reloaded",
     "status": "inactive",
     "active": false,
     "installed": "2.25.13",
     "available": "3.3.8",
     "priority": "P2",
     "vulns": [
      {
       "name": "Limit Login Attempts Security &#8211; Login Security, 2FA, Firewall, Brute Force Prevention [limit-login-attempts-reloaded] < 2.25.27",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2023-6934"
      },
      {
       "name": "Limit Login Attempts Security &#8211; Login Security, 2FA, Firewall, Brute Force Prevention [limit-login-attempts-reloaded] < 2.25.26",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2023-5525"
      },
      {
       "name": "Limit Login Attempts Security &#8211; Login Security, 2FA, Firewall, Brute Force Prevention [limit-login-attempts-reloaded] < 3.3.5",
       "cvss": "3.7",
       "severity": "LOW",
       "cve": "CVE-2026-18356"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.25.13 -> 3.3.8 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "make-column-clickable-elementor",
     "status": "inactive",
     "active": false,
     "installed": "1.4.0",
     "available": "1.6.2",
     "priority": "P2",
     "vulns": [
      {
       "name": "Make Column Clickable for Elementor [make-column-clickable-elementor] < 1.6.1",
       "cvss": "0.0",
       "severity": null,
       "cve": "CVE-2025-59592"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.4.0 -> 1.6.2"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "pojo-accessibility",
     "status": "inactive",
     "active": false,
     "installed": "2.1.0",
     "available": "4.1.4",
     "priority": "P2",
     "vulns": [
      {
       "name": "Web Accessibility (formally known as Ally) &#8211; WCAG Scanning, Guided Fixes, Usability Widget [pojo-accessibility] < 4.0.3",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-25386"
      },
      {
       "name": "Web Accessibility (formally known as Ally) &#8211; WCAG Scanning, Guided Fixes, Usability Widget [pojo-accessibility] < 3.8.1",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-10700"
      },
      {
       "name": "Web Accessibility (formally known as Ally) &#8211; WCAG Scanning, Guided Fixes, Usability Widget [pojo-accessibility] < 3.2.0",
       "cvss": "0.0",
       "severity": null,
       "cve": "CVE-2025-32640"
      },
      {
       "name": "Web Accessibility (formally known as Ally) &#8211; WCAG Scanning, Guided Fixes, Usability Widget [pojo-accessibility] < 4.1.0",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-2413"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.1.0 -> 4.1.4 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "post-type-switcher",
     "status": "inactive",
     "active": false,
     "installed": "3.2.1",
     "available": "4.0.1",
     "priority": "P2",
     "vulns": [
      {
       "name": "Post Type Switcher [post-type-switcher] < 4.0.1",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-12524"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.2.1 -> 4.0.1 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "shortpixel-adaptive-images",
     "status": "inactive",
     "active": false,
     "installed": "3.7.1",
     "available": "3.11.6",
     "priority": "P2",
     "vulns": [
      {
       "name": "ShortPixel Adaptive Images &#8211; WebP, AVIF, CDN, Image Optimization [shortpixel-adaptive-images] < 3.11.4",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-57342"
      },
      {
       "name": "ShortPixel Adaptive Images &#8211; WebP, AVIF, CDN, Image Optimization [shortpixel-adaptive-images] < 3.11.5",
       "cvss": "5.8",
       "severity": "MEDIUM",
       "cve": "CVE-2026-56066"
      },
      {
       "name": "ShortPixel Adaptive Images &#8211; WebP, AVIF, CDN, Image Optimization [shortpixel-adaptive-images] < 3.8.3",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2024-31230"
      },
      {
       "name": "ShortPixel Adaptive Images &#8211; WebP, AVIF, CDN, Image Optimization [shortpixel-adaptive-images] < 3.8.4",
       "cvss": "4.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-35172"
      }
     ],
     "vuln_count": 9,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.7.1 -> 3.11.6 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "remove-old-slugspermalinks",
     "status": "inactive",
     "active": false,
     "installed": "2.6.2",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Slugs Manager: Delete Old Permalinks from WordPress Database [remove-old-slugspermalinks] < 2.7.0",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2024-30536"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "white-label",
     "status": "inactive",
     "active": false,
     "installed": "2.8.0",
     "available": "2.16.9",
     "priority": "P2",
     "vulns": [
      {
       "name": "White Label &#8211; WordPress Custom Admin, Custom Login Page, and Custom Dashboard [white-label] < 2.9.1",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2023-52128"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 2.8.0 -> 2.16.9 (skipped 8 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wp-migrate-db",
     "status": "inactive",
     "active": false,
     "installed": "2.6.5",
     "available": "2.7.11",
     "priority": "P2",
     "vulns": [
      {
       "name": "WP Migrate Lite &#8211; Migration Made Easy [wp-migrate-db] < 2.7.7",
       "cvss": "5.8",
       "severity": "MEDIUM",
       "cve": "CVE-2025-11427"
      },
      {
       "name": "WP Migrate Lite &#8211; Migration Made Easy [wp-migrate-db] < 2.7.9",
       "cvss": "4.7",
       "severity": "MEDIUM",
       "cve": "CVE-2026-49043"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.6.5 -> 2.7.11"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "https-redirection",
     "status": "inactive",
     "active": false,
     "installed": "1.9.1",
     "available": "2.0.1",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 1.9.1 -> 2.0.1 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "online-active-users",
     "status": "inactive",
     "active": false,
     "installed": "1.2",
     "available": "3.4.4",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 1.2 -> 3.4.4 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "admin-taxonomy-filter",
     "status": "active",
     "active": true,
     "installed": "1.0.2",
     "available": "1.0.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.0.2 -> 1.0.5"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "child-theme-configurator",
     "status": "active",
     "active": true,
     "installed": "2.6.2",
     "available": "2.6.7",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 2.6.2 -> 2.6.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "classic-editor",
     "status": "active",
     "active": true,
     "installed": "1.6.3",
     "available": "1.7.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.6.3 -> 1.7.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "disable-json-api",
     "status": "active",
     "active": true,
     "installed": "1.7",
     "available": "1.8",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.7 -> 1.8"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "duplicate-page",
     "status": "active",
     "active": true,
     "installed": "4.5.2",
     "available": "4.5.9",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 4.5.2 -> 4.5.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "flying-pages",
     "status": "active",
     "active": true,
     "installed": "2.4.6",
     "available": "2.4.7",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 2.4.6 -> 2.4.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wp-revisions-control",
     "status": "active",
     "active": true,
     "installed": "1.4.3",
     "available": "1.4.4",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.4.3 -> 1.4.4"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "admin-css-mu",
     "status": "inactive",
     "active": false,
     "installed": "2.8",
     "available": "2.10",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.8 -> 2.10"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "advanced-post-queries",
     "status": "inactive",
     "active": false,
     "installed": "1.1.0",
     "available": "1.1.4",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.1.0 -> 1.1.4"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "akismet",
     "status": "inactive",
     "active": false,
     "installed": "5.0.1",
     "available": "5.7.2",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.0.1 -> 5.7.2 (skipped 7 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "bulk-delete",
     "status": "inactive",
     "active": false,
     "installed": "6.0.2",
     "available": "6.12",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 6.0.2 -> 6.12 (skipped 12 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "cookie-law-info",
     "status": "inactive",
     "active": false,
     "installed": "3.0.8",
     "available": "3.5.6",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.0.8 -> 3.5.6 (skipped 5 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "headers-security-advanced-hsts-wp",
     "status": "inactive",
     "active": false,
     "installed": "5.0.21",
     "available": "5.3.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.0.21 -> 5.3.5 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "regenerate-thumbnails",
     "status": "inactive",
     "active": false,
     "installed": "3.1.5",
     "available": "3.1.6",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 3.1.5 -> 3.1.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wp-widget-disable",
     "status": "inactive",
     "active": false,
     "installed": "3.0.0",
     "available": "3.0.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 3.0.0 -> 3.0.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wp-smartcrop",
     "status": "inactive",
     "active": false,
     "installed": "2.0.6",
     "available": "2.0.10",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 2.0.6 -> 2.0.10"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    }
   ],
   "p0": 8,
   "p1": 18,
   "total_updates": 52
  },
  "wpengine:kovdoidev": {
   "platform": "wpengine",
   "install": "kovdoidev",
   "environment": "development",
   "domain": "kovdoidev.wpengine.com",
   "siteurl": "https://kovdoidev.wpengine.com",
   "core": "7.0.3",
   "core_update": "7.0.4",
   "theme": "genesis-block-theme",
   "updates": [
    {
     "plugin": "genesis-blocks",
     "status": "active",
     "active": true,
     "installed": "2.0.0",
     "available": "3.1.11",
     "priority": "P2",
     "vulns": [
      {
       "name": "Genesis Blocks [genesis-blocks] < 3.1.3",
       "cvss": "6.8",
       "severity": "MEDIUM",
       "cve": "CVE-2024-2761"
      },
      {
       "name": "Genesis Blocks [genesis-blocks] < 3.1.4",
       "cvss": "6.8",
       "severity": "MEDIUM",
       "cve": "CVE-2024-3901"
      },
      {
       "name": "Genesis Blocks [genesis-blocks] < 3.1.3",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-1946"
      },
      {
       "name": "Genesis Blocks [genesis-blocks] < 3.1.4",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-3563"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.0.0 -> 3.1.11 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "akismet",
     "status": "inactive",
     "active": false,
     "installed": "5.1",
     "available": "5.7.2",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.1 -> 5.7.2 (skipped 6 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    }
   ],
   "p0": 0,
   "p1": 0,
   "total_updates": 2
  },
  "wpengine:epochdev1": {
   "platform": "wpengine",
   "install": "epochdev1",
   "environment": "production",
   "domain": "epochdev1.wpenginepowered.com",
   "siteurl": "https://epochdev1.wpenginepowered.com",
   "core": "7.0.3",
   "core_update": "7.0.4",
   "theme": "acwebdev",
   "updates": [
    {
     "plugin": "advanced-custom-fields-pro",
     "status": "active",
     "active": true,
     "installed": "6.2.5",
     "available": "6.8.10",
     "priority": "P0",
     "vulns": [
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.2.10",
       "cvss": "9.9",
       "severity": "CRITICAL",
       "cve": "CVE-2024-34762"
      },
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.2.10",
       "cvss": "8.5",
       "severity": "HIGH",
       "cve": "CVE-2024-34761"
      },
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.3.8",
       "cvss": "6.6",
       "severity": "MEDIUM",
       "cve": "CVE-2024-9529"
      },
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.3.0",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-4565"
      }
     ],
     "vuln_count": 10,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "multi-minor jump 6.2.5 -> 6.8.10 (skipped 6 minor releases)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "insert-headers-and-footers",
     "status": "active",
     "active": true,
     "installed": "2.1.8",
     "available": "2.3.9",
     "priority": "P1",
     "vulns": [
      {
       "name": "WPCode &#8211; Insert Headers and Footers + Custom Code Snippets &#8211; WordPress Code Manager [insert-headers-and-footers] < 2.3.6",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-8832"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.1.8 -> 2.3.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "genesis-blocks",
     "status": "active",
     "active": true,
     "installed": "3.1.1",
     "available": "3.1.11",
     "priority": "P2",
     "vulns": [
      {
       "name": "Genesis Blocks [genesis-blocks] < 3.1.3",
       "cvss": "6.8",
       "severity": "MEDIUM",
       "cve": "CVE-2024-2761"
      },
      {
       "name": "Genesis Blocks [genesis-blocks] < 3.1.4",
       "cvss": "6.8",
       "severity": "MEDIUM",
       "cve": "CVE-2024-3901"
      },
      {
       "name": "Genesis Blocks [genesis-blocks] < 3.1.3",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-1946"
      },
      {
       "name": "Genesis Blocks [genesis-blocks] < 3.1.4",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-3563"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 3.1.1 -> 3.1.11"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "limit-login-attempts-reloaded",
     "status": "active",
     "active": true,
     "installed": "3.3.4",
     "available": "3.3.8",
     "priority": "P2",
     "vulns": [
      {
       "name": "Limit Login Attempts Security &#8211; Login Security, 2FA, Firewall, Brute Force Prevention [limit-login-attempts-reloaded] < 3.3.5",
       "cvss": "3.7",
       "severity": "LOW",
       "cve": "CVE-2026-18356"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 3.3.4 -> 3.3.8"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "megamenu",
     "status": "active",
     "active": true,
     "installed": "3.3",
     "available": "3.10.8",
     "priority": "P2",
     "vulns": [
      {
       "name": "Max Mega Menu [megamenu] < 3.3.1",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-28003"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.3 -> 3.10.8 (skipped 7 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "classic-editor",
     "status": "active",
     "active": true,
     "installed": "1.6.3",
     "available": "1.7.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.6.3 -> 1.7.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "cookie-law-info",
     "status": "active",
     "active": true,
     "installed": "3.1.8",
     "available": "3.5.6",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.1.8 -> 3.5.6 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "disable-css-js-cache",
     "status": "active",
     "active": true,
     "installed": "1.0.3",
     "available": "1.2.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.0.3 -> 1.2.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "headers-security-advanced-hsts-wp",
     "status": "active",
     "active": true,
     "installed": "5.0.30",
     "available": "5.3.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.0.30 -> 5.3.5 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wpe-site-migration",
     "status": "active",
     "active": true,
     "installed": "1.0.0-beta.24",
     "available": "1.8.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 1.0.0-beta.24 -> 1.8.5 (skipped 8 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    }
   ],
   "p0": 1,
   "p1": 1,
   "total_updates": 10
  },
  "wpengine:ascentialprd": {
   "platform": "wpengine",
   "install": "ascentialprd",
   "environment": "production",
   "domain": "ascentialprd.wpenginepowered.com",
   "siteurl": "https://ascentialprd.wpenginepowered.com",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "hello-ascential",
   "updates": [
    {
     "plugin": "elementor-pro",
     "status": "active",
     "active": true,
     "installed": "3.27.1",
     "available": "4.0.3",
     "priority": "P0",
     "vulns": [
      {
       "name": "Elementor Pro [elementor-pro] < 4.2.2",
       "cvss": "9.0",
       "severity": "CRITICAL",
       "cve": "CVE-2026-32475"
      },
      {
       "name": "Elementor Pro [elementor-pro] < 3.29.1",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-50555"
      },
      {
       "name": "Elementor Pro [elementor-pro] < 3.29.1",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-3076"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.27.1 -> 4.0.3 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "woocommerce",
     "status": "inactive",
     "active": false,
     "installed": "9.6.0",
     "available": "11.1.0",
     "priority": "P0",
     "vulns": [
      {
       "name": "WooCommerce [woocommerce] == 7.1.0 (unfixed)",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2022-50972"
      },
      {
       "name": "WooCommerce [woocommerce] < 11.0",
       "cvss": "7.6",
       "severity": "HIGH",
       "cve": "CVE-2026-57777"
      },
      {
       "name": "WooCommerce [woocommerce] < 11.1.0",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-48888"
      },
      {
       "name": "WooCommerce [woocommerce] < 10.4.3",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-15033"
      }
     ],
     "vuln_count": 7,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 9.6.0 -> 11.1.0 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "hide-my-wp",
     "status": "inactive",
     "active": false,
     "installed": "5.4.01",
     "available": "7.0.11",
     "priority": "P0",
     "vulns": [
      {
       "name": "Hide My WP Ghost &#8211; Security &amp; Firewall [hide-my-wp] < 5.4.02",
       "cvss": "9.6",
       "severity": "CRITICAL",
       "cve": "CVE-2025-26909"
      },
      {
       "name": "Hide My WP Ghost &#8211; Security &amp; Firewall [hide-my-wp] < 5.4.02",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2025-2056"
      },
      {
       "name": "Hide My WP Ghost &#8211; Security &amp; Firewall [hide-my-wp] < 7.0.10",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-81806"
      },
      {
       "name": "Hide My WP Ghost &#8211; Security &amp; Firewall [hide-my-wp] <= 6.2.12 (unfixed)",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2025-69098"
      }
     ],
     "vuln_count": 7,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 5.4.01 -> 7.0.11 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "mainwp-child",
     "status": "active",
     "active": true,
     "installed": "5.3.5",
     "available": "6.2",
     "priority": "P1",
     "vulns": [
      {
       "name": "MainWP Child &#8211; Securely Connects to the MainWP Dashboard to Manage Multiple Sites [mainwp-child] < 6.1.2",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-27366"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 5.3.5 -> 6.2 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "shortpixel-image-optimiser",
     "status": "active",
     "active": true,
     "installed": "6.1.1",
     "available": "6.5.6",
     "priority": "P1",
     "vulns": [
      {
       "name": "ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 6.4.4",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-39471"
      },
      {
       "name": "ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 6.3.5",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-11378"
      },
      {
       "name": "ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 6.4.4",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-4335"
      },
      {
       "name": "ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 6.4.3",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-1246"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 6.1.1 -> 6.5.6 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "revslider",
     "status": "active",
     "active": true,
     "installed": "6.7.18",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "Slider Revolution [revslider] < 7.0.11",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-6692"
      },
      {
       "name": "Slider Revolution [revslider] < 7.1.0",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-57678"
      },
      {
       "name": "Slider Revolution [revslider] < 6.7.37",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-9217"
      },
      {
       "name": "Slider Revolution [revslider] < 6.7.38",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-10249"
      }
     ],
     "vuln_count": 9,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "insert-headers-and-footers",
     "status": "active",
     "active": true,
     "installed": "2.2.5",
     "available": "2.3.9",
     "priority": "P1",
     "vulns": [
      {
       "name": "WPCode &#8211; Insert Headers and Footers + Custom Code Snippets &#8211; WordPress Code Manager [insert-headers-and-footers] < 2.3.6",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-8832"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.2.5 -> 2.3.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "all-in-one-wp-security-and-firewall",
     "status": "inactive",
     "active": false,
     "installed": "5.4.2",
     "available": "5.4.9",
     "priority": "P1",
     "vulns": [
      {
       "name": "All-In-One Security (AIOS) \u2013 Security and Firewall [all-in-one-wp-security-and-firewall] < 5.4.8",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-8438"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 5.4.2 -> 5.4.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "debug-log-manager",
     "status": "inactive",
     "active": false,
     "installed": "2.3.3",
     "available": "2.5.2",
     "priority": "P1",
     "vulns": [
      {
       "name": "Debug Log Manager &#8211; Conveniently Monitor and Inspect Errors [debug-log-manager] < 2.3.5",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2025-3809"
      },
      {
       "name": "Debug Log Manager &#8211; Conveniently Monitor and Inspect Errors [debug-log-manager] < 2.5.1",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-9016"
      },
      {
       "name": "Debug Log Manager &#8211; Conveniently Monitor and Inspect Errors [debug-log-manager] < 2.3.5",
       "cvss": "0.0",
       "severity": null,
       "cve": "CVE-2025-32613"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.3.3 -> 2.5.2"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "jet-menu",
     "status": "inactive",
     "active": false,
     "installed": "2.4.8",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "JetMenu [jet-menu] < 2.4.9.1",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2025-26953"
      },
      {
       "name": "JetMenu [jet-menu] < 2.4.11.2",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-53987"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "link-whisper",
     "status": "inactive",
     "active": false,
     "installed": "0.7.9",
     "available": "0.9.7",
     "priority": "P1",
     "vulns": [
      {
       "name": "Link Whisper Free [link-whisper] < 0.9.1",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2025-11262"
      },
      {
       "name": "Link Whisper Free [link-whisper] < 0.8.9",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2025-67927"
      },
      {
       "name": "Link Whisper Free [link-whisper] < 0.9.3",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-22357"
      },
      {
       "name": "Link Whisper Free [link-whisper] < 0.9.5",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-57333"
      }
     ],
     "vuln_count": 8,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 0.7.9 -> 0.9.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "updraftplus",
     "status": "inactive",
     "active": false,
     "installed": "1.25.1",
     "available": "1.26.7",
     "priority": "P1",
     "vulns": [
      {
       "name": "UpdraftPlus: WP Backup &amp; Migration Plugin [updraftplus] < 1.26.5",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2026-10795"
      },
      {
       "name": "UpdraftPlus: WP Backup &amp; Migration Plugin [updraftplus] < 1.26.7",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-76549"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "minor version bump 1.25.1 -> 1.26.7",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wp-optimize",
     "status": "inactive",
     "active": false,
     "installed": "3.8.0",
     "available": "4.6.1",
     "priority": "P1",
     "vulns": [
      {
       "name": "WP-Optimize \u2013 Cache, Compress images, Minify &amp; Clean database to boost page speed &amp; performance [wp-optimize] < 4.5.3",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2026-7252"
      },
      {
       "name": "WP-Optimize \u2013 Cache, Compress images, Minify &amp; Clean database to boost page speed &amp; performance [wp-optimize] < 4.2.0",
       "cvss": "4.1",
       "severity": "MEDIUM",
       "cve": "CVE-2025-3951"
      },
      {
       "name": "WP-Optimize \u2013 Cache, Compress images, Minify &amp; Clean database to boost page speed &amp; performance [wp-optimize] < 4.5.1",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-2712"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.8.0 -> 4.6.1 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wpide",
     "status": "inactive",
     "active": false,
     "installed": "3.5.0",
     "available": "3.5.9",
     "priority": "P1",
     "vulns": [
      {
       "name": "WPIDE &#8211; File Manager &amp; Code Editor [wpide] < 3.5.7",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-57766"
      },
      {
       "name": "WPIDE &#8211; File Manager &amp; Code Editor [wpide] < 3.5.8",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-66440"
      },
      {
       "name": "WPIDE &#8211; File Manager &amp; Code Editor [wpide] < 3.5.2",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2024-13362"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 3.5.0 -> 3.5.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "elementor",
     "status": "active",
     "active": true,
     "installed": "3.27.2",
     "available": "4.2.4",
     "priority": "P2",
     "vulns": [
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.29.1",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-50555"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.35.6",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-32352"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 4.1.4",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-57619"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.27.5",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-13445"
      }
     ],
     "vuln_count": 15,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.27.2 -> 4.2.4 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "limit-login-attempts-reloaded",
     "status": "active",
     "active": true,
     "installed": "2.26.18",
     "available": "3.3.8",
     "priority": "P2",
     "vulns": [
      {
       "name": "Limit Login Attempts Security &#8211; Login Security, 2FA, Firewall, Brute Force Prevention [limit-login-attempts-reloaded] < 3.3.5",
       "cvss": "3.7",
       "severity": "LOW",
       "cve": "CVE-2026-18356"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.26.18 -> 3.3.8 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "search-filter-pro",
     "status": "active",
     "active": true,
     "installed": "2.5.19",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Search & Filter Pro [search-filter-pro] < 2.5.20",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-1528"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "simple-banner",
     "status": "active",
     "active": true,
     "installed": "3.0.6",
     "available": "3.3.2",
     "priority": "P2",
     "vulns": [
      {
       "name": "Simple Banner &#8211; Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website [simple-banner] < 3.1.0",
       "cvss": "4.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-12033"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.0.6 -> 3.3.2 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "simple-download-monitor",
     "status": "active",
     "active": true,
     "installed": "3.9.26",
     "available": "4.1.1",
     "priority": "P2",
     "vulns": [
      {
       "name": "Simple Download Monitor [simple-download-monitor] < 3.9.35",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-58197"
      },
      {
       "name": "Simple Download Monitor [simple-download-monitor] < 3.9.34",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-8977"
      },
      {
       "name": "Simple Download Monitor [simple-download-monitor] < 4.0.6",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-2383"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.9.26 -> 4.1.1 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "smtp2go",
     "status": "active",
     "active": true,
     "installed": "1.11.1",
     "available": "1.17.1",
     "priority": "P2",
     "vulns": [
      {
       "name": "SMTP2GO for WordPress &#8211; Email Made Easy [smtp2go] < 1.12.2",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-54011"
      },
      {
       "name": "SMTP2GO for WordPress &#8211; Email Made Easy [smtp2go] < 1.17.0",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-7621"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 1.11.1 -> 1.17.1 (skipped 6 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "stop-user-enumeration",
     "status": "active",
     "active": true,
     "installed": "1.6.3",
     "available": "1.7.8",
     "priority": "P2",
     "vulns": [
      {
       "name": "Stop User Enumeration [stop-user-enumeration] < 1.7.3",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-4302"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.6.3 -> 1.7.8"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "svg-support",
     "status": "active",
     "active": true,
     "installed": "2.5.8",
     "available": "2.6.1",
     "priority": "P2",
     "vulns": [
      {
       "name": "SVG Support [svg-support] < 2.5.11",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-10222"
      },
      {
       "name": "SVG Support [svg-support] < 2.5.9",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2022-23638"
      },
      {
       "name": "SVG Support [svg-support] < 2.5.15",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-48973"
      },
      {
       "name": "SVG Support [svg-support] < 2.5.17",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-13340"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.5.8 -> 2.6.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "duplicate-post",
     "status": "active",
     "active": true,
     "installed": "4.5",
     "available": "4.7",
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast Duplicate Post [duplicate-post] <= 4.6 (unfixed)",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-53740"
      },
      {
       "name": "Yoast Duplicate Post [duplicate-post] <= 4.6 (unfixed)",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-53739"
      },
      {
       "name": "Yoast Duplicate Post [duplicate-post] < 4.6",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-1217"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 4.5 -> 4.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "wordpress-seo",
     "status": "active",
     "active": true,
     "installed": "24.3",
     "available": "28.5",
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 26.6",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-14481"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 27.2",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-3427"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 26.9",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-1293"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 28.1",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-15425"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 24.3 -> 28.5 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "wordpress-seo-premium",
     "status": "active",
     "active": true,
     "installed": "24.3",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast SEO Premium [wordpress-seo-premium] < 27.6.1",
       "cvss": "6.6",
       "severity": "MEDIUM",
       "cve": "CVE-2026-10821"
      },
      {
       "name": "Yoast SEO Premium [wordpress-seo-premium] < 26.7",
       "cvss": "5.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-40722"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "wp-discussion-board",
     "status": "inactive",
     "active": false,
     "installed": "2.5.5",
     "available": "2.6.0",
     "priority": "P2",
     "vulns": [
      {
       "name": "Discussion Board &#8211; WordPress Forum Plugin [wp-discussion-board] < 2.5.6",
       "cvss": "6.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-8483"
      },
      {
       "name": "Discussion Board &#8211; WordPress Forum Plugin [wp-discussion-board] < 2.5.8",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-69023"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.5.5 -> 2.6.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "dracula-dark-mode",
     "status": "inactive",
     "active": false,
     "installed": "1.2.7",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Dracula Dark Mode \u2013  Accessibility, Reading Mode &amp; Dark Mode for WordPress [dracula-dark-mode] < 1.2.8 (closed)",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2024-13362"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "goal-tracker-ga",
     "status": "inactive",
     "active": false,
     "installed": "1.1.5",
     "available": "1.1.6",
     "priority": "P2",
     "vulns": [
      {
       "name": "Goal Tracker &#8211; Custom Event Tracking for GA4 [goal-tracker-ga] < 1.1.6",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2024-13362"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.1.5 -> 1.1.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "nitropack",
     "status": "inactive",
     "active": false,
     "installed": "1.17.6",
     "available": "1.20.0",
     "priority": "P2",
     "vulns": [
      {
       "name": "NitroPack \u2013 Performance, Page Speed &amp; Cache Plugin for Core Web Vitals, CDN &amp; Image Optimization [nitropack] < 1.19.4",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-39669"
      },
      {
       "name": "NitroPack \u2013 Performance, Page Speed &amp; Cache Plugin for Core Web Vitals, CDN &amp; Image Optimization [nitropack] < 1.18.5",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2025-8778"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 1.17.6 -> 1.20.0 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "query-monitor",
     "status": "inactive",
     "active": false,
     "installed": "3.17.0",
     "available": "4.0.7",
     "priority": "P2",
     "vulns": [
      {
       "name": "Query Monitor [query-monitor] < 3.20.4",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-4267"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.17.0 -> 4.0.7 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "sucuri-scanner",
     "status": "inactive",
     "active": false,
     "installed": "1.9.8",
     "available": "2.8",
     "priority": "P2",
     "vulns": [
      {
       "name": "Sucuri Security &#8211; Auditing, Malware Scanner and Security Hardening [sucuri-scanner] <= 2.7.3 (unfixed)",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-73033"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 1.9.8 -> 2.8 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "agile-store-locator",
     "status": "active",
     "active": true,
     "installed": "4.10.13",
     "available": "5.4.6",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 4.10.13 -> 5.4.6 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "font-awesome",
     "status": "active",
     "active": true,
     "installed": "4.5.0",
     "available": "5.2.1",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 4.5.0 -> 5.2.1 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "weglot",
     "status": "active",
     "active": true,
     "installed": "5.2",
     "available": "6.2",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 5.2 -> 6.2 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "wpai-acf-add-on",
     "status": "active",
     "active": true,
     "installed": "3.3.9",
     "available": "4.0.2",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.3.9 -> 4.0.2 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "online-active-users",
     "status": "inactive",
     "active": false,
     "installed": "2.5",
     "available": "3.4.4",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.5 -> 3.4.4 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "prevent-browser-caching",
     "status": "inactive",
     "active": false,
     "installed": "2.3.5",
     "available": "3.2.1",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.3.5 -> 3.2.1 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "eps-301-redirects",
     "status": "active",
     "active": true,
     "installed": "2.83",
     "available": "2.85",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.83 -> 2.85"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "advanced-custom-fields-pro",
     "status": "active",
     "active": true,
     "installed": "6.3.12",
     "available": "6.8.10",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "multi-minor jump 6.3.12 -> 6.8.10 (skipped 5 minor releases)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE WITH CAPTURE \u2014 routine bump but on a sitewide-impact plugin; watch the diff closely."
    },
    {
     "plugin": "cookie-law-info",
     "status": "active",
     "active": true,
     "installed": "3.2.8",
     "available": "3.5.6",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.2.8 -> 3.5.6 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "dynamic-content-for-elementor",
     "status": "active",
     "active": true,
     "installed": "3.2.3",
     "available": "3.4.13",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "minor version bump 3.2.3 -> 3.4.13",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE WITH CAPTURE \u2014 routine bump but on a sitewide-impact plugin; watch the diff closely."
    },
    {
     "plugin": "headers-security-advanced-hsts-wp",
     "status": "active",
     "active": true,
     "installed": "5.0.44",
     "available": "5.3.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.0.44 -> 5.3.5 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "megamenu",
     "status": "active",
     "active": true,
     "installed": "3.4.1",
     "available": "3.10.8",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.4.1 -> 3.10.8 (skipped 6 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "page-links-to",
     "status": "active",
     "active": true,
     "installed": "3.3.7",
     "available": "3.4.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 3.3.7 -> 3.4.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "post-types-order",
     "status": "active",
     "active": true,
     "installed": "2.3.3",
     "available": "2.5.3",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.3.3 -> 2.5.3"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "view-transitions",
     "status": "active",
     "active": true,
     "installed": "1.1.1",
     "available": "1.2.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.1.1 -> 1.2.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wp-revisions-control",
     "status": "active",
     "active": true,
     "installed": "1.4.3",
     "available": "1.4.4",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.4.3 -> 1.4.4"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wp-search-with-algolia",
     "status": "active",
     "active": true,
     "installed": "2.8.2",
     "available": "2.14.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 2.8.2 -> 2.14.1 (skipped 6 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wps-hide-login",
     "status": "active",
     "active": true,
     "installed": "1.9.17.1",
     "available": "1.9.19",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.9.17.1 -> 1.9.19"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "admin-taxonomy-filter",
     "status": "inactive",
     "active": false,
     "installed": "1.0.4",
     "available": "1.0.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.0.4 -> 1.0.5"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "cachebuster",
     "status": "inactive",
     "active": false,
     "installed": "1.8",
     "available": "1.10",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.8 -> 1.10"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "duplicate-page",
     "status": "inactive",
     "active": false,
     "installed": "4.5.4",
     "available": "4.5.9",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 4.5.4 -> 4.5.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "search-regex",
     "status": "inactive",
     "active": false,
     "installed": "3.1.2",
     "available": "3.4.4",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.1.2 -> 3.4.4 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wp-hide-security-enhancer",
     "status": "inactive",
     "active": false,
     "installed": "2.6",
     "available": "2.9.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 2.6 -> 2.9.1 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wp-mail-smtp",
     "status": "inactive",
     "active": false,
     "installed": "4.3.0",
     "available": "4.9.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 4.3.0 -> 4.9.0 (skipped 6 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    }
   ],
   "p0": 3,
   "p1": 11,
   "total_updates": 50
  },
  "wpengine:norwestvpdev": {
   "platform": "wpengine",
   "install": "norwestvpdev",
   "environment": "development",
   "domain": "norwestvpdev.wpenginepowered.com",
   "siteurl": "https://norwestvpdev.wpenginepowered.com",
   "core": "7.0.4",
   "core_update": null,
   "theme": "brand-nav-child-theme",
   "updates": [
    {
     "plugin": "elementor-pro",
     "status": "active",
     "active": true,
     "installed": "3.23.3",
     "available": null,
     "priority": "P0",
     "vulns": [
      {
       "name": "Elementor Pro [elementor-pro] < 4.2.2",
       "cvss": "9.0",
       "severity": "CRITICAL",
       "cve": "CVE-2026-32475"
      },
      {
       "name": "Elementor Pro [elementor-pro] < 3.25.11",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-8494"
      },
      {
       "name": "Elementor Pro [elementor-pro] < 3.29.1",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-50555"
      },
      {
       "name": "Elementor Pro [elementor-pro] < 3.29.1",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-3076"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "revisionary",
     "status": "active",
     "active": true,
     "installed": "3.6.2",
     "available": null,
     "priority": "P0",
     "vulns": [
      {
       "name": "PublishPress Revisions: Duplicate Posts, Submit, Approve and Schedule Content Changes [revisionary] < 3.7.24",
       "cvss": "9.3",
       "severity": "CRITICAL",
       "cve": "CVE-2026-32539"
      },
      {
       "name": "PublishPress Revisions: Duplicate Posts, Submit, Approve and Schedule Content Changes [revisionary] < 3.7.23",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-25322"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "ewww-image-optimizer",
     "status": "active",
     "active": true,
     "installed": "8.1.3",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "EWWW Image Optimizer [ewww-image-optimizer] < 8.7.7",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-84773"
      },
      {
       "name": "EWWW Image Optimizer [ewww-image-optimizer] < 8.7.4",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-15446"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "link-whisper",
     "status": "active",
     "active": true,
     "installed": "0.8.0",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "Link Whisper Free [link-whisper] < 0.9.1",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2025-11262"
      },
      {
       "name": "Link Whisper Free [link-whisper] < 0.8.9",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2025-67927"
      },
      {
       "name": "Link Whisper Free [link-whisper] < 0.9.3",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-22357"
      },
      {
       "name": "Link Whisper Free [link-whisper] < 0.9.5",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-57333"
      }
     ],
     "vuln_count": 8,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "mainwp-child",
     "status": "active",
     "active": true,
     "installed": "5.4.0.4",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "MainWP Child &#8211; Securely Connects to the MainWP Dashboard to Manage Multiple Sites [mainwp-child] < 6.1.2",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-27366"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "one-user-avatar",
     "status": "active",
     "active": true,
     "installed": "2.5.0",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "One User Avatar | User Profile Picture [one-user-avatar] < 2.5.5",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-18983"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "revslider",
     "status": "active",
     "active": true,
     "installed": "6.7.18",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "Slider Revolution [revslider] < 7.0.11",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-6692"
      },
      {
       "name": "Slider Revolution [revslider] < 7.1.0",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-57678"
      },
      {
       "name": "Slider Revolution [revslider] < 6.7.37",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-9217"
      },
      {
       "name": "Slider Revolution [revslider] < 6.7.38",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-10249"
      }
     ],
     "vuln_count": 9,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "wp-optimize",
     "status": "active",
     "active": true,
     "installed": "4.1.1",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "WP-Optimize \u2013 Cache, Compress images, Minify &amp; Clean database to boost page speed &amp; performance [wp-optimize] < 4.5.3",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2026-7252"
      },
      {
       "name": "WP-Optimize \u2013 Cache, Compress images, Minify &amp; Clean database to boost page speed &amp; performance [wp-optimize] < 4.2.0",
       "cvss": "4.1",
       "severity": "MEDIUM",
       "cve": "CVE-2025-3951"
      },
      {
       "name": "WP-Optimize \u2013 Cache, Compress images, Minify &amp; Clean database to boost page speed &amp; performance [wp-optimize] < 4.5.1",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-2712"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "insert-headers-and-footers",
     "status": "active",
     "active": true,
     "installed": "2.2.7",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "WPCode &#8211; Insert Headers and Footers + Custom Code Snippets &#8211; WordPress Code Manager [insert-headers-and-footers] < 2.3.6",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-8832"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "wpvivid-backuprestore",
     "status": "active",
     "active": true,
     "installed": "0.9.114",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "WPvivid \u2014 Backup, Migration &amp; Staging [wpvivid-backuprestore] < 0.9.117",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2025-5961"
      },
      {
       "name": "WPvivid \u2014 Backup, Migration &amp; Staging [wpvivid-backuprestore] < 0.9.132",
       "cvss": "4.9",
       "severity": "MEDIUM",
       "cve": "CVE-2026-17555"
      },
      {
       "name": "WPvivid \u2014 Backup, Migration &amp; Staging [wpvivid-backuprestore] < 0.9.129",
       "cvss": "3.8",
       "severity": "LOW",
       "cve": "CVE-2025-12656"
      },
      {
       "name": "WPvivid \u2014 Backup, Migration &amp; Staging [wpvivid-backuprestore] < 0.9.121",
       "cvss": "2.7",
       "severity": "LOW",
       "cve": "CVE-2025-12654"
      }
     ],
     "vuln_count": 10,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "codepress-admin-columns",
     "status": "inactive",
     "active": false,
     "installed": "4.7.7",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "Admin Columns [codepress-admin-columns] < 7.0.19",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-7654"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "perfmatters",
     "status": "inactive",
     "active": false,
     "installed": "2.4.0",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "Perfmatters [perfmatters] < 2.6.5",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-13251"
      },
      {
       "name": "Perfmatters [perfmatters] < 2.6.4",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-56047"
      },
      {
       "name": "Perfmatters [perfmatters] < 2.6.5",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-57671"
      },
      {
       "name": "Perfmatters [perfmatters] < 2.6.0",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-4350"
      }
     ],
     "vuln_count": 5,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "updraftplus",
     "status": "inactive",
     "active": false,
     "installed": "1.25.3",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "UpdraftPlus: WP Backup &amp; Migration Plugin [updraftplus] < 1.26.5",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2026-10795"
      },
      {
       "name": "UpdraftPlus: WP Backup &amp; Migration Plugin [updraftplus] < 1.26.7",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-76549"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "admin-site-enhancements",
     "status": "active",
     "active": true,
     "installed": "7.9.9",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Admin and Site Enhancements (ASE) [admin-site-enhancements] < 8.4.1",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-32423"
      },
      {
       "name": "Admin and Site Enhancements (ASE) [admin-site-enhancements] < 8.1.0",
       "cvss": "2.7",
       "severity": "LOW",
       "cve": "CVE-2025-64255"
      },
      {
       "name": "Admin and Site Enhancements (ASE) [admin-site-enhancements] < 8.8.4",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-12083"
      },
      {
       "name": "Admin and Site Enhancements (ASE) [admin-site-enhancements] < 9.0.1",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-19615"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "am-lottieplayer",
     "status": "active",
     "active": true,
     "installed": "3.5.2",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "AM LottiePlayer [am-lottieplayer] < 3.5.4",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-1529"
      },
      {
       "name": "AM LottiePlayer [am-lottieplayer] <= 3.6.0 (unfixed)",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2025-1794"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "elementor",
     "status": "active",
     "active": true,
     "installed": "3.23.4",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.25.11",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-54444"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.29.1",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-50555"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.35.6",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-32352"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 4.1.4",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-57619"
      }
     ],
     "vuln_count": 20,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "search-filter-pro",
     "status": "active",
     "active": true,
     "installed": "2.5.14",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Search & Filter Pro [search-filter-pro] < 2.5.18",
       "cvss": "4.8",
       "severity": "MEDIUM",
       "cve": "CVE-2024-6481"
      },
      {
       "name": "Search & Filter Pro [search-filter-pro] < 2.5.20",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-1528"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "search-exclude",
     "status": "active",
     "active": true,
     "installed": "2.4.7",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Search Exclude [search-exclude] < 2.5.0",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-2821"
      },
      {
       "name": "Search Exclude [search-exclude] < 2.5.8",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-10646"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "simple-banner",
     "status": "active",
     "active": true,
     "installed": "3.0.6",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Simple Banner &#8211; Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website [simple-banner] < 3.1.0",
       "cvss": "4.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-12033"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "sticky-header-effects-for-elementor",
     "status": "active",
     "active": true,
     "installed": "1.7.8",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Sticky Header Effects for Elementor [sticky-header-effects-for-elementor] < 2.1.3",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-58251"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "svg-support",
     "status": "active",
     "active": true,
     "installed": "2.5.14",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "SVG Support [svg-support] < 2.5.15",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-48973"
      },
      {
       "name": "SVG Support [svg-support] < 2.5.17",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-13340"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "duplicate-post",
     "status": "active",
     "active": true,
     "installed": "4.5",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast Duplicate Post [duplicate-post] <= 4.6 (unfixed)",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-53740"
      },
      {
       "name": "Yoast Duplicate Post [duplicate-post] <= 4.6 (unfixed)",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-53739"
      },
      {
       "name": "Yoast Duplicate Post [duplicate-post] < 4.6",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-1217"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "wordpress-seo",
     "status": "active",
     "active": true,
     "installed": "24.8.1",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 26.6",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-14481"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 27.2",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-3427"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 26.9",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-1293"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 28.1",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-15425"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "wordpress-seo-premium",
     "status": "active",
     "active": true,
     "installed": "24.8",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast SEO Premium [wordpress-seo-premium] < 27.6.1",
       "cvss": "6.6",
       "severity": "MEDIUM",
       "cve": "CVE-2026-10821"
      },
      {
       "name": "Yoast SEO Premium [wordpress-seo-premium] < 26.7",
       "cvss": "5.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-40722"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    }
   ],
   "p0": 2,
   "p1": 11,
   "total_updates": 0
  },
  "wpengine:titanstg1": {
   "platform": "wpengine",
   "install": "titanstg1",
   "environment": "staging",
   "domain": "titanstg1.wpenginepowered.com",
   "siteurl": "https://titanstg1.wpenginepowered.com",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "theme",
   "updates": [
    {
     "plugin": "translatepress-multilingual",
     "status": "active",
     "active": true,
     "installed": "2.9.6",
     "available": "3.3.6",
     "priority": "P0",
     "vulns": [
      {
       "name": "TranslatePress &#8211; Translate Multilingual sites with AI Translation [translatepress-multilingual] < 3.3.3",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2026-78267"
      },
      {
       "name": "TranslatePress &#8211; Translate Multilingual sites with AI Translation [translatepress-multilingual] < 3.3.2",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2026-19632"
      },
      {
       "name": "TranslatePress &#8211; Translate Multilingual sites with AI Translation [translatepress-multilingual] < 2.10.3",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2025-58592"
      },
      {
       "name": "TranslatePress &#8211; Translate Multilingual sites with AI Translation [translatepress-multilingual] < 3.3",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-18510"
      }
     ],
     "vuln_count": 10,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.9.6 -> 3.3.6 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "gravityforms",
     "status": "active",
     "active": true,
     "installed": "2.10.5",
     "available": "3.1.1",
     "priority": "P1",
     "vulns": [
      {
       "name": "Gravity Forms [gravityforms] < 3.0.3",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2026-19513"
      },
      {
       "name": "Gravity Forms [gravityforms] < 3.0.0",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-16649"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.10.5 -> 3.1.1 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "mainwp-child",
     "status": "active",
     "active": true,
     "installed": "5.4.0.2",
     "available": "6.2",
     "priority": "P1",
     "vulns": [
      {
       "name": "MainWP Child &#8211; Securely Connects to the MainWP Dashboard to Manage Multiple Sites [mainwp-child] < 6.1.2",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-27366"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 5.4.0.2 -> 6.2 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "popup-maker",
     "status": "active",
     "active": true,
     "installed": "1.20.4",
     "available": "1.25.0",
     "priority": "P1",
     "vulns": [
      {
       "name": "Popup Maker &#8211; Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.23.0",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-8848"
      },
      {
       "name": "Popup Maker &#8211; Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.24.0",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-28177"
      },
      {
       "name": "Popup Maker &#8211; Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.20.5",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-4205"
      },
      {
       "name": "Popup Maker &#8211; Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.21.0",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-9490"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 1.20.4 -> 1.25.0 (skipped 5 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "wp-smushit",
     "status": "active",
     "active": true,
     "installed": "3.17.1",
     "available": "4.3.3",
     "priority": "P1",
     "vulns": [
      {
       "name": "Smush \u2013 Image Optimization, Compression, Lazy Load, WebP &amp; CDN [wp-smushit] < 4.3.0",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-81285"
      },
      {
       "name": "Smush \u2013 Image Optimization, Compression, Lazy Load, WebP &amp; CDN [wp-smushit] < 4.3.2",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-19223"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.17.1 -> 4.3.3 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "wordpress-importer",
     "status": "active",
     "active": true,
     "installed": "0.8.3",
     "available": "0.9.6",
     "priority": "P1",
     "vulns": [
      {
       "name": "WordPress Importer [wordpress-importer] < 0.8.4",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2024-13889"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 0.8.3 -> 0.9.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "insert-headers-and-footers",
     "status": "active",
     "active": true,
     "installed": "2.2.6",
     "available": "2.3.9",
     "priority": "P1",
     "vulns": [
      {
       "name": "WPCode &#8211; Insert Headers and Footers + Custom Code Snippets &#8211; WordPress Code Manager [insert-headers-and-footers] < 2.3.6",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-8832"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.2.6 -> 2.3.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "acf-to-rest-api",
     "status": "active",
     "active": true,
     "installed": "3.3.4",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "ACF to REST API [acf-to-rest-api] <= 3.3.4 (unfixed + closed)",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-62979"
      },
      {
       "name": "ACF to REST API [acf-to-rest-api] <= 3.3.4 (unfixed + closed)",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-12030"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "simple-banner",
     "status": "active",
     "active": true,
     "installed": "3.0.4",
     "available": "3.3.2",
     "priority": "P2",
     "vulns": [
      {
       "name": "Simple Banner &#8211; Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website [simple-banner] < 3.0.5",
       "cvss": "4.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-13898"
      },
      {
       "name": "Simple Banner &#8211; Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website [simple-banner] < 3.1.0",
       "cvss": "4.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-12033"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.0.4 -> 3.3.2 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "sucuri-scanner",
     "status": "active",
     "active": true,
     "installed": "1.9.9",
     "available": "2.8",
     "priority": "P2",
     "vulns": [
      {
       "name": "Sucuri Security &#8211; Auditing, Malware Scanner and Security Hardening [sucuri-scanner] <= 2.7.3 (unfixed)",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-73033"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 1.9.9 -> 2.8 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "two-factor-2fa-via-email",
     "status": "active",
     "active": true,
     "installed": "1.9.6",
     "available": "1.9.10",
     "priority": "P2",
     "vulns": [
      {
       "name": "Two Factor (2FA) Authentication via Email [two-factor-2fa-via-email] < 1.9.9",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-13587"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.9.6 -> 1.9.10"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "duplicate-post",
     "status": "active",
     "active": true,
     "installed": "4.5",
     "available": "4.7",
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast Duplicate Post [duplicate-post] <= 4.6 (unfixed)",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-53740"
      },
      {
       "name": "Yoast Duplicate Post [duplicate-post] <= 4.6 (unfixed)",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-53739"
      },
      {
       "name": "Yoast Duplicate Post [duplicate-post] < 4.6",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-1217"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 4.5 -> 4.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "change-admin-email-setting-without-outbound-email",
     "status": "active",
     "active": true,
     "installed": "4.1",
     "available": "5.0",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 4.1 -> 5.0 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "better-wp-security",
     "status": "active",
     "active": true,
     "installed": "9.3.6",
     "available": "10.0.3",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 9.3.6 -> 10.0.3 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "eps-301-redirects",
     "status": "active",
     "active": true,
     "installed": "2.78",
     "available": "2.85",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 2.78 -> 2.85 (skipped 7 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "advanced-custom-fields-pro",
     "status": "active",
     "active": true,
     "installed": "6.3.12",
     "available": "6.8.10",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "multi-minor jump 6.3.12 -> 6.8.10 (skipped 5 minor releases)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE WITH CAPTURE \u2014 routine bump but on a sitewide-impact plugin; watch the diff closely."
    },
    {
     "plugin": "akismet",
     "status": "active",
     "active": true,
     "installed": "5.3.7",
     "available": "5.7.2",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.3.7 -> 5.7.2 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "force-regenerate-thumbnails",
     "status": "active",
     "active": true,
     "installed": "2.2.1",
     "available": "2.3.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.2.1 -> 2.3.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "headers-security-advanced-hsts-wp",
     "status": "active",
     "active": true,
     "installed": "5.0.42",
     "available": "5.3.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.0.42 -> 5.3.5 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "simple-page-ordering",
     "status": "active",
     "active": true,
     "installed": "2.7.3",
     "available": "2.8.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.7.3 -> 2.8.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "autodescription",
     "status": "active",
     "active": true,
     "installed": "5.1.2",
     "available": "5.1.4",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 5.1.2 -> 5.1.4"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "translatepress-developer",
     "status": "active",
     "active": true,
     "installed": "1.5.5",
     "available": "1.8.7",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 1.5.5 -> 1.8.7 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wp-mail-smtp",
     "status": "active",
     "active": true,
     "installed": "4.4.0",
     "available": "4.9.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 4.4.0 -> 4.9.0 (skipped 5 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "redirection",
     "status": "inactive",
     "active": false,
     "installed": "5.5.2",
     "available": "5.10.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.5.2 -> 5.10.0 (skipped 5 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    }
   ],
   "p0": 1,
   "p1": 6,
   "total_updates": 23
  },
  "wpengine:omprd": {
   "platform": "wpengine",
   "install": "omprd",
   "environment": "production",
   "domain": "omprd.wpenginepowered.com",
   "siteurl": "https://omprd.wpenginepowered.com",
   "core": "7.0.3",
   "core_update": "7.0.4",
   "theme": "acwebdev",
   "updates": [
    {
     "plugin": "insert-headers-and-footers",
     "status": "active",
     "active": true,
     "installed": "2.1.7",
     "available": "2.3.9",
     "priority": "P1",
     "vulns": [
      {
       "name": "WPCode &#8211; Insert Headers and Footers + Custom Code Snippets &#8211; WordPress Code Manager [insert-headers-and-footers] < 2.3.6",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-8832"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.1.7 -> 2.3.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "genesis-blocks",
     "status": "active",
     "active": true,
     "installed": "3.1.1",
     "available": "3.1.11",
     "priority": "P2",
     "vulns": [
      {
       "name": "Genesis Blocks [genesis-blocks] < 3.1.3",
       "cvss": "6.8",
       "severity": "MEDIUM",
       "cve": "CVE-2024-2761"
      },
      {
       "name": "Genesis Blocks [genesis-blocks] < 3.1.4",
       "cvss": "6.8",
       "severity": "MEDIUM",
       "cve": "CVE-2024-3901"
      },
      {
       "name": "Genesis Blocks [genesis-blocks] < 3.1.3",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-1946"
      },
      {
       "name": "Genesis Blocks [genesis-blocks] < 3.1.4",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-3563"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 3.1.1 -> 3.1.11"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "cookie-law-info",
     "status": "active",
     "active": true,
     "installed": "3.1.8",
     "available": "3.5.6",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.1.8 -> 3.5.6 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "akismet",
     "status": "inactive",
     "active": false,
     "installed": "5.3",
     "available": "5.7.2",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.3 -> 5.7.2 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    }
   ],
   "p0": 0,
   "p1": 1,
   "total_updates": 4
  },
  "wpengine:kitocrosbyddev": {
   "platform": "wpengine",
   "install": "kitocrosbyddev",
   "environment": "development",
   "domain": "kitocrosbyddev.wpengine.com",
   "siteurl": "http://kitocrosbyddev.wpengine.com",
   "core": "7.0.3",
   "core_update": "7.0.4",
   "theme": "hello-kitocrosby",
   "updates": [
    {
     "plugin": "advanced-custom-fields-pro",
     "status": "active",
     "active": true,
     "installed": "6.2.1.1",
     "available": "6.8.10",
     "priority": "P0",
     "vulns": [
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.2.10",
       "cvss": "9.9",
       "severity": "CRITICAL",
       "cve": "CVE-2024-34762"
      },
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.2.10",
       "cvss": "8.5",
       "severity": "HIGH",
       "cve": "CVE-2024-34761"
      },
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.3.8",
       "cvss": "6.6",
       "severity": "MEDIUM",
       "cve": "CVE-2024-9529"
      },
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.3.0",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-4565"
      }
     ],
     "vuln_count": 12,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "multi-minor jump 6.2.1.1 -> 6.8.10 (skipped 6 minor releases)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "elementor",
     "status": "active",
     "active": true,
     "installed": "3.15.1",
     "available": "4.2.4",
     "priority": "P0",
     "vulns": [
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.18.2",
       "cvss": "9.9",
       "severity": "CRITICAL",
       "cve": "CVE-2023-48777"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.19.1",
       "cvss": "8.5",
       "severity": "HIGH",
       "cve": "CVE-2024-24934"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.16.5",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2023-47505"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.16.5",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2023-47504"
      }
     ],
     "vuln_count": 28,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.15.1 -> 4.2.4 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "ewww-image-optimizer",
     "status": "active",
     "active": true,
     "installed": "7.2.0",
     "available": "8.7.7",
     "priority": "P1",
     "vulns": [
      {
       "name": "EWWW Image Optimizer [ewww-image-optimizer] < 8.7.7",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-84773"
      },
      {
       "name": "EWWW Image Optimizer [ewww-image-optimizer] < 8.7.4",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-15446"
      },
      {
       "name": "EWWW Image Optimizer [ewww-image-optimizer] < 7.2.1",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2023-40600"
      },
      {
       "name": "EWWW Image Optimizer [ewww-image-optimizer] < 7.3.0",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2024-31924"
      }
     ],
     "vuln_count": 6,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 7.2.0 -> 8.7.7 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "polylang",
     "status": "active",
     "active": true,
     "installed": "3.4.5",
     "available": "3.8.9",
     "priority": "P1",
     "vulns": [
      {
       "name": "Polylang [polylang] < 3.7.4",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2025-64353"
      },
      {
       "name": "Polylang [polylang] < 3.8.6",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-65458"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "multi-minor jump 3.4.5 -> 3.8.9 (skipped 4 minor releases)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "insert-headers-and-footers",
     "status": "active",
     "active": true,
     "installed": "2.1.0",
     "available": "2.3.9",
     "priority": "P1",
     "vulns": [
      {
       "name": "WPCode &#8211; Insert Headers and Footers + Custom Code Snippets &#8211; WordPress Code Manager [insert-headers-and-footers] < 2.3.6",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-8832"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.1.0 -> 2.3.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "wp-hide-security-enhancer",
     "status": "inactive",
     "active": false,
     "installed": "2.1.5",
     "available": "2.9.1",
     "priority": "P1",
     "vulns": [
      {
       "name": "WP Hide &amp; Security Enhancer [wp-hide-security-enhancer] < 2.5.2",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2024-11585"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 2.1.5 -> 2.9.1 (skipped 8 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "limit-login-attempts-reloaded",
     "status": "active",
     "active": true,
     "installed": "2.25.21",
     "available": "3.3.8",
     "priority": "P2",
     "vulns": [
      {
       "name": "Limit Login Attempts Security &#8211; Login Security, 2FA, Firewall, Brute Force Prevention [limit-login-attempts-reloaded] < 2.25.27",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2023-6934"
      },
      {
       "name": "Limit Login Attempts Security &#8211; Login Security, 2FA, Firewall, Brute Force Prevention [limit-login-attempts-reloaded] < 2.25.26",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2023-5525"
      },
      {
       "name": "Limit Login Attempts Security &#8211; Login Security, 2FA, Firewall, Brute Force Prevention [limit-login-attempts-reloaded] < 3.3.5",
       "cvss": "3.7",
       "severity": "LOW",
       "cve": "CVE-2026-18356"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.25.21 -> 3.3.8 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "megamenu",
     "status": "active",
     "active": true,
     "installed": "3.2.3",
     "available": "3.10.8",
     "priority": "P2",
     "vulns": [
      {
       "name": "Max Mega Menu [megamenu] < 3.3.1",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-28003"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.2.3 -> 3.10.8 (skipped 8 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "svg-support",
     "status": "active",
     "active": true,
     "installed": "2.5.5",
     "available": "2.6.1",
     "priority": "P2",
     "vulns": [
      {
       "name": "SVG Support [svg-support] < 2.5.11",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-10222"
      },
      {
       "name": "SVG Support [svg-support] < 2.5.9",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2022-23638"
      },
      {
       "name": "SVG Support [svg-support] < 2.5.8",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2023-6708"
      },
      {
       "name": "SVG Support [svg-support] < 2.5.15",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-48973"
      }
     ],
     "vuln_count": 5,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.5.5 -> 2.6.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "advanced-custom-fields",
     "status": "inactive",
     "active": false,
     "installed": "6.2.0",
     "available": "6.8.10",
     "priority": "P2",
     "vulns": [
      {
       "name": "Advanced Custom Fields (ACF\u00ae) [advanced-custom-fields] < 6.3.8",
       "cvss": "6.6",
       "severity": "MEDIUM",
       "cve": "CVE-2024-9529"
      },
      {
       "name": "Advanced Custom Fields (ACF\u00ae) [advanced-custom-fields] < 6.3.0",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-4565"
      },
      {
       "name": "Advanced Custom Fields (ACF\u00ae) [advanced-custom-fields] < 6.3.6",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2024-45429"
      },
      {
       "name": "Advanced Custom Fields (ACF\u00ae) [advanced-custom-fields] < 6.2.5",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2023-6701"
      }
     ],
     "vuln_count": 11,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "multi-minor jump 6.2.0 -> 6.8.10 (skipped 6 minor releases)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "font-awesome",
     "status": "active",
     "active": true,
     "installed": "4.4.0",
     "available": "5.2.1",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 4.4.0 -> 5.2.1 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "admin-taxonomy-filter",
     "status": "active",
     "active": true,
     "installed": "1.0.2",
     "available": "1.0.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.0.2 -> 1.0.5"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "child-theme-configurator",
     "status": "active",
     "active": true,
     "installed": "2.6.2",
     "available": "2.6.7",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 2.6.2 -> 2.6.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "cookie-law-info",
     "status": "active",
     "active": true,
     "installed": "3.1.1",
     "available": "3.5.6",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.1.1 -> 3.5.6 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "disable-json-api",
     "status": "active",
     "active": true,
     "installed": "1.7",
     "available": "1.8",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.7 -> 1.8"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "disable-xml-rpc-api",
     "status": "active",
     "active": true,
     "installed": "2.1.4.8",
     "available": "2.1.7",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 2.1.4.8 -> 2.1.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "duplicate-menu",
     "status": "active",
     "active": true,
     "installed": "0.2.2",
     "available": "0.2.3",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 0.2.2 -> 0.2.3"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "duplicate-page",
     "status": "active",
     "active": true,
     "installed": "4.5.2",
     "available": "4.5.9",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 4.5.2 -> 4.5.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "headers-security-advanced-hsts-wp",
     "status": "active",
     "active": true,
     "installed": "5.0.28",
     "available": "5.3.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.0.28 -> 5.3.5 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wp-widget-disable",
     "status": "active",
     "active": true,
     "installed": "3.0.0",
     "available": "3.0.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 3.0.0 -> 3.0.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wpe-site-migration",
     "status": "active",
     "active": true,
     "installed": "1.0.0-beta.6",
     "available": "1.8.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 1.0.0-beta.6 -> 1.8.5 (skipped 8 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wp-revisions-control",
     "status": "active",
     "active": true,
     "installed": "1.4.3",
     "available": "1.4.4",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.4.3 -> 1.4.4"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    }
   ],
   "p0": 2,
   "p1": 4,
   "total_updates": 22
  },
  "wpengine:ascentialstg": {
   "platform": "wpengine",
   "install": "ascentialstg",
   "environment": "staging",
   "domain": "ascentialstg.wpengine.com",
   "siteurl": "https://ascentialstg.wpengine.com",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "hello-ascential",
   "updates": [
    {
     "plugin": "elementor-pro",
     "status": "active",
     "active": true,
     "installed": "3.35.1",
     "available": "4.2.1",
     "priority": "P0",
     "vulns": [
      {
       "name": "Elementor Pro [elementor-pro] < 4.2.2",
       "cvss": "9.0",
       "severity": "CRITICAL",
       "cve": "CVE-2026-32475"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.35.1 -> 4.2.1 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "woocommerce",
     "status": "inactive",
     "active": false,
     "installed": "10.5.3",
     "available": "11.1.0",
     "priority": "P0",
     "vulns": [
      {
       "name": "WooCommerce [woocommerce] == 7.1.0 (unfixed)",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2022-50972"
      },
      {
       "name": "WooCommerce [woocommerce] < 11.0",
       "cvss": "7.6",
       "severity": "HIGH",
       "cve": "CVE-2026-57777"
      },
      {
       "name": "WooCommerce [woocommerce] < 11.1.0",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-48888"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 10.5.3 -> 11.1.0 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "mainwp-child",
     "status": "active",
     "active": true,
     "installed": "6.0.1",
     "available": "6.2",
     "priority": "P1",
     "vulns": [
      {
       "name": "MainWP Child &#8211; Securely Connects to the MainWP Dashboard to Manage Multiple Sites [mainwp-child] < 6.1.2",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-27366"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 6.0.1 -> 6.2"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "insert-headers-and-footers",
     "status": "active",
     "active": true,
     "installed": "2.3.4",
     "available": "2.3.9",
     "priority": "P1",
     "vulns": [
      {
       "name": "WPCode &#8211; Insert Headers and Footers + Custom Code Snippets &#8211; WordPress Code Manager [insert-headers-and-footers] < 2.3.6",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-8832"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 2.3.4 -> 2.3.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "all-in-one-wp-security-and-firewall",
     "status": "inactive",
     "active": false,
     "installed": "5.4.6",
     "available": "5.4.9",
     "priority": "P1",
     "vulns": [
      {
       "name": "All-In-One Security (AIOS) \u2013 Security and Firewall [all-in-one-wp-security-and-firewall] < 5.4.8",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-8438"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 5.4.6 -> 5.4.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "jet-menu",
     "status": "inactive",
     "active": false,
     "installed": "2.4.8",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "JetMenu [jet-menu] < 2.4.9.1",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2025-26953"
      },
      {
       "name": "JetMenu [jet-menu] < 2.4.11.2",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-53987"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "link-whisper",
     "status": "inactive",
     "active": false,
     "installed": "0.9.1",
     "available": "0.9.7",
     "priority": "P1",
     "vulns": [
      {
       "name": "Link Whisper Free [link-whisper] < 0.9.3",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-22357"
      },
      {
       "name": "Link Whisper Free [link-whisper] < 0.9.5",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-57333"
      },
      {
       "name": "Link Whisper Free [link-whisper] <= 0.9.2 (unfixed)",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-62970"
      },
      {
       "name": "Link Whisper Free [link-whisper] < 0.9.7",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-14601"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 0.9.1 -> 0.9.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "shortpixel-image-optimiser",
     "status": "inactive",
     "active": false,
     "installed": "6.4.3",
     "available": "6.5.6",
     "priority": "P1",
     "vulns": [
      {
       "name": "ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 6.4.4",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-39471"
      },
      {
       "name": "ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 6.4.4",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-4335"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 6.4.3 -> 6.5.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "revslider",
     "status": "inactive",
     "active": false,
     "installed": "6.7.18",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "Slider Revolution [revslider] < 7.0.11",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-6692"
      },
      {
       "name": "Slider Revolution [revslider] < 7.1.0",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-57678"
      },
      {
       "name": "Slider Revolution [revslider] < 6.7.37",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-9217"
      },
      {
       "name": "Slider Revolution [revslider] < 6.7.38",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-10249"
      }
     ],
     "vuln_count": 9,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "updraftplus",
     "status": "inactive",
     "active": false,
     "installed": "1.26.2",
     "available": "1.26.7",
     "priority": "P1",
     "vulns": [
      {
       "name": "UpdraftPlus: WP Backup &amp; Migration Plugin [updraftplus] < 1.26.5",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2026-10795"
      },
      {
       "name": "UpdraftPlus: WP Backup &amp; Migration Plugin [updraftplus] < 1.26.7",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-76549"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "patch bump 1.26.2 -> 1.26.7",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wp-optimize",
     "status": "inactive",
     "active": false,
     "installed": "4.5.0",
     "available": "4.6.1",
     "priority": "P1",
     "vulns": [
      {
       "name": "WP-Optimize \u2013 Cache, Compress images, Minify &amp; Clean database to boost page speed &amp; performance [wp-optimize] < 4.5.3",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2026-7252"
      },
      {
       "name": "WP-Optimize \u2013 Cache, Compress images, Minify &amp; Clean database to boost page speed &amp; performance [wp-optimize] < 4.5.1",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-2712"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "minor version bump 4.5.0 -> 4.6.1",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "hide-my-wp",
     "status": "inactive",
     "active": false,
     "installed": "5.5.02",
     "available": "7.0.11",
     "priority": "P1",
     "vulns": [
      {
       "name": "Hide My WP Ghost &#8211; Security &amp; Firewall [hide-my-wp] < 7.0.10",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-81806"
      },
      {
       "name": "Hide My WP Ghost &#8211; Security &amp; Firewall [hide-my-wp] <= 6.2.12 (unfixed)",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2025-69098"
      },
      {
       "name": "Hide My WP Ghost &#8211; Security &amp; Firewall [hide-my-wp] < 7.0.00",
       "cvss": "4.7",
       "severity": "MEDIUM",
       "cve": "CVE-2026-39484"
      },
      {
       "name": "Hide My WP Ghost &#8211; Security &amp; Firewall [hide-my-wp] < 7.0.07",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-59546"
      }
     ],
     "vuln_count": 5,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 5.5.02 -> 7.0.11 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wpide",
     "status": "inactive",
     "active": false,
     "installed": "3.5.3",
     "available": "3.5.9",
     "priority": "P1",
     "vulns": [
      {
       "name": "WPIDE &#8211; File Manager &amp; Code Editor [wpide] < 3.5.7",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-57766"
      },
      {
       "name": "WPIDE &#8211; File Manager &amp; Code Editor [wpide] < 3.5.8",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-66440"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 3.5.3 -> 3.5.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "elementor",
     "status": "active",
     "active": true,
     "installed": "3.35.6",
     "available": "4.2.4",
     "priority": "P2",
     "vulns": [
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 4.1.4",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-57619"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 4.0.5",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-6127"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 4.1.1",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-49782"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.35.8",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-1206"
      }
     ],
     "vuln_count": 5,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.35.6 -> 4.2.4 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "smtp2go",
     "status": "active",
     "active": true,
     "installed": "1.14.1",
     "available": "1.17.1",
     "priority": "P2",
     "vulns": [
      {
       "name": "SMTP2GO for WordPress &#8211; Email Made Easy [smtp2go] < 1.17.0",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-7621"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 1.14.1 -> 1.17.1 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "wordpress-seo",
     "status": "active",
     "active": true,
     "installed": "27.1.1",
     "available": "28.5",
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 27.2",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-3427"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 28.1",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-15425"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 27.1.1 -> 28.5 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "debug-log-manager",
     "status": "inactive",
     "active": false,
     "installed": "2.4.3",
     "available": "2.5.2",
     "priority": "P2",
     "vulns": [
      {
       "name": "Debug Log Manager &#8211; Conveniently Monitor and Inspect Errors [debug-log-manager] < 2.5.1",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-9016"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.4.3 -> 2.5.2"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "dracula-dark-mode",
     "status": "inactive",
     "active": false,
     "installed": "1.2.7",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Dracula Dark Mode \u2013  Accessibility, Reading Mode &amp; Dark Mode for WordPress [dracula-dark-mode] < 1.2.8 (closed)",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2024-13362"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "limit-login-attempts-reloaded",
     "status": "inactive",
     "active": false,
     "installed": "2.26.28",
     "available": "3.3.8",
     "priority": "P2",
     "vulns": [
      {
       "name": "Limit Login Attempts Security &#8211; Login Security, 2FA, Firewall, Brute Force Prevention [limit-login-attempts-reloaded] < 3.3.5",
       "cvss": "3.7",
       "severity": "LOW",
       "cve": "CVE-2026-18356"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.26.28 -> 3.3.8 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "nitropack",
     "status": "inactive",
     "active": false,
     "installed": "1.19.1",
     "available": "1.20.0",
     "priority": "P2",
     "vulns": [
      {
       "name": "NitroPack \u2013 Performance, Page Speed &amp; Cache Plugin for Core Web Vitals, CDN &amp; Image Optimization [nitropack] < 1.19.4",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-39669"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.19.1 -> 1.20.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "query-monitor",
     "status": "inactive",
     "active": false,
     "installed": "3.20.2",
     "available": "4.0.7",
     "priority": "P2",
     "vulns": [
      {
       "name": "Query Monitor [query-monitor] < 3.20.4",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-4267"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.20.2 -> 4.0.7 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "search-filter-pro",
     "status": "inactive",
     "active": false,
     "installed": "2.5.19",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Search & Filter Pro [search-filter-pro] < 2.5.20",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-1528"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "sucuri-scanner",
     "status": "inactive",
     "active": false,
     "installed": "2.6",
     "available": "2.8",
     "priority": "P2",
     "vulns": [
      {
       "name": "Sucuri Security &#8211; Auditing, Malware Scanner and Security Hardening [sucuri-scanner] <= 2.7.3 (unfixed)",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-73033"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.6 -> 2.8"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "svg-support",
     "status": "inactive",
     "active": false,
     "installed": "2.5.14",
     "available": "2.6.1",
     "priority": "P2",
     "vulns": [
      {
       "name": "SVG Support [svg-support] < 2.5.15",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-48973"
      },
      {
       "name": "SVG Support [svg-support] < 2.5.17",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-13340"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.5.14 -> 2.6.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "duplicate-post",
     "status": "inactive",
     "active": false,
     "installed": "4.5",
     "available": "4.7",
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast Duplicate Post [duplicate-post] <= 4.6 (unfixed)",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-53740"
      },
      {
       "name": "Yoast Duplicate Post [duplicate-post] <= 4.6 (unfixed)",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-53739"
      },
      {
       "name": "Yoast Duplicate Post [duplicate-post] < 4.6",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-1217"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 4.5 -> 4.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wordpress-seo-premium",
     "status": "inactive",
     "active": false,
     "installed": "24.3",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast SEO Premium [wordpress-seo-premium] < 27.6.1",
       "cvss": "6.6",
       "severity": "MEDIUM",
       "cve": "CVE-2026-10821"
      },
      {
       "name": "Yoast SEO Premium [wordpress-seo-premium] < 26.7",
       "cvss": "5.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-40722"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "weglot",
     "status": "active",
     "active": true,
     "installed": "5.4",
     "available": "6.2",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 5.4 -> 6.2 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "prevent-browser-caching",
     "status": "inactive",
     "active": false,
     "installed": "2.3.5",
     "available": "3.2.1",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.3.5 -> 3.2.1 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "eps-301-redirects",
     "status": "active",
     "active": true,
     "installed": "2.83",
     "available": "2.85",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.83 -> 2.85"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "advanced-custom-fields-pro",
     "status": "active",
     "active": true,
     "installed": "6.7.1",
     "available": "6.8.10",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "minor version bump 6.7.1 -> 6.8.10",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE WITH CAPTURE \u2014 routine bump but on a sitewide-impact plugin; watch the diff closely."
    },
    {
     "plugin": "cookie-law-info",
     "status": "active",
     "active": true,
     "installed": "3.4.0",
     "available": "3.5.6",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 3.4.0 -> 3.5.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "font-awesome",
     "status": "active",
     "active": true,
     "installed": "5.1.3",
     "available": "5.2.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 5.1.3 -> 5.2.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "headers-security-advanced-hsts-wp",
     "status": "active",
     "active": true,
     "installed": "5.2.5",
     "available": "5.3.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 5.2.5 -> 5.3.5"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "view-transitions",
     "status": "active",
     "active": true,
     "installed": "1.2.0",
     "available": "1.2.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.2.0 -> 1.2.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "cachebuster",
     "status": "inactive",
     "active": false,
     "installed": "1.8",
     "available": "1.10",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.8 -> 1.10"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wp-discussion-board",
     "status": "inactive",
     "active": false,
     "installed": "2.5.8",
     "available": "2.6.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.5.8 -> 2.6.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "duplicate-page",
     "status": "inactive",
     "active": false,
     "installed": "4.5.6",
     "available": "4.5.9",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 4.5.6 -> 4.5.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "megamenu",
     "status": "inactive",
     "active": false,
     "installed": "3.7",
     "available": "3.10.8",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.7 -> 3.10.8 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "online-active-users",
     "status": "inactive",
     "active": false,
     "installed": "3.1",
     "available": "3.4.4",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.1 -> 3.4.4 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "page-links-to",
     "status": "inactive",
     "active": false,
     "installed": "3.3.7",
     "available": "3.4.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 3.3.7 -> 3.4.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "post-types-order",
     "status": "inactive",
     "active": false,
     "installed": "2.4.3",
     "available": "2.5.3",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.4.3 -> 2.5.3"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "search-regex",
     "status": "inactive",
     "active": false,
     "installed": "3.4.1",
     "available": "3.4.4",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 3.4.1 -> 3.4.4"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "simple-banner",
     "status": "inactive",
     "active": false,
     "installed": "3.2.1",
     "available": "3.3.2",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 3.2.1 -> 3.3.2"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "simple-download-monitor",
     "status": "inactive",
     "active": false,
     "installed": "4.0.6",
     "available": "4.1.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 4.0.6 -> 4.1.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "stop-user-enumeration",
     "status": "inactive",
     "active": false,
     "installed": "1.7.7",
     "available": "1.7.8",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.7.7 -> 1.7.8"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wp-hide-security-enhancer",
     "status": "inactive",
     "active": false,
     "installed": "2.8.2",
     "available": "2.9.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.8.2 -> 2.9.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wp-mail-smtp",
     "status": "inactive",
     "active": false,
     "installed": "4.7.1",
     "available": "4.9.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 4.7.1 -> 4.9.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wp-search-with-algolia",
     "status": "inactive",
     "active": false,
     "installed": "2.11.1",
     "available": "2.14.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 2.11.1 -> 2.14.1 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wps-hide-login",
     "status": "inactive",
     "active": false,
     "installed": "1.9.18",
     "available": "1.9.19",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.9.18 -> 1.9.19"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    }
   ],
   "p0": 2,
   "p1": 11,
   "total_updates": 44
  },
  "wpengine:overmatdev": {
   "platform": "wpengine",
   "install": "overmatdev",
   "environment": "development",
   "domain": "overmatdev.wpenginepowered.com",
   "siteurl": "https://overmatdev.wpenginepowered.com",
   "core": "7.0.3",
   "core_update": "7.0.4",
   "theme": "acwebdev",
   "updates": [
    {
     "plugin": "insert-headers-and-footers",
     "status": "active",
     "active": true,
     "installed": "2.1.7",
     "available": "2.3.9",
     "priority": "P1",
     "vulns": [
      {
       "name": "WPCode &#8211; Insert Headers and Footers + Custom Code Snippets &#8211; WordPress Code Manager [insert-headers-and-footers] < 2.3.6",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-8832"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.1.7 -> 2.3.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "genesis-blocks",
     "status": "active",
     "active": true,
     "installed": "3.1.1",
     "available": "3.1.11",
     "priority": "P2",
     "vulns": [
      {
       "name": "Genesis Blocks [genesis-blocks] < 3.1.3",
       "cvss": "6.8",
       "severity": "MEDIUM",
       "cve": "CVE-2024-2761"
      },
      {
       "name": "Genesis Blocks [genesis-blocks] < 3.1.4",
       "cvss": "6.8",
       "severity": "MEDIUM",
       "cve": "CVE-2024-3901"
      },
      {
       "name": "Genesis Blocks [genesis-blocks] < 3.1.3",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-1946"
      },
      {
       "name": "Genesis Blocks [genesis-blocks] < 3.1.4",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-3563"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 3.1.1 -> 3.1.11"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "cookie-law-info",
     "status": "active",
     "active": true,
     "installed": "3.1.8",
     "available": "3.5.6",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.1.8 -> 3.5.6 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "megamenu",
     "status": "active",
     "active": true,
     "installed": "3.3.1",
     "available": "3.10.8",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.3.1 -> 3.10.8 (skipped 7 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wpe-site-migration",
     "status": "active",
     "active": true,
     "installed": "1.0.0-beta.23",
     "available": "1.8.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 1.0.0-beta.23 -> 1.8.5 (skipped 8 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "akismet",
     "status": "inactive",
     "active": false,
     "installed": "5.3",
     "available": "5.7.2",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.3 -> 5.7.2 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    }
   ],
   "p0": 0,
   "p1": 1,
   "total_updates": 6
  },
  "wpengine:epochprd": {
   "platform": "wpengine",
   "install": "epochprd",
   "environment": "production",
   "domain": "epochprd.wpenginepowered.com",
   "siteurl": "https://epochprd.wpenginepowered.com",
   "core": "7.0.3",
   "core_update": "7.0.4",
   "theme": "genesis-block-theme",
   "updates": [
    {
     "plugin": "genesis-blocks",
     "status": "active",
     "active": true,
     "installed": "3.1.1",
     "available": "3.1.11",
     "priority": "P2",
     "vulns": [
      {
       "name": "Genesis Blocks [genesis-blocks] < 3.1.3",
       "cvss": "6.8",
       "severity": "MEDIUM",
       "cve": "CVE-2024-2761"
      },
      {
       "name": "Genesis Blocks [genesis-blocks] < 3.1.4",
       "cvss": "6.8",
       "severity": "MEDIUM",
       "cve": "CVE-2024-3901"
      },
      {
       "name": "Genesis Blocks [genesis-blocks] < 3.1.3",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-1946"
      },
      {
       "name": "Genesis Blocks [genesis-blocks] < 3.1.4",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-3563"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 3.1.1 -> 3.1.11"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "akismet",
     "status": "inactive",
     "active": false,
     "installed": "5.3",
     "available": "5.7.2",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.3 -> 5.7.2 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    }
   ],
   "p0": 0,
   "p1": 0,
   "total_updates": 2
  },
  "wpengine:titanprd": {
   "platform": "wpengine",
   "install": "titanprd",
   "environment": "production",
   "domain": "www.titansystems.com",
   "siteurl": "https://www.titansystems.com",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "theme",
   "updates": [
    {
     "plugin": "acf-to-rest-api",
     "status": "active",
     "active": true,
     "installed": "3.3.4",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "ACF to REST API [acf-to-rest-api] <= 3.3.4 (unfixed + closed)",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-62979"
      },
      {
       "name": "ACF to REST API [acf-to-rest-api] <= 3.3.4 (unfixed + closed)",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-12030"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "advanced-custom-fields-pro",
     "status": "active",
     "active": true,
     "installed": "6.8.7",
     "available": "6.8.10",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "patch bump 6.8.7 -> 6.8.10",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE WITH CAPTURE \u2014 routine bump but on a sitewide-impact plugin; watch the diff closely."
    }
   ],
   "p0": 0,
   "p1": 0,
   "total_updates": 1
  },
  "wpengine:acwebdev1": {
   "platform": "wpengine",
   "install": "acwebdev1",
   "environment": "production",
   "domain": "acwebdev1.wpenginepowered.com",
   "siteurl": "http://acwebdev1.wpenginepowered.com",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "amplifi",
   "updates": [
    {
     "plugin": "advanced-custom-fields-pro",
     "status": "active",
     "active": true,
     "installed": "6.8.7",
     "available": "6.8.10",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "patch bump 6.8.7 -> 6.8.10",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE WITH CAPTURE \u2014 routine bump but on a sitewide-impact plugin; watch the diff closely."
    }
   ],
   "p0": 0,
   "p1": 0,
   "total_updates": 1
  },
  "wpengine:wingsdev1": {
   "platform": "wpengine",
   "install": "wingsdev1",
   "environment": "development",
   "domain": "wingsdev1.wpenginepowered.com",
   "siteurl": "https://wingsdev1.wpenginepowered.com",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "genesis-block-theme",
   "updates": [
    {
     "plugin": "genesis-blocks",
     "status": "active",
     "active": true,
     "installed": "3.1.2",
     "available": "3.1.11",
     "priority": "P2",
     "vulns": [
      {
       "name": "Genesis Blocks [genesis-blocks] < 3.1.3",
       "cvss": "6.8",
       "severity": "MEDIUM",
       "cve": "CVE-2024-2761"
      },
      {
       "name": "Genesis Blocks [genesis-blocks] < 3.1.4",
       "cvss": "6.8",
       "severity": "MEDIUM",
       "cve": "CVE-2024-3901"
      },
      {
       "name": "Genesis Blocks [genesis-blocks] < 3.1.3",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-1946"
      },
      {
       "name": "Genesis Blocks [genesis-blocks] < 3.1.4",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-3563"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 3.1.2 -> 3.1.11"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "akismet",
     "status": "inactive",
     "active": false,
     "installed": "5.3.1",
     "available": "5.7.2",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.3.1 -> 5.7.2 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    }
   ],
   "p0": 0,
   "p1": 0,
   "total_updates": 2
  },
  "wpengine:wingsdevsite": {
   "platform": "wpengine",
   "install": "wingsdevsite",
   "environment": "development",
   "domain": "wingsdevsite.wpenginepowered.com",
   "siteurl": "http://wingsdevsite.wpenginepowered.com",
   "core": "7.0.3",
   "core_update": "7.0.4",
   "theme": "hello-elementor",
   "updates": [
    {
     "plugin": "advanced-custom-fields-pro",
     "status": "active",
     "active": true,
     "installed": "6.2.9",
     "available": "6.8.10",
     "priority": "P0",
     "vulns": [
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.2.10",
       "cvss": "9.9",
       "severity": "CRITICAL",
       "cve": "CVE-2024-34762"
      },
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.2.10",
       "cvss": "8.5",
       "severity": "HIGH",
       "cve": "CVE-2024-34761"
      },
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.3.8",
       "cvss": "6.6",
       "severity": "MEDIUM",
       "cve": "CVE-2024-9529"
      },
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.3.0",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-4565"
      }
     ],
     "vuln_count": 10,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "multi-minor jump 6.2.9 -> 6.8.10 (skipped 6 minor releases)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "elementor-pro",
     "status": "active",
     "active": true,
     "installed": "3.21.0",
     "available": "3.21.3",
     "priority": "P0",
     "vulns": [
      {
       "name": "Elementor Pro [elementor-pro] < 4.2.2",
       "cvss": "9.0",
       "severity": "CRITICAL",
       "cve": "CVE-2026-32475"
      },
      {
       "name": "Elementor Pro [elementor-pro] < 3.25.11",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-8494"
      },
      {
       "name": "Elementor Pro [elementor-pro] < 3.29.1",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-50555"
      },
      {
       "name": "Elementor Pro [elementor-pro] < 3.21.3",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2024-35656"
      }
     ],
     "vuln_count": 6,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "patch bump 3.21.0 -> 3.21.3",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "jet-engine",
     "status": "active",
     "active": true,
     "installed": "3.4.4",
     "available": null,
     "priority": "P0",
     "vulns": [
      {
       "name": "JetEngine [jet-engine] < 3.8.10",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2026-49075"
      },
      {
       "name": "JetEngine [jet-engine] < 3.8.10.1",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2026-52706"
      },
      {
       "name": "JetEngine [jet-engine] < 3.8.14.1",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2026-66613"
      },
      {
       "name": "JetEngine [jet-engine] < 3.8.8.2",
       "cvss": "9.3",
       "severity": "CRITICAL",
       "cve": "CVE-2026-42774"
      }
     ],
     "vuln_count": 33,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "the-events-calendar",
     "status": "active",
     "active": true,
     "installed": "6.6.4.2",
     "available": "6.17.4.1",
     "priority": "P0",
     "vulns": [
      {
       "name": "The Events Calendar [the-events-calendar] < 6.17.3",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2026-78265"
      },
      {
       "name": "The Events Calendar [the-events-calendar] < 6.17.4.1",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2026-78006"
      },
      {
       "name": "The Events Calendar [the-events-calendar] < 6.17.3.1",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2026-78159"
      },
      {
       "name": "The Events Calendar [the-events-calendar] < 6.16.3",
       "cvss": "9.3",
       "severity": "CRITICAL",
       "cve": "CVE-2026-49772"
      }
     ],
     "vuln_count": 20,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 6.6.4.2 -> 6.17.4.1 (skipped 11 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "yet-another-related-posts-plugin",
     "status": "active",
     "active": true,
     "installed": "5.30.10",
     "available": "5.30.11",
     "priority": "P0",
     "vulns": [
      {
       "name": "YARPP &#8211; Yet Another Related Posts Plugin [yet-another-related-posts-plugin] < 5.30.11 (closed)",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2024-43919"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 5.30.10 -> 5.30.11"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "event-tickets",
     "status": "active",
     "active": true,
     "installed": "5.10.0",
     "available": "5.29.4",
     "priority": "P1",
     "vulns": [
      {
       "name": "Event Tickets and Registration [event-tickets] < 5.26.6",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2025-11517"
      },
      {
       "name": "Event Tickets and Registration [event-tickets] < 5.28.5.1",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-57705"
      },
      {
       "name": "Event Tickets and Registration [event-tickets] < 5.27.4.1",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-3174"
      },
      {
       "name": "Event Tickets and Registration [event-tickets] < 5.29.3",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-78263"
      }
     ],
     "vuln_count": 14,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.10.0 -> 5.29.4 (skipped 19 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "jet-tricks",
     "status": "active",
     "active": true,
     "installed": "1.4.9",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "JetTricks [jet-tricks] < 1.5.1.1",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2025-26942"
      },
      {
       "name": "JetTricks [jet-tricks] < 1.5.4.2",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-53992"
      },
      {
       "name": "JetTricks [jet-tricks] < 1.5.4.2",
       "cvss": "0.0",
       "severity": null,
       "cve": "CVE-2025-53991"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "shortpixel-image-optimiser",
     "status": "active",
     "active": true,
     "installed": "5.5.5",
     "available": "6.5.6",
     "priority": "P1",
     "vulns": [
      {
       "name": "ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 5.6.4",
       "cvss": "7.6",
       "severity": "HIGH",
       "cve": "CVE-2024-48043"
      },
      {
       "name": "ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 6.4.4",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-39471"
      },
      {
       "name": "ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 5.6.4",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-48044"
      },
      {
       "name": "ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 6.3.5",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-11378"
      }
     ],
     "vuln_count": 6,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 5.5.5 -> 6.5.6 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "events-calendar-pro",
     "status": "active",
     "active": true,
     "installed": "6.5.0",
     "available": "7.8.2",
     "priority": "P1",
     "vulns": [
      {
       "name": "The Events Calendar Pro [events-calendar-pro] < 7.0.2.1",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2024-8016"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 6.5.0 -> 7.8.2 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "wordpress-importer",
     "status": "active",
     "active": true,
     "installed": "0.8.2",
     "available": "0.9.6",
     "priority": "P1",
     "vulns": [
      {
       "name": "WordPress Importer [wordpress-importer] < 0.8.4",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2024-13889"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 0.8.2 -> 0.9.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "wp-all-import-pro",
     "status": "active",
     "active": true,
     "installed": "4.8.7",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "WP All Import Pro [wp-all-import-pro] < 4.9.4",
       "cvss": "7.6",
       "severity": "HIGH",
       "cve": "CVE-2024-9624"
      },
      {
       "name": "WP All Import Pro [wp-all-import-pro] < 4.9.8",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2024-9664"
      },
      {
       "name": "WP All Import Pro [wp-all-import-pro] < 4.9.8",
       "cvss": "5.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-8722"
      },
      {
       "name": "WP All Import Pro [wp-all-import-pro] < 4.9.8",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2024-9661"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "insert-headers-and-footers",
     "status": "active",
     "active": true,
     "installed": "2.1.11",
     "available": "2.3.9",
     "priority": "P1",
     "vulns": [
      {
       "name": "WPCode &#8211; Insert Headers and Footers + Custom Code Snippets &#8211; WordPress Code Manager [insert-headers-and-footers] < 2.3.6",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-8832"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.1.11 -> 2.3.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "auto-upload-images",
     "status": "active",
     "active": true,
     "installed": "3.3.2",
     "available": "3.4.0",
     "priority": "P2",
     "vulns": [
      {
       "name": "Auto Upload Images [auto-upload-images] <= 3.3.2 (unfixed + closed)",
       "cvss": "0.0",
       "severity": null,
       "cve": "CVE-2025-49985"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 3.3.2 -> 3.4.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "elementor",
     "status": "active",
     "active": true,
     "installed": "3.21.0",
     "available": "4.2.4",
     "priority": "P2",
     "vulns": [
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.25.11",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-54444"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.29.1",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-50555"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.35.6",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-32352"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 4.1.4",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-57619"
      }
     ],
     "vuln_count": 22,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.21.0 -> 4.2.4 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "post-type-switcher",
     "status": "active",
     "active": true,
     "installed": "3.3.1",
     "available": "4.0.1",
     "priority": "P2",
     "vulns": [
      {
       "name": "Post Type Switcher [post-type-switcher] < 4.0.1",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-12524"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.3.1 -> 4.0.1 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "search-filter-pro",
     "status": "active",
     "active": true,
     "installed": "2.5.17",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Search & Filter Pro [search-filter-pro] < 2.5.18",
       "cvss": "4.8",
       "severity": "MEDIUM",
       "cve": "CVE-2024-6481"
      },
      {
       "name": "Search & Filter Pro [search-filter-pro] < 2.5.20",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-1528"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "simple-banner",
     "status": "active",
     "active": true,
     "installed": "2.17.0",
     "available": "3.3.2",
     "priority": "P2",
     "vulns": [
      {
       "name": "Simple Banner &#8211; Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website [simple-banner] < 3.0.5",
       "cvss": "4.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-13898"
      },
      {
       "name": "Simple Banner &#8211; Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website [simple-banner] < 3.1.0",
       "cvss": "4.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-12033"
      },
      {
       "name": "Simple Banner &#8211; Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website [simple-banner] < 3.0.4",
       "cvss": "3.5",
       "severity": "LOW",
       "cve": "CVE-2024-12769"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.17.0 -> 3.3.2 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "prevent-browser-caching",
     "status": "active",
     "active": true,
     "installed": "2.3.5",
     "available": "3.2.1",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.3.5 -> 3.2.1 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "wpai-acf-add-on",
     "status": "active",
     "active": true,
     "installed": "3.3.8",
     "available": "4.0.2",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.3.8 -> 4.0.2 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "admin-taxonomy-filter",
     "status": "active",
     "active": true,
     "installed": "1.0.2",
     "available": "1.0.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.0.2 -> 1.0.5"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "bulk-post-update-date",
     "status": "active",
     "active": true,
     "installed": "1.5.0",
     "available": "1.6.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.5.0 -> 1.6.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "cookie-law-info",
     "status": "active",
     "active": true,
     "installed": "3.2.2",
     "available": "3.5.6",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.2.2 -> 3.5.6 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "duplicate-page",
     "status": "active",
     "active": true,
     "installed": "4.5.3",
     "available": "4.5.9",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 4.5.3 -> 4.5.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "dynamic-content-for-elementor",
     "status": "active",
     "active": true,
     "installed": "2.13.9",
     "available": "2.13.11",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "patch bump 2.13.9 -> 2.13.11",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE WITH CAPTURE \u2014 routine bump but on a sitewide-impact plugin; watch the diff closely."
    },
    {
     "plugin": "featured-image-admin-thumb-fiat",
     "status": "active",
     "active": true,
     "installed": "1.6",
     "available": "1.6.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.6 -> 1.6.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "post-types-order",
     "status": "active",
     "active": true,
     "installed": "2.2.1",
     "available": "2.5.3",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 2.2.1 -> 2.5.3 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "simple-website-redirect",
     "status": "active",
     "active": true,
     "installed": "1.2.8",
     "available": "1.3.2",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.2.8 -> 1.3.2"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wp-search-with-algolia",
     "status": "active",
     "active": true,
     "installed": "2.8.1",
     "available": "2.14.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 2.8.1 -> 2.14.1 (skipped 6 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "intuitive-custom-post-order",
     "status": "inactive",
     "active": false,
     "installed": "3.1.5",
     "available": "3.2.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 3.1.5 -> 3.2.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    }
   ],
   "p0": 5,
   "p1": 7,
   "total_updates": 25
  },
  "wpengine:ascentialmisc": {
   "platform": "wpengine",
   "install": "ascentialmisc",
   "environment": "development",
   "domain": "ascentialmisc.wpenginepowered.com",
   "siteurl": "https://ascentialmisc.wpenginepowered.com",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "genesis-block-theme",
   "updates": [
    {
     "plugin": "genesis-blocks",
     "status": "active",
     "active": true,
     "installed": "3.1.3",
     "available": "3.1.11",
     "priority": "P2",
     "vulns": [
      {
       "name": "Genesis Blocks [genesis-blocks] < 3.1.4",
       "cvss": "6.8",
       "severity": "MEDIUM",
       "cve": "CVE-2024-3901"
      },
      {
       "name": "Genesis Blocks [genesis-blocks] < 3.1.4",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-3563"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 3.1.3 -> 3.1.11"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "akismet",
     "status": "inactive",
     "active": false,
     "installed": "5.3.2",
     "available": "5.7.2",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.3.2 -> 5.7.2 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    }
   ],
   "p0": 0,
   "p1": 0,
   "total_updates": 2
  },
  "wpengine:wingsdevsite1": {
   "platform": "wpengine",
   "install": "wingsdevsite1",
   "environment": "production",
   "domain": "wingsdevsite1.wpenginepowered.com",
   "siteurl": "https://wingsdevsite1.wpenginepowered.com",
   "core": "7.0.3",
   "core_update": "7.0.4",
   "theme": "genesis-block-theme",
   "updates": [
    {
     "plugin": "genesis-blocks",
     "status": "active",
     "active": true,
     "installed": "3.1.3",
     "available": "3.1.11",
     "priority": "P2",
     "vulns": [
      {
       "name": "Genesis Blocks [genesis-blocks] < 3.1.4",
       "cvss": "6.8",
       "severity": "MEDIUM",
       "cve": "CVE-2024-3901"
      },
      {
       "name": "Genesis Blocks [genesis-blocks] < 3.1.4",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-3563"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 3.1.3 -> 3.1.11"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "akismet",
     "status": "inactive",
     "active": false,
     "installed": "5.3.1",
     "available": "5.7.2",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.3.1 -> 5.7.2 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    }
   ],
   "p0": 0,
   "p1": 0,
   "total_updates": 2
  },
  "wpengine:cimatprd": {
   "platform": "wpengine",
   "install": "cimatprd",
   "environment": "production",
   "domain": "www.cimat-balancing.com",
   "siteurl": "https://www.cimat-balancing.com",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "theme",
   "updates": [
    {
     "plugin": "gravityforms",
     "status": "inactive",
     "active": false,
     "installed": "2.9.31",
     "available": null,
     "priority": "P0",
     "vulns": [
      {
       "name": "Gravity Forms [gravityforms] < 2.10.1",
       "cvss": "9.6",
       "severity": "CRITICAL",
       "cve": "CVE-2026-48866"
      },
      {
       "name": "Gravity Forms [gravityforms] < 3.0.3",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2026-19513"
      },
      {
       "name": "Gravity Forms [gravityforms] < 2.10.5",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-12997"
      },
      {
       "name": "Gravity Forms [gravityforms] < 2.10.1",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-5111"
      }
     ],
     "vuln_count": 9,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "acf-to-rest-api",
     "status": "active",
     "active": true,
     "installed": "3.3.4",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "ACF to REST API [acf-to-rest-api] <= 3.3.4 (unfixed + closed)",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-62979"
      },
      {
       "name": "ACF to REST API [acf-to-rest-api] <= 3.3.4 (unfixed + closed)",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-12030"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "wp-migrate-db",
     "status": "active",
     "active": true,
     "installed": "2.7.7",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "WP Migrate Lite &#8211; Migration Made Easy [wp-migrate-db] < 2.7.9",
       "cvss": "4.7",
       "severity": "MEDIUM",
       "cve": "CVE-2026-49043"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "wordpress-seo",
     "status": "active",
     "active": true,
     "installed": "26.9",
     "available": "28.5",
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 27.2",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-3427"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 28.1",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-15425"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 26.9 -> 28.5 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "gutenberg",
     "status": "active",
     "active": true,
     "installed": "22.5.0",
     "available": "24.0.0",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 22.5.0 -> 24.0.0 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "advanced-custom-fields-pro",
     "status": "active",
     "active": true,
     "installed": "6.7.0.2",
     "available": "6.8.10",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "minor version bump 6.7.0.2 -> 6.8.10",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE WITH CAPTURE \u2014 routine bump but on a sitewide-impact plugin; watch the diff closely."
    },
    {
     "plugin": "amplifi-plugins",
     "status": "active",
     "active": true,
     "installed": "3.2.1",
     "available": "3.3.7",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 3.2.1 -> 3.3.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    }
   ],
   "p0": 1,
   "p1": 0,
   "total_updates": 4
  },
  "wpengine:b64dev": {
   "platform": "wpengine",
   "install": "b64dev",
   "environment": "production",
   "domain": "b64dev.wpenginepowered.com",
   "siteurl": "http://b64dev.wpenginepowered.com",
   "core": "7.0.3",
   "core_update": "7.0.4",
   "theme": "bootscore-child",
   "updates": [
    {
     "plugin": "wp-all-export-pro",
     "status": "active",
     "active": true,
     "installed": "1.9.1",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "WP ALL Export Pro [wp-all-export-pro] < 1.9.2",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2024-7419"
      },
      {
       "name": "WP ALL Export Pro [wp-all-export-pro] < 1.9.2",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2024-7425"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "wp-all-import-pro",
     "status": "active",
     "active": true,
     "installed": "4.9.0",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "WP All Import Pro [wp-all-import-pro] < 4.9.4",
       "cvss": "7.6",
       "severity": "HIGH",
       "cve": "CVE-2024-9624"
      },
      {
       "name": "WP All Import Pro [wp-all-import-pro] < 4.9.8",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2024-9664"
      },
      {
       "name": "WP All Import Pro [wp-all-import-pro] < 4.9.8",
       "cvss": "5.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-8722"
      },
      {
       "name": "WP All Import Pro [wp-all-import-pro] < 4.9.8",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2024-9661"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "advanced-custom-fields-pro",
     "status": "active",
     "active": true,
     "installed": "6.3.8",
     "available": "6.8.10",
     "priority": "P2",
     "vulns": [
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.3.9",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2024-49593"
      },
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.3.9",
       "cvss": null,
       "severity": null,
       "cve": ""
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "multi-minor jump 6.3.8 -> 6.8.10 (skipped 5 minor releases)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "query-monitor",
     "status": "active",
     "active": true,
     "installed": "3.16.4",
     "available": "4.0.7",
     "priority": "P2",
     "vulns": [
      {
       "name": "Query Monitor [query-monitor] < 3.20.4",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-4267"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.16.4 -> 4.0.7 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "simple-banner",
     "status": "active",
     "active": true,
     "installed": "3.0.3",
     "available": "3.3.2",
     "priority": "P2",
     "vulns": [
      {
       "name": "Simple Banner &#8211; Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website [simple-banner] < 3.0.5",
       "cvss": "4.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-13898"
      },
      {
       "name": "Simple Banner &#8211; Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website [simple-banner] < 3.1.0",
       "cvss": "4.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-12033"
      },
      {
       "name": "Simple Banner &#8211; Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website [simple-banner] < 3.0.4",
       "cvss": "3.5",
       "severity": "LOW",
       "cve": "CVE-2024-12769"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.0.3 -> 3.3.2 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "wordpress-seo",
     "status": "active",
     "active": true,
     "installed": "23.6",
     "available": "28.5",
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 26.6",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-14481"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 27.2",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-3427"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 26.9",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-1293"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 28.1",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-15425"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 23.6 -> 28.5 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "prevent-browser-caching",
     "status": "active",
     "active": true,
     "installed": "2.3.5",
     "available": "3.2.1",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.3.5 -> 3.2.1 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "wpae-acf-add-on",
     "status": "active",
     "active": true,
     "installed": "1.0.5",
     "available": "2.0.0",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 1.0.5 -> 2.0.0 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "wpai-acf-add-on",
     "status": "active",
     "active": true,
     "installed": "3.3.8",
     "available": "4.0.2",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.3.8 -> 4.0.2 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "megamenu",
     "status": "active",
     "active": true,
     "installed": "3.3.2",
     "available": "3.10.8",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.3.2 -> 3.10.8 (skipped 7 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    }
   ],
   "p0": 0,
   "p1": 2,
   "total_updates": 8
  },
  "wpengine:bepcoprd": {
   "platform": "wpengine",
   "install": "bepcoprd",
   "environment": "production",
   "domain": "bepcoprd.wpenginepowered.com",
   "siteurl": "https://bepcoprd.wpenginepowered.com",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "theme",
   "updates": [
    {
     "plugin": "advanced-custom-fields-pro",
     "status": "active",
     "active": true,
     "installed": "6.2.6.1",
     "available": "6.8.10",
     "priority": "P0",
     "vulns": [
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.2.10",
       "cvss": "9.9",
       "severity": "CRITICAL",
       "cve": "CVE-2024-34762"
      },
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.2.10",
       "cvss": "8.5",
       "severity": "HIGH",
       "cve": "CVE-2024-34761"
      },
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.3.8",
       "cvss": "6.6",
       "severity": "MEDIUM",
       "cve": "CVE-2024-9529"
      },
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.3.0",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-4565"
      }
     ],
     "vuln_count": 10,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "multi-minor jump 6.2.6.1 -> 6.8.10 (skipped 6 minor releases)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "gravityforms",
     "status": "active",
     "active": true,
     "installed": "2.8.9",
     "available": "3.1.1",
     "priority": "P0",
     "vulns": [
      {
       "name": "Gravity Forms [gravityforms] < 2.9.21",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2025-12352"
      },
      {
       "name": "Gravity Forms [gravityforms] < 2.10.1",
       "cvss": "9.6",
       "severity": "CRITICAL",
       "cve": "CVE-2026-48866"
      },
      {
       "name": "Gravity Forms [gravityforms] < 2.9.22",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2025-12974"
      },
      {
       "name": "Gravity Forms [gravityforms] < 3.0.3",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2026-19513"
      }
     ],
     "vuln_count": 17,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.8.9 -> 3.1.1 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "translatepress-multilingual",
     "status": "active",
     "active": true,
     "installed": "2.7.6",
     "available": "3.3.6",
     "priority": "P0",
     "vulns": [
      {
       "name": "TranslatePress &#8211; Translate Multilingual sites with AI Translation [translatepress-multilingual] < 3.3.3",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2026-78267"
      },
      {
       "name": "TranslatePress &#8211; Translate Multilingual sites with AI Translation [translatepress-multilingual] < 3.3.2",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2026-19632"
      },
      {
       "name": "TranslatePress &#8211; Translate Multilingual sites with AI Translation [translatepress-multilingual] < 2.10.3",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2025-58592"
      },
      {
       "name": "TranslatePress &#8211; Translate Multilingual sites with AI Translation [translatepress-multilingual] < 3.3",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-18510"
      }
     ],
     "vuln_count": 10,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.7.6 -> 3.3.6 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "popup-maker",
     "status": "active",
     "active": true,
     "installed": "1.18.5",
     "available": "1.25.0",
     "priority": "P1",
     "vulns": [
      {
       "name": "Popup Maker &#8211; Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.23.0",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-8848"
      },
      {
       "name": "Popup Maker &#8211; Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.24.0",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-28177"
      },
      {
       "name": "Popup Maker &#8211; Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.20.3",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-24746"
      },
      {
       "name": "Popup Maker &#8211; Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.20.5",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-4205"
      }
     ],
     "vuln_count": 9,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 1.18.5 -> 1.25.0 (skipped 7 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "wp-smushit",
     "status": "active",
     "active": true,
     "installed": "3.16.2",
     "available": "4.3.3",
     "priority": "P1",
     "vulns": [
      {
       "name": "Smush \u2013 Image Optimization, Compression, Lazy Load, WebP &amp; CDN [wp-smushit] < 4.3.0",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-81285"
      },
      {
       "name": "Smush \u2013 Image Optimization, Compression, Lazy Load, WebP &amp; CDN [wp-smushit] < 3.16.5",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2023-3352"
      },
      {
       "name": "Smush \u2013 Image Optimization, Compression, Lazy Load, WebP &amp; CDN [wp-smushit] < 3.17.1",
       "cvss": "4.1",
       "severity": "MEDIUM",
       "cve": "CVE-2025-22288"
      },
      {
       "name": "Smush \u2013 Image Optimization, Compression, Lazy Load, WebP &amp; CDN [wp-smushit] < 4.3.2",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-19223"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.16.2 -> 4.3.3 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "wordpress-importer",
     "status": "active",
     "active": true,
     "installed": "0.8.2",
     "available": "0.9.6",
     "priority": "P1",
     "vulns": [
      {
       "name": "WordPress Importer [wordpress-importer] < 0.8.4",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2024-13889"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 0.8.2 -> 0.9.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "insert-headers-and-footers",
     "status": "inactive",
     "active": false,
     "installed": "2.1.12",
     "available": "2.3.9",
     "priority": "P1",
     "vulns": [
      {
       "name": "WPCode &#8211; Insert Headers and Footers + Custom Code Snippets &#8211; WordPress Code Manager [insert-headers-and-footers] < 2.3.6",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-8832"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.1.12 -> 2.3.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "acf-to-rest-api",
     "status": "active",
     "active": true,
     "installed": "3.3.3",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "ACF to REST API [acf-to-rest-api] <= 3.3.4 (unfixed + closed)",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-62979"
      },
      {
       "name": "ACF to REST API [acf-to-rest-api] <= 3.3.4 (unfixed + closed)",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-12030"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "wp-mail-smtp",
     "status": "active",
     "active": true,
     "installed": "4.0.1",
     "available": "4.9.0",
     "priority": "P2",
     "vulns": [
      {
       "name": "WP Mail SMTP by WPForms &#8211; The Most Popular SMTP and Email Log Plugin [wp-mail-smtp] < 4.1.0",
       "cvss": "2.7",
       "severity": "LOW",
       "cve": "CVE-2024-6694"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 4.0.1 -> 4.9.0 (skipped 9 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "duplicate-post",
     "status": "active",
     "active": true,
     "installed": "4.5",
     "available": "4.7",
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast Duplicate Post [duplicate-post] <= 4.6 (unfixed)",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-53740"
      },
      {
       "name": "Yoast Duplicate Post [duplicate-post] <= 4.6 (unfixed)",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-53739"
      },
      {
       "name": "Yoast Duplicate Post [duplicate-post] < 4.6",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-1217"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 4.5 -> 4.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "better-wp-security",
     "status": "active",
     "active": true,
     "installed": "9.3.2",
     "available": "10.0.3",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 9.3.2 -> 10.0.3 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "akismet",
     "status": "active",
     "active": true,
     "installed": "5.3.2",
     "available": "5.7.2",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.3.2 -> 5.7.2 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "force-regenerate-thumbnails",
     "status": "active",
     "active": true,
     "installed": "2.1.4",
     "available": "2.3.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.1.4 -> 2.3.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "redirection",
     "status": "active",
     "active": true,
     "installed": "5.4.2",
     "available": "5.10.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.4.2 -> 5.10.0 (skipped 6 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "simple-page-ordering",
     "status": "active",
     "active": true,
     "installed": "2.7.0",
     "available": "2.8.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.7.0 -> 2.8.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "autodescription",
     "status": "active",
     "active": true,
     "installed": "5.0.6",
     "available": "5.1.4",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 5.0.6 -> 5.1.4"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    }
   ],
   "p0": 3,
   "p1": 4,
   "total_updates": 15
  },
  "wpengine:ascentialsec1": {
   "platform": "wpengine",
   "install": "ascentialsec1",
   "environment": "production",
   "domain": "ascentialsec1.wpenginepowered.com",
   "siteurl": "https://ascentialsec1.wpenginepowered.com",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "genesis-block-theme",
   "updates": [
    {
     "plugin": "genesis-blocks",
     "status": "active",
     "active": true,
     "installed": "3.1.5",
     "available": "3.1.11",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 3.1.5 -> 3.1.11"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "akismet",
     "status": "inactive",
     "active": false,
     "installed": "5.3.2",
     "available": "5.7.2",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.3.2 -> 5.7.2 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    }
   ],
   "p0": 0,
   "p1": 0,
   "total_updates": 2
  },
  "wpengine:mhlandingpages": {
   "platform": "wpengine",
   "install": "mhlandingpages",
   "environment": "development",
   "domain": "mhlandingpages.wpenginepowered.com",
   "siteurl": "http://mhlandingpages.wpenginepowered.com",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "bootscore-child",
   "updates": [
    {
     "plugin": "insert-headers-and-footers",
     "status": "active",
     "active": true,
     "installed": "2.2.0",
     "available": "2.3.9",
     "priority": "P1",
     "vulns": [
      {
       "name": "WPCode &#8211; Insert Headers and Footers + Custom Code Snippets &#8211; WordPress Code Manager [insert-headers-and-footers] < 2.3.6",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-8832"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.2.0 -> 2.3.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "advanced-custom-fields-pro",
     "status": "active",
     "active": true,
     "installed": "6.3.4",
     "available": "6.8.10",
     "priority": "P2",
     "vulns": [
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.3.8",
       "cvss": "6.6",
       "severity": "MEDIUM",
       "cve": "CVE-2024-9529"
      },
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.3.6",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2024-45429"
      },
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.3.9",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2024-49593"
      },
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.3.9",
       "cvss": null,
       "severity": null,
       "cve": ""
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "multi-minor jump 6.3.4 -> 6.8.10 (skipped 5 minor releases)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "duplicate-page",
     "status": "active",
     "active": true,
     "installed": "4.5.3",
     "available": "4.5.9",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 4.5.3 -> 4.5.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "simply-static",
     "status": "active",
     "active": true,
     "installed": "3.1.7.4",
     "available": "3.8.13",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.1.7.4 -> 3.8.13 (skipped 7 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    }
   ],
   "p0": 0,
   "p1": 1,
   "total_updates": 4
  },
  "wpengine:norwestdev1": {
   "platform": "wpengine",
   "install": "norwestdev1",
   "environment": "production",
   "domain": "norwestdev1.wpenginepowered.com",
   "siteurl": "https://norwestdev1.wpenginepowered.com",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "brand-nav-child-theme",
   "updates": [
    {
     "plugin": "ewww-image-optimizer",
     "status": "active",
     "active": true,
     "installed": "8.7.5",
     "available": "8.7.7",
     "priority": "P1",
     "vulns": [
      {
       "name": "EWWW Image Optimizer [ewww-image-optimizer] < 8.7.7",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-84773"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 8.7.5 -> 8.7.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "one-user-avatar",
     "status": "active",
     "active": true,
     "installed": "2.5.4",
     "available": "2.5.6",
     "priority": "P1",
     "vulns": [
      {
       "name": "One User Avatar | User Profile Picture [one-user-avatar] < 2.5.5",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-18983"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 2.5.4 -> 2.5.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "revslider",
     "status": "active",
     "active": true,
     "installed": "6.7.18",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "Slider Revolution [revslider] < 7.0.11",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-6692"
      },
      {
       "name": "Slider Revolution [revslider] < 7.1.0",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-57678"
      },
      {
       "name": "Slider Revolution [revslider] < 6.7.37",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-9217"
      },
      {
       "name": "Slider Revolution [revslider] < 6.7.38",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-10249"
      }
     ],
     "vuln_count": 9,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "search-filter-pro",
     "status": "active",
     "active": true,
     "installed": "2.5.14",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Search & Filter Pro [search-filter-pro] < 2.5.18",
       "cvss": "4.8",
       "severity": "MEDIUM",
       "cve": "CVE-2024-6481"
      },
      {
       "name": "Search & Filter Pro [search-filter-pro] < 2.5.20",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-1528"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "simple-cloudflare-turnstile",
     "status": "active",
     "active": true,
     "installed": "1.42.1",
     "available": "1.43.1",
     "priority": "P2",
     "vulns": [
      {
       "name": "Simple CAPTCHA with Cloudflare Turnstile [simple-cloudflare-turnstile] < 1.42.3",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-66632"
      },
      {
       "name": "Simple CAPTCHA with Cloudflare Turnstile [simple-cloudflare-turnstile] < 1.42.3",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-85116"
      },
      {
       "name": "Simple CAPTCHA with Cloudflare Turnstile [simple-cloudflare-turnstile] < 1.42.3",
       "cvss": "5.6",
       "severity": "MEDIUM",
       "cve": "CVE-2026-66674"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.42.1 -> 1.43.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "wordpress-seo-premium",
     "status": "active",
     "active": true,
     "installed": "24.8",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast SEO Premium [wordpress-seo-premium] < 27.6.1",
       "cvss": "6.6",
       "severity": "MEDIUM",
       "cve": "CVE-2026-10821"
      },
      {
       "name": "Yoast SEO Premium [wordpress-seo-premium] < 26.7",
       "cvss": "5.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-40722"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "metasync",
     "status": "inactive",
     "active": false,
     "installed": "2.6.22",
     "available": "2.6.26",
     "priority": "P2",
     "vulns": [
      {
       "name": "Search Atlas SEO &#8211; OTTO AI SEO Automation for WordPress [metasync] < 2.6.24",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-15247"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 2.6.22 -> 2.6.26"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "admin-site-enhancements",
     "status": "active",
     "active": true,
     "installed": "9.0.1",
     "available": "9.1.2",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 9.0.1 -> 9.1.2"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "advanced-custom-fields-pro",
     "status": "active",
     "active": true,
     "installed": "6.8.3",
     "available": "6.8.10",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "patch bump 6.8.3 -> 6.8.10",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE WITH CAPTURE \u2014 routine bump but on a sitewide-impact plugin; watch the diff closely."
    },
    {
     "plugin": "tinymce-advanced",
     "status": "active",
     "active": true,
     "installed": "5.9.2",
     "available": "5.10.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 5.9.2 -> 5.10.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "am-lottieplayer",
     "status": "active",
     "active": true,
     "installed": "4.0.0",
     "available": "4.1.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 4.0.0 -> 4.1.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "amplifi-plugins",
     "status": "active",
     "active": true,
     "installed": "3.3.2",
     "available": "3.3.7",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 3.3.2 -> 3.3.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "cookie-law-info",
     "status": "active",
     "active": true,
     "installed": "3.5.4",
     "available": "3.5.6",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 3.5.4 -> 3.5.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "dynamic-content-for-elementor",
     "status": "active",
     "active": true,
     "installed": "3.4.12",
     "available": "3.4.13",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "patch bump 3.4.12 -> 3.4.13",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE WITH CAPTURE \u2014 routine bump but on a sitewide-impact plugin; watch the diff closely."
    },
    {
     "plugin": "elementor",
     "status": "active",
     "active": true,
     "installed": "4.2.3",
     "available": "4.2.4",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "patch bump 4.2.3 -> 4.2.4",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE WITH CAPTURE \u2014 routine bump but on a sitewide-impact plugin; watch the diff closely."
    },
    {
     "plugin": "elementor-pro",
     "status": "active",
     "active": true,
     "installed": "4.2.2",
     "available": "4.2.3",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "patch bump 4.2.2 -> 4.2.3",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE WITH CAPTURE \u2014 routine bump but on a sitewide-impact plugin; watch the diff closely."
    },
    {
     "plugin": "headers-security-advanced-hsts-wp",
     "status": "active",
     "active": true,
     "installed": "5.3.4",
     "available": "5.3.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 5.3.4 -> 5.3.5"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "mainwp-child",
     "status": "active",
     "active": true,
     "installed": "6.1.7",
     "available": "6.2",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 6.1.7 -> 6.2"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "search-exclude",
     "status": "active",
     "active": true,
     "installed": "2.6.5",
     "available": "2.6.6",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 2.6.5 -> 2.6.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "simple-banner",
     "status": "active",
     "active": true,
     "installed": "3.3.1",
     "available": "3.3.2",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 3.3.1 -> 3.3.2"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wp-security-audit-log",
     "status": "active",
     "active": true,
     "installed": "5.6.5",
     "available": "5.6.6",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 5.6.5 -> 5.6.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "insert-headers-and-footers",
     "status": "active",
     "active": true,
     "installed": "2.3.8",
     "available": "2.3.9",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 2.3.8 -> 2.3.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wordpress-seo",
     "status": "active",
     "active": true,
     "installed": "28.3",
     "available": "28.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "minor version bump 28.3 -> 28.5",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE WITH CAPTURE \u2014 routine bump but on a sitewide-impact plugin; watch the diff closely."
    },
    {
     "plugin": "melapress-login-security",
     "status": "inactive",
     "active": false,
     "installed": "2.3.0",
     "available": "2.4.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.3.0 -> 2.4.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "simply-static",
     "status": "inactive",
     "active": false,
     "installed": "3.8.11",
     "available": "3.8.13",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 3.8.11 -> 3.8.13"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    }
   ],
   "p0": 0,
   "p1": 3,
   "total_updates": 22
  },
  "wpengine:epicprd": {
   "platform": "wpengine",
   "install": "epicprd",
   "environment": "production",
   "domain": "epicprd.wpenginepowered.com",
   "siteurl": "https://epicprd.wpenginepowered.com",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "theme",
   "updates": [
    {
     "plugin": "advanced-custom-fields-pro",
     "status": "active",
     "active": true,
     "installed": "6.2.6.1",
     "available": "6.8.10",
     "priority": "P0",
     "vulns": [
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.2.10",
       "cvss": "9.9",
       "severity": "CRITICAL",
       "cve": "CVE-2024-34762"
      },
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.2.10",
       "cvss": "8.5",
       "severity": "HIGH",
       "cve": "CVE-2024-34761"
      },
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.3.8",
       "cvss": "6.6",
       "severity": "MEDIUM",
       "cve": "CVE-2024-9529"
      },
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.3.0",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-4565"
      }
     ],
     "vuln_count": 10,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "multi-minor jump 6.2.6.1 -> 6.8.10 (skipped 6 minor releases)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "gravityforms",
     "status": "active",
     "active": true,
     "installed": "2.8.9",
     "available": "3.1.1",
     "priority": "P0",
     "vulns": [
      {
       "name": "Gravity Forms [gravityforms] < 2.9.21",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2025-12352"
      },
      {
       "name": "Gravity Forms [gravityforms] < 2.10.1",
       "cvss": "9.6",
       "severity": "CRITICAL",
       "cve": "CVE-2026-48866"
      },
      {
       "name": "Gravity Forms [gravityforms] < 2.9.22",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2025-12974"
      },
      {
       "name": "Gravity Forms [gravityforms] < 3.0.3",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2026-19513"
      }
     ],
     "vuln_count": 17,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.8.9 -> 3.1.1 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "translatepress-multilingual",
     "status": "active",
     "active": true,
     "installed": "2.7.6",
     "available": "3.3.6",
     "priority": "P0",
     "vulns": [
      {
       "name": "TranslatePress &#8211; Translate Multilingual sites with AI Translation [translatepress-multilingual] < 3.3.3",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2026-78267"
      },
      {
       "name": "TranslatePress &#8211; Translate Multilingual sites with AI Translation [translatepress-multilingual] < 3.3.2",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2026-19632"
      },
      {
       "name": "TranslatePress &#8211; Translate Multilingual sites with AI Translation [translatepress-multilingual] < 2.10.3",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2025-58592"
      },
      {
       "name": "TranslatePress &#8211; Translate Multilingual sites with AI Translation [translatepress-multilingual] < 3.3",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-18510"
      }
     ],
     "vuln_count": 10,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.7.6 -> 3.3.6 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "popup-maker",
     "status": "active",
     "active": true,
     "installed": "1.18.5",
     "available": "1.25.0",
     "priority": "P1",
     "vulns": [
      {
       "name": "Popup Maker &#8211; Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.23.0",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-8848"
      },
      {
       "name": "Popup Maker &#8211; Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.24.0",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-28177"
      },
      {
       "name": "Popup Maker &#8211; Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.20.3",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-24746"
      },
      {
       "name": "Popup Maker &#8211; Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.20.5",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-4205"
      }
     ],
     "vuln_count": 9,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 1.18.5 -> 1.25.0 (skipped 7 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "wp-smushit",
     "status": "active",
     "active": true,
     "installed": "3.16.2",
     "available": "4.3.3",
     "priority": "P1",
     "vulns": [
      {
       "name": "Smush \u2013 Image Optimization, Compression, Lazy Load, WebP &amp; CDN [wp-smushit] < 4.3.0",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-81285"
      },
      {
       "name": "Smush \u2013 Image Optimization, Compression, Lazy Load, WebP &amp; CDN [wp-smushit] < 3.16.5",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2023-3352"
      },
      {
       "name": "Smush \u2013 Image Optimization, Compression, Lazy Load, WebP &amp; CDN [wp-smushit] < 3.17.1",
       "cvss": "4.1",
       "severity": "MEDIUM",
       "cve": "CVE-2025-22288"
      },
      {
       "name": "Smush \u2013 Image Optimization, Compression, Lazy Load, WebP &amp; CDN [wp-smushit] < 4.3.2",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-19223"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.16.2 -> 4.3.3 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "wordpress-importer",
     "status": "active",
     "active": true,
     "installed": "0.8.2",
     "available": "0.9.6",
     "priority": "P1",
     "vulns": [
      {
       "name": "WordPress Importer [wordpress-importer] < 0.8.4",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2024-13889"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 0.8.2 -> 0.9.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "insert-headers-and-footers",
     "status": "inactive",
     "active": false,
     "installed": "2.1.12",
     "available": "2.3.9",
     "priority": "P1",
     "vulns": [
      {
       "name": "WPCode &#8211; Insert Headers and Footers + Custom Code Snippets &#8211; WordPress Code Manager [insert-headers-and-footers] < 2.3.6",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-8832"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.1.12 -> 2.3.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "acf-to-rest-api",
     "status": "active",
     "active": true,
     "installed": "3.3.3",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "ACF to REST API [acf-to-rest-api] <= 3.3.4 (unfixed + closed)",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-62979"
      },
      {
       "name": "ACF to REST API [acf-to-rest-api] <= 3.3.4 (unfixed + closed)",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-12030"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "wp-mail-smtp",
     "status": "active",
     "active": true,
     "installed": "4.0.1",
     "available": "4.9.0",
     "priority": "P2",
     "vulns": [
      {
       "name": "WP Mail SMTP by WPForms &#8211; The Most Popular SMTP and Email Log Plugin [wp-mail-smtp] < 4.1.0",
       "cvss": "2.7",
       "severity": "LOW",
       "cve": "CVE-2024-6694"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 4.0.1 -> 4.9.0 (skipped 9 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "duplicate-post",
     "status": "active",
     "active": true,
     "installed": "4.5",
     "available": "4.7",
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast Duplicate Post [duplicate-post] <= 4.6 (unfixed)",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-53740"
      },
      {
       "name": "Yoast Duplicate Post [duplicate-post] <= 4.6 (unfixed)",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-53739"
      },
      {
       "name": "Yoast Duplicate Post [duplicate-post] < 4.6",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-1217"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 4.5 -> 4.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "better-wp-security",
     "status": "active",
     "active": true,
     "installed": "9.3.2",
     "available": "10.0.3",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 9.3.2 -> 10.0.3 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "akismet",
     "status": "active",
     "active": true,
     "installed": "5.3.2",
     "available": "5.7.2",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.3.2 -> 5.7.2 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "force-regenerate-thumbnails",
     "status": "active",
     "active": true,
     "installed": "2.1.4",
     "available": "2.3.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.1.4 -> 2.3.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "redirection",
     "status": "active",
     "active": true,
     "installed": "5.4.2",
     "available": "5.10.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.4.2 -> 5.10.0 (skipped 6 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "simple-page-ordering",
     "status": "active",
     "active": true,
     "installed": "2.7.0",
     "available": "2.8.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.7.0 -> 2.8.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "autodescription",
     "status": "active",
     "active": true,
     "installed": "5.0.6",
     "available": "5.1.4",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 5.0.6 -> 5.1.4"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    }
   ],
   "p0": 3,
   "p1": 4,
   "total_updates": 15
  },
  "wpengine:ascentialdev2": {
   "platform": "wpengine",
   "install": "ascentialdev2",
   "environment": "staging",
   "domain": "ascentialdev2.wpenginepowered.com",
   "siteurl": "https://ascentialdev2.wpenginepowered.com",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "hello-ascential",
   "updates": [
    {
     "plugin": "elementor-pro",
     "status": "active",
     "active": true,
     "installed": "3.25.2",
     "available": "3.25.4",
     "priority": "P0",
     "vulns": [
      {
       "name": "Elementor Pro [elementor-pro] < 4.2.2",
       "cvss": "9.0",
       "severity": "CRITICAL",
       "cve": "CVE-2026-32475"
      },
      {
       "name": "Elementor Pro [elementor-pro] < 3.25.11",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-8494"
      },
      {
       "name": "Elementor Pro [elementor-pro] < 3.29.1",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-50555"
      },
      {
       "name": "Elementor Pro [elementor-pro] < 3.29.1",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-3076"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "patch bump 3.25.2 -> 3.25.4",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "hide-my-wp",
     "status": "inactive",
     "active": false,
     "installed": "5.3.01",
     "available": "7.0.11",
     "priority": "P0",
     "vulns": [
      {
       "name": "Hide My WP Ghost &#8211; Security &amp; Firewall [hide-my-wp] < 5.4.02",
       "cvss": "9.6",
       "severity": "CRITICAL",
       "cve": "CVE-2025-26909"
      },
      {
       "name": "Hide My WP Ghost &#8211; Security &amp; Firewall [hide-my-wp] < 5.4.02",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2025-2056"
      },
      {
       "name": "Hide My WP Ghost &#8211; Security &amp; Firewall [hide-my-wp] < 7.0.10",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-81806"
      },
      {
       "name": "Hide My WP Ghost &#8211; Security &amp; Firewall [hide-my-wp] <= 6.2.12 (unfixed)",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2025-69098"
      }
     ],
     "vuln_count": 9,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 5.3.01 -> 7.0.11 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "alttext-ai",
     "status": "active",
     "active": true,
     "installed": "1.9.0",
     "available": "1.10.38",
     "priority": "P1",
     "vulns": [
      {
       "name": "Alt Text AI &#8211; Automatically generate image alt text for SEO and accessibility [alttext-ai] < 1.9.94",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2025-46232"
      },
      {
       "name": "Alt Text AI &#8211; Automatically generate image alt text for SEO and accessibility [alttext-ai] < 1.10.18",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-25348"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.9.0 -> 1.10.38"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "jet-menu",
     "status": "active",
     "active": true,
     "installed": "2.4.4",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "JetMenu [jet-menu] < 2.4.9.1",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2025-26953"
      },
      {
       "name": "JetMenu [jet-menu] < 2.4.11.2",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-53987"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "link-whisper",
     "status": "active",
     "active": true,
     "installed": "0.7.7",
     "available": "0.9.7",
     "priority": "P1",
     "vulns": [
      {
       "name": "Link Whisper Free [link-whisper] < 0.9.1",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2025-11262"
      },
      {
       "name": "Link Whisper Free [link-whisper] < 0.8.9",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2025-67927"
      },
      {
       "name": "Link Whisper Free [link-whisper] < 0.9.3",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-22357"
      },
      {
       "name": "Link Whisper Free [link-whisper] < 0.9.5",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-57333"
      }
     ],
     "vuln_count": 9,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 0.7.7 -> 0.9.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "mainwp-child",
     "status": "active",
     "active": true,
     "installed": "5.2",
     "available": "6.2",
     "priority": "P1",
     "vulns": [
      {
       "name": "MainWP Child &#8211; Securely Connects to the MainWP Dashboard to Manage Multiple Sites [mainwp-child] < 5.3.4",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2024-10783"
      },
      {
       "name": "MainWP Child &#8211; Securely Connects to the MainWP Dashboard to Manage Multiple Sites [mainwp-child] < 6.1.2",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-27366"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 5.2 -> 6.2 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "shortpixel-image-optimiser",
     "status": "active",
     "active": true,
     "installed": "5.6.4",
     "available": "6.5.6",
     "priority": "P1",
     "vulns": [
      {
       "name": "ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 6.4.4",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-39471"
      },
      {
       "name": "ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 6.3.5",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-11378"
      },
      {
       "name": "ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 6.4.4",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-4335"
      },
      {
       "name": "ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 6.4.3",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-1246"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 5.6.4 -> 6.5.6 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "simple-download-monitor",
     "status": "active",
     "active": true,
     "installed": "3.9.25",
     "available": "4.1.1",
     "priority": "P1",
     "vulns": [
      {
       "name": "Simple Download Monitor [simple-download-monitor] < 3.9.26",
       "cvss": "7.6",
       "severity": "HIGH",
       "cve": "CVE-2025-24663"
      },
      {
       "name": "Simple Download Monitor [simple-download-monitor] < 3.9.35",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-58197"
      },
      {
       "name": "Simple Download Monitor [simple-download-monitor] < 3.9.34",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-8977"
      },
      {
       "name": "Simple Download Monitor [simple-download-monitor] < 4.0.6",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-2383"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.9.25 -> 4.1.1 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "revslider",
     "status": "active",
     "active": true,
     "installed": "6.7.18",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "Slider Revolution [revslider] < 7.0.11",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-6692"
      },
      {
       "name": "Slider Revolution [revslider] < 7.1.0",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-57678"
      },
      {
       "name": "Slider Revolution [revslider] < 6.7.37",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-9217"
      },
      {
       "name": "Slider Revolution [revslider] < 6.7.38",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-10249"
      }
     ],
     "vuln_count": 9,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "updraftplus",
     "status": "active",
     "active": true,
     "installed": "1.24.6",
     "available": "1.26.7",
     "priority": "P1",
     "vulns": [
      {
       "name": "UpdraftPlus: WP Backup &amp; Migration Plugin [updraftplus] < 1.24.12",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2024-10957"
      },
      {
       "name": "UpdraftPlus: WP Backup &amp; Migration Plugin [updraftplus] < 1.26.5",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2026-10795"
      },
      {
       "name": "UpdraftPlus: WP Backup &amp; Migration Plugin [updraftplus] < 1.25.1",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2025-0215"
      },
      {
       "name": "UpdraftPlus: WP Backup &amp; Migration Plugin [updraftplus] < 1.26.7",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-76549"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "minor version bump 1.24.6 -> 1.26.7",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "wp-optimize",
     "status": "active",
     "active": true,
     "installed": "3.7.0",
     "available": "4.6.1",
     "priority": "P1",
     "vulns": [
      {
       "name": "WP-Optimize \u2013 Cache, Compress images, Minify &amp; Clean database to boost page speed &amp; performance [wp-optimize] < 4.5.3",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2026-7252"
      },
      {
       "name": "WP-Optimize \u2013 Cache, Compress images, Minify &amp; Clean database to boost page speed &amp; performance [wp-optimize] < 4.2.0",
       "cvss": "4.1",
       "severity": "MEDIUM",
       "cve": "CVE-2025-3951"
      },
      {
       "name": "WP-Optimize \u2013 Cache, Compress images, Minify &amp; Clean database to boost page speed &amp; performance [wp-optimize] < 4.5.1",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-2712"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.7.0 -> 4.6.1 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "wp-all-import-pro",
     "status": "active",
     "active": true,
     "installed": "4.9.3",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "WP All Import Pro [wp-all-import-pro] < 4.9.4",
       "cvss": "7.6",
       "severity": "HIGH",
       "cve": "CVE-2024-9624"
      },
      {
       "name": "WP All Import Pro [wp-all-import-pro] < 4.9.8",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2024-9664"
      },
      {
       "name": "WP All Import Pro [wp-all-import-pro] < 4.9.8",
       "cvss": "5.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-8722"
      },
      {
       "name": "WP All Import Pro [wp-all-import-pro] < 4.9.8",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2024-9661"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "insert-headers-and-footers",
     "status": "active",
     "active": true,
     "installed": "2.2.3",
     "available": "2.3.9",
     "priority": "P1",
     "vulns": [
      {
       "name": "WPCode &#8211; Insert Headers and Footers + Custom Code Snippets &#8211; WordPress Code Manager [insert-headers-and-footers] < 2.3.6",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-8832"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.2.3 -> 2.3.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "wpide",
     "status": "active",
     "active": true,
     "installed": "3.5.0",
     "available": "3.5.9",
     "priority": "P1",
     "vulns": [
      {
       "name": "WPIDE &#8211; File Manager &amp; Code Editor [wpide] < 3.5.7",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-57766"
      },
      {
       "name": "WPIDE &#8211; File Manager &amp; Code Editor [wpide] < 3.5.8",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-66440"
      },
      {
       "name": "WPIDE &#8211; File Manager &amp; Code Editor [wpide] < 3.5.2",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2024-13362"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 3.5.0 -> 3.5.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "debug-log-manager",
     "status": "inactive",
     "active": false,
     "installed": "2.3.3",
     "available": "2.5.2",
     "priority": "P1",
     "vulns": [
      {
       "name": "Debug Log Manager &#8211; Conveniently Monitor and Inspect Errors [debug-log-manager] < 2.3.5",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2025-3809"
      },
      {
       "name": "Debug Log Manager &#8211; Conveniently Monitor and Inspect Errors [debug-log-manager] < 2.5.1",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-9016"
      },
      {
       "name": "Debug Log Manager &#8211; Conveniently Monitor and Inspect Errors [debug-log-manager] < 2.3.5",
       "cvss": "0.0",
       "severity": null,
       "cve": "CVE-2025-32613"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.3.3 -> 2.5.2"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "nitropack",
     "status": "inactive",
     "active": false,
     "installed": "1.17.2",
     "available": "1.20.0",
     "priority": "P1",
     "vulns": [
      {
       "name": "NitroPack \u2013 Performance, Page Speed &amp; Cache Plugin for Core Web Vitals, CDN &amp; Image Optimization [nitropack] < 1.17.6",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2024-11848"
      },
      {
       "name": "NitroPack \u2013 Performance, Page Speed &amp; Cache Plugin for Core Web Vitals, CDN &amp; Image Optimization [nitropack] < 1.19.4",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-39669"
      },
      {
       "name": "NitroPack \u2013 Performance, Page Speed &amp; Cache Plugin for Core Web Vitals, CDN &amp; Image Optimization [nitropack] < 1.17.6",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2024-11851"
      },
      {
       "name": "NitroPack \u2013 Performance, Page Speed &amp; Cache Plugin for Core Web Vitals, CDN &amp; Image Optimization [nitropack] < 1.18.5",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2025-8778"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 1.17.2 -> 1.20.0 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wp-hide-security-enhancer",
     "status": "inactive",
     "active": false,
     "installed": "2.4.7",
     "available": "2.9.1",
     "priority": "P1",
     "vulns": [
      {
       "name": "WP Hide &amp; Security Enhancer [wp-hide-security-enhancer] < 2.5.2",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2024-11585"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 2.4.7 -> 2.9.1 (skipped 5 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "dracula-dark-mode",
     "status": "active",
     "active": true,
     "installed": "1.2.4",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Dracula Dark Mode \u2013  Accessibility, Reading Mode &amp; Dark Mode for WordPress [dracula-dark-mode] < 1.2.8 (closed)",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2024-13362"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "elementor",
     "status": "active",
     "active": true,
     "installed": "3.25.3",
     "available": "4.2.4",
     "priority": "P2",
     "vulns": [
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.25.11",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-54444"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.29.1",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-50555"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.35.6",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-32352"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 4.1.4",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-57619"
      }
     ],
     "vuln_count": 18,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.25.3 -> 4.2.4 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "goal-tracker-ga",
     "status": "active",
     "active": true,
     "installed": "1.1.4",
     "available": "1.1.6",
     "priority": "P2",
     "vulns": [
      {
       "name": "Goal Tracker &#8211; Custom Event Tracking for GA4 [goal-tracker-ga] < 1.1.6",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2024-13362"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.1.4 -> 1.1.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "limit-login-attempts-reloaded",
     "status": "active",
     "active": true,
     "installed": "2.26.14",
     "available": "3.3.8",
     "priority": "P2",
     "vulns": [
      {
       "name": "Limit Login Attempts Security &#8211; Login Security, 2FA, Firewall, Brute Force Prevention [limit-login-attempts-reloaded] < 3.3.5",
       "cvss": "3.7",
       "severity": "LOW",
       "cve": "CVE-2026-18356"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.26.14 -> 3.3.8 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "query-monitor",
     "status": "active",
     "active": true,
     "installed": "3.16.4",
     "available": "4.0.7",
     "priority": "P2",
     "vulns": [
      {
       "name": "Query Monitor [query-monitor] < 3.20.4",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-4267"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.16.4 -> 4.0.7 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "search-filter-pro",
     "status": "active",
     "active": true,
     "installed": "2.5.19",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Search & Filter Pro [search-filter-pro] < 2.5.20",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-1528"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "smtp2go",
     "status": "active",
     "active": true,
     "installed": "1.10.0",
     "available": "1.17.1",
     "priority": "P2",
     "vulns": [
      {
       "name": "SMTP2GO for WordPress &#8211; Email Made Easy [smtp2go] < 1.12.2",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-54011"
      },
      {
       "name": "SMTP2GO for WordPress &#8211; Email Made Easy [smtp2go] < 1.17.0",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-7621"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 1.10.0 -> 1.17.1 (skipped 7 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "sucuri-scanner",
     "status": "active",
     "active": true,
     "installed": "1.9.6",
     "available": "2.8",
     "priority": "P2",
     "vulns": [
      {
       "name": "Sucuri Security &#8211; Auditing, Malware Scanner and Security Hardening [sucuri-scanner] <= 2.7.3 (unfixed)",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-73033"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 1.9.6 -> 2.8 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "svg-support",
     "status": "active",
     "active": true,
     "installed": "2.5.8",
     "available": "2.6.1",
     "priority": "P2",
     "vulns": [
      {
       "name": "SVG Support [svg-support] < 2.5.11",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-10222"
      },
      {
       "name": "SVG Support [svg-support] < 2.5.9",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2022-23638"
      },
      {
       "name": "SVG Support [svg-support] < 2.5.15",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-48973"
      },
      {
       "name": "SVG Support [svg-support] < 2.5.17",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-13340"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.5.8 -> 2.6.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "wordpress-seo",
     "status": "active",
     "active": true,
     "installed": "23.7",
     "available": "28.5",
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 26.6",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-14481"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 27.2",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-3427"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 26.9",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-1293"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 28.1",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-15425"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 23.7 -> 28.5 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "wordpress-seo-premium",
     "status": "active",
     "active": true,
     "installed": "23.4",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast SEO Premium [wordpress-seo-premium] < 27.6.1",
       "cvss": "6.6",
       "severity": "MEDIUM",
       "cve": "CVE-2026-10821"
      },
      {
       "name": "Yoast SEO Premium [wordpress-seo-premium] < 26.7",
       "cvss": "5.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-40722"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "agile-store-locator",
     "status": "active",
     "active": true,
     "installed": "4.10.13",
     "available": "5.4.6",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 4.10.13 -> 5.4.6 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "font-awesome",
     "status": "active",
     "active": true,
     "installed": "4.5.0",
     "available": "5.2.1",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 4.5.0 -> 5.2.1 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "online-active-users",
     "status": "active",
     "active": true,
     "installed": "2.3",
     "available": "3.4.4",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.3 -> 3.4.4 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "wpai-acf-add-on",
     "status": "active",
     "active": true,
     "installed": "3.3.9",
     "available": "4.0.2",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.3.9 -> 4.0.2 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "prevent-browser-caching",
     "status": "inactive",
     "active": false,
     "installed": "2.3.5",
     "available": "3.2.1",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.3.5 -> 3.2.1 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wordfence",
     "status": "inactive",
     "active": false,
     "installed": "7.11.7",
     "available": "9.0.1",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 7.11.7 -> 9.0.1 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "eps-301-redirects",
     "status": "active",
     "active": true,
     "installed": "2.77",
     "available": "2.85",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 2.77 -> 2.85 (skipped 8 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "admin-taxonomy-filter",
     "status": "active",
     "active": true,
     "installed": "1.0.4",
     "available": "1.0.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.0.4 -> 1.0.5"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "advanced-custom-fields-pro",
     "status": "active",
     "active": true,
     "installed": "6.3.10",
     "available": "6.8.10",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "multi-minor jump 6.3.10 -> 6.8.10 (skipped 5 minor releases)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE WITH CAPTURE \u2014 routine bump but on a sitewide-impact plugin; watch the diff closely."
    },
    {
     "plugin": "cachebuster",
     "status": "active",
     "active": true,
     "installed": "1.8",
     "available": "1.10",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.8 -> 1.10"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "cookie-law-info",
     "status": "active",
     "active": true,
     "installed": "3.2.7",
     "available": "3.5.6",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.2.7 -> 3.5.6 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "duplicate-page",
     "status": "active",
     "active": true,
     "installed": "4.5.4",
     "available": "4.5.9",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 4.5.4 -> 4.5.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "dynamic-content-for-elementor",
     "status": "active",
     "active": true,
     "installed": "3.0.16",
     "available": "3.4.13",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "multi-minor jump 3.0.16 -> 3.4.13 (skipped 4 minor releases)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE WITH CAPTURE \u2014 routine bump but on a sitewide-impact plugin; watch the diff closely."
    },
    {
     "plugin": "megamenu",
     "status": "active",
     "active": true,
     "installed": "3.3.2",
     "available": "3.10.8",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.3.2 -> 3.10.8 (skipped 7 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "page-links-to",
     "status": "active",
     "active": true,
     "installed": "3.3.7",
     "available": "3.4.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 3.3.7 -> 3.4.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "search-regex",
     "status": "active",
     "active": true,
     "installed": "3.1.0",
     "available": "3.4.4",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.1.0 -> 3.4.4 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wp-revisions-control",
     "status": "active",
     "active": true,
     "installed": "1.4.3",
     "available": "1.4.4",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.4.3 -> 1.4.4"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wp-search-with-algolia",
     "status": "active",
     "active": true,
     "installed": "2.8.1",
     "available": "2.14.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 2.8.1 -> 2.14.1 (skipped 6 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wps-hide-login",
     "status": "active",
     "active": true,
     "installed": "1.9.17.1",
     "available": "1.9.19",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.9.17.1 -> 1.9.19"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "disable-xml-rpc-api",
     "status": "inactive",
     "active": false,
     "installed": "2.1.6",
     "available": "2.1.7",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 2.1.6 -> 2.1.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "headers-security-advanced-hsts-wp",
     "status": "inactive",
     "active": false,
     "installed": "5.0.41",
     "available": "5.3.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.0.41 -> 5.3.5 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wp-mail-smtp",
     "status": "inactive",
     "active": false,
     "installed": "4.1.1",
     "available": "4.9.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 4.1.1 -> 4.9.0 (skipped 8 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    }
   ],
   "p0": 2,
   "p1": 15,
   "total_updates": 44
  },
  "wpengine:vhaprd": {
   "platform": "wpengine",
   "install": "vhaprd",
   "environment": "production",
   "domain": "vhaprd.wpenginepowered.com",
   "siteurl": "https://vhaprd.wpenginepowered.com",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "genesis-block-theme",
   "updates": [
    {
     "plugin": "genesis-blocks",
     "status": "active",
     "active": true,
     "installed": "3.1.5",
     "available": "3.1.11",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 3.1.5 -> 3.1.11"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "akismet",
     "status": "inactive",
     "active": false,
     "installed": "5.3.3",
     "available": "5.7.2",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.3.3 -> 5.7.2 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    }
   ],
   "p0": 0,
   "p1": 0,
   "total_updates": 2
  },
  "wpengine:napt2024dev": {
   "platform": "wpengine",
   "install": "napt2024dev",
   "environment": "development",
   "domain": "napt2024dev.wpenginepowered.com",
   "siteurl": "http://napt2024dev.wpenginepowered.com",
   "core": "7.0.3",
   "core_update": "7.0.4",
   "theme": "bootscore-child",
   "updates": [
    {
     "plugin": "ajax-search-lite",
     "status": "active",
     "active": true,
     "installed": "4.12.4",
     "available": "4.14.5",
     "priority": "P0",
     "vulns": [
      {
       "name": "Ajax Search Lite &#8211; Live Search &amp; Filter [ajax-search-lite] < 4.14.5",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2026-28139"
      },
      {
       "name": "Ajax Search Lite &#8211; Live Search &amp; Filter [ajax-search-lite] < 4.13.4",
       "cvss": "5.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-48086"
      },
      {
       "name": "Ajax Search Lite &#8211; Live Search &amp; Filter [ajax-search-lite] < 4.12.5",
       "cvss": "3.5",
       "severity": "LOW",
       "cve": "CVE-2024-13585"
      },
      {
       "name": "Ajax Search Lite &#8211; Live Search &amp; Filter [ajax-search-lite] < 4.13.2",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2025-7956"
      }
     ],
     "vuln_count": 5,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 4.12.4 -> 4.14.5"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "elementor-pro",
     "status": "active",
     "active": true,
     "installed": "3.26.1",
     "available": null,
     "priority": "P0",
     "vulns": [
      {
       "name": "Elementor Pro [elementor-pro] < 4.2.2",
       "cvss": "9.0",
       "severity": "CRITICAL",
       "cve": "CVE-2026-32475"
      },
      {
       "name": "Elementor Pro [elementor-pro] < 3.29.1",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-50555"
      },
      {
       "name": "Elementor Pro [elementor-pro] < 3.29.1",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-3076"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "wp-security-audit-log",
     "status": "active",
     "active": true,
     "installed": "5.2.2",
     "available": "5.6.6",
     "priority": "P0",
     "vulns": [
      {
       "name": "WP Activity Log [wp-security-audit-log] < 5.3.3",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2025-0767"
      },
      {
       "name": "WP Activity Log [wp-security-audit-log] < 5.6.4",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2026-54806"
      },
      {
       "name": "WP Activity Log [wp-security-audit-log] < 5.6.4",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-56005"
      },
      {
       "name": "WP Activity Log [wp-security-audit-log] < 5.6.0",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-25331"
      }
     ],
     "vuln_count": 7,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.2.2 -> 5.6.6 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "revslider",
     "status": "active",
     "active": true,
     "installed": "6.7.25",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "Slider Revolution [revslider] < 7.0.11",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-6692"
      },
      {
       "name": "Slider Revolution [revslider] < 7.1.0",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-57678"
      },
      {
       "name": "Slider Revolution [revslider] < 6.7.37",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-9217"
      },
      {
       "name": "Slider Revolution [revslider] < 6.7.38",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-10249"
      }
     ],
     "vuln_count": 8,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "wp-all-import-pro",
     "status": "active",
     "active": true,
     "installed": "4.9.4",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "WP All Import Pro [wp-all-import-pro] < 4.9.8",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2024-9664"
      },
      {
       "name": "WP All Import Pro [wp-all-import-pro] < 4.9.8",
       "cvss": "5.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-8722"
      },
      {
       "name": "WP All Import Pro [wp-all-import-pro] < 4.9.8",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2024-9661"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "insert-headers-and-footers",
     "status": "active",
     "active": true,
     "installed": "2.2.4.1",
     "available": "2.3.9",
     "priority": "P1",
     "vulns": [
      {
       "name": "WPCode &#8211; Insert Headers and Footers + Custom Code Snippets &#8211; WordPress Code Manager [insert-headers-and-footers] < 2.3.6",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-8832"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.2.4.1 -> 2.3.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "contact-form-7",
     "status": "active",
     "active": true,
     "installed": "6.0.1",
     "available": "6.1.7",
     "priority": "P2",
     "vulns": [
      {
       "name": "Contact Form 7 [contact-form-7] < 6.0.6",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-3247"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 6.0.1 -> 6.1.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "elementor",
     "status": "active",
     "active": true,
     "installed": "3.26.1",
     "available": "4.2.4",
     "priority": "P2",
     "vulns": [
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.29.1",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-50555"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.35.6",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-32352"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 4.1.4",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-57619"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.27.5",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-13445"
      }
     ],
     "vuln_count": 15,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.26.1 -> 4.2.4 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "flamingo",
     "status": "active",
     "active": true,
     "installed": "2.5",
     "available": "2.6.4",
     "priority": "P2",
     "vulns": [
      {
       "name": "Flamingo [flamingo] < 2.6.3",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-12853"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.5 -> 2.6.4"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "simple-banner",
     "status": "active",
     "active": true,
     "installed": "3.0.4",
     "available": "3.3.2",
     "priority": "P2",
     "vulns": [
      {
       "name": "Simple Banner &#8211; Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website [simple-banner] < 3.0.5",
       "cvss": "4.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-13898"
      },
      {
       "name": "Simple Banner &#8211; Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website [simple-banner] < 3.1.0",
       "cvss": "4.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-12033"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.0.4 -> 3.3.2 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "wp-dummy-content-generator",
     "status": "active",
     "active": true,
     "installed": "3.4.5",
     "available": "4.0.0",
     "priority": "P2",
     "vulns": [
      {
       "name": "WP Dummy Content Generator [wp-dummy-content-generator] < 4.0.0",
       "cvss": "0.0",
       "severity": null,
       "cve": "CVE-2025-49234"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.4.5 -> 4.0.0 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "wp-mail-logging",
     "status": "active",
     "active": true,
     "installed": "1.13.1",
     "available": "1.16.0",
     "priority": "P2",
     "vulns": [
      {
       "name": "WP Mail Logging [wp-mail-logging] < 1.16",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-2471"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 1.13.1 -> 1.16.0 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "wordpress-seo",
     "status": "active",
     "active": true,
     "installed": "24.1",
     "available": "28.5",
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 26.6",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-14481"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 27.2",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-3427"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 26.9",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-1293"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 28.1",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-15425"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 24.1 -> 28.5 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "search-filter",
     "status": "inactive",
     "active": false,
     "installed": "1.2.17",
     "available": "1.2.18",
     "priority": "P2",
     "vulns": [
      {
       "name": "Search &amp; Filter [search-filter] < 1.2.18",
       "cvss": "4.7",
       "severity": "MEDIUM",
       "cve": "CVE-2025-48099"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.2.17 -> 1.2.18"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "search-filter-pro",
     "status": "inactive",
     "active": false,
     "installed": "2.5.14",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Search & Filter Pro [search-filter-pro] < 2.5.18",
       "cvss": "4.8",
       "severity": "MEDIUM",
       "cve": "CVE-2024-6481"
      },
      {
       "name": "Search & Filter Pro [search-filter-pro] < 2.5.20",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-1528"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "font-awesome",
     "status": "active",
     "active": true,
     "installed": "4.5.0",
     "available": "5.2.1",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 4.5.0 -> 5.2.1 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "wpai-acf-add-on",
     "status": "active",
     "active": true,
     "installed": "3.3.9",
     "available": "4.0.2",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.3.9 -> 4.0.2 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "advanced-custom-fields-pro",
     "status": "active",
     "active": true,
     "installed": "6.3.11",
     "available": "6.8.10",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "multi-minor jump 6.3.11 -> 6.8.10 (skipped 5 minor releases)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE WITH CAPTURE \u2014 routine bump but on a sitewide-impact plugin; watch the diff closely."
    },
    {
     "plugin": "duplicate-page",
     "status": "active",
     "active": true,
     "installed": "4.5.4",
     "available": "4.5.9",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 4.5.4 -> 4.5.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "page-links-to",
     "status": "active",
     "active": true,
     "installed": "3.3.7",
     "available": "3.4.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 3.3.7 -> 3.4.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "redirection",
     "status": "active",
     "active": true,
     "installed": "5.5.1",
     "available": "5.10.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.5.1 -> 5.10.0 (skipped 5 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "redirect-redirection",
     "status": "active",
     "active": true,
     "installed": "1.2.5",
     "available": "1.3.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.2.5 -> 1.3.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "safe-svg",
     "status": "active",
     "active": true,
     "installed": "2.3.1",
     "available": "2.5.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.3.1 -> 2.5.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "uixpress",
     "status": "active",
     "active": true,
     "installed": "1.0.19",
     "available": "1.2.14",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.0.19 -> 1.2.14"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wp-mail-smtp",
     "status": "active",
     "active": true,
     "installed": "4.3.0",
     "available": "4.9.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 4.3.0 -> 4.9.0 (skipped 6 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wp-migrate-db-pro",
     "status": "active",
     "active": true,
     "installed": "2.7.0",
     "available": "2.7.11",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 2.7.0 -> 2.7.11"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    }
   ],
   "p0": 3,
   "p1": 3,
   "total_updates": 22
  },
  "wpengine:winterparkprd": {
   "platform": "wpengine",
   "install": "winterparkprd",
   "environment": "production",
   "domain": "winterparkprd.wpenginepowered.com",
   "siteurl": "https://winterparkprd.wpenginepowered.com",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "genesis-block-theme",
   "updates": [
    {
     "plugin": "genesis-blocks",
     "status": "active",
     "active": true,
     "installed": "3.1.5",
     "available": "3.1.11",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 3.1.5 -> 3.1.11"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "akismet",
     "status": "inactive",
     "active": false,
     "installed": "5.3.3",
     "available": "5.7.2",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.3.3 -> 5.7.2 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    }
   ],
   "p0": 0,
   "p1": 0,
   "total_updates": 2
  },
  "wpengine:xlmachineprd": {
   "platform": "wpengine",
   "install": "xlmachineprd",
   "environment": "production",
   "domain": "xlmachineprd.wpenginepowered.com",
   "siteurl": "https://xlmachineprd.wpenginepowered.com",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "genesis-block-theme",
   "updates": [
    {
     "plugin": "genesis-blocks",
     "status": "active",
     "active": true,
     "installed": "3.1.5",
     "available": "3.1.11",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 3.1.5 -> 3.1.11"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "akismet",
     "status": "inactive",
     "active": false,
     "installed": "5.3.3",
     "available": "5.7.2",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.3.3 -> 5.7.2 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    }
   ],
   "p0": 0,
   "p1": 0,
   "total_updates": 2
  },
  "wpengine:b64": {
   "platform": "wpengine",
   "install": "b64",
   "environment": "development",
   "domain": "b64.wpenginepowered.com",
   "siteurl": "https://b64.wpenginepowered.com",
   "core": "7.0.3",
   "core_update": "7.0.4",
   "theme": "bootscore-child",
   "updates": [
    {
     "plugin": "ewww-image-optimizer",
     "status": "active",
     "active": true,
     "installed": "8.0.0",
     "available": "8.7.7",
     "priority": "P1",
     "vulns": [
      {
       "name": "EWWW Image Optimizer [ewww-image-optimizer] < 8.7.7",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-84773"
      },
      {
       "name": "EWWW Image Optimizer [ewww-image-optimizer] < 8.7.4",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-15446"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 8.0.0 -> 8.7.7 (skipped 7 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "updraftplus",
     "status": "active",
     "active": true,
     "installed": "1.25.1",
     "available": "1.26.7",
     "priority": "P1",
     "vulns": [
      {
       "name": "UpdraftPlus: WP Backup &amp; Migration Plugin [updraftplus] < 1.26.5",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2026-10795"
      },
      {
       "name": "UpdraftPlus: WP Backup &amp; Migration Plugin [updraftplus] < 1.26.7",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-76549"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "minor version bump 1.25.1 -> 1.26.7",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "wp-optimize",
     "status": "active",
     "active": true,
     "installed": "3.8.0",
     "available": "4.6.1",
     "priority": "P1",
     "vulns": [
      {
       "name": "WP-Optimize \u2013 Cache, Compress images, Minify &amp; Clean database to boost page speed &amp; performance [wp-optimize] < 4.5.3",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2026-7252"
      },
      {
       "name": "WP-Optimize \u2013 Cache, Compress images, Minify &amp; Clean database to boost page speed &amp; performance [wp-optimize] < 4.2.0",
       "cvss": "4.1",
       "severity": "MEDIUM",
       "cve": "CVE-2025-3951"
      },
      {
       "name": "WP-Optimize \u2013 Cache, Compress images, Minify &amp; Clean database to boost page speed &amp; performance [wp-optimize] < 4.5.1",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-2712"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.8.0 -> 4.6.1 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "insert-headers-and-footers",
     "status": "active",
     "active": true,
     "installed": "2.2.5",
     "available": "2.3.9",
     "priority": "P1",
     "vulns": [
      {
       "name": "WPCode &#8211; Insert Headers and Footers + Custom Code Snippets &#8211; WordPress Code Manager [insert-headers-and-footers] < 2.3.6",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-8832"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.2.5 -> 2.3.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "wpide",
     "status": "active",
     "active": true,
     "installed": "3.5.0",
     "available": "3.5.9",
     "priority": "P1",
     "vulns": [
      {
       "name": "WPIDE &#8211; File Manager &amp; Code Editor [wpide] < 3.5.7",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-57766"
      },
      {
       "name": "WPIDE &#8211; File Manager &amp; Code Editor [wpide] < 3.5.8",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-66440"
      },
      {
       "name": "WPIDE &#8211; File Manager &amp; Code Editor [wpide] < 3.5.2",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2024-13362"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 3.5.0 -> 3.5.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "mainwp-child",
     "status": "inactive",
     "active": false,
     "installed": "5.3.4",
     "available": "6.2",
     "priority": "P1",
     "vulns": [
      {
       "name": "MainWP Child &#8211; Securely Connects to the MainWP Dashboard to Manage Multiple Sites [mainwp-child] < 6.1.2",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-27366"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 5.3.4 -> 6.2 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "limit-login-attempts-reloaded",
     "status": "active",
     "active": true,
     "installed": "2.26.16",
     "available": "3.3.8",
     "priority": "P2",
     "vulns": [
      {
       "name": "Limit Login Attempts Security &#8211; Login Security, 2FA, Firewall, Brute Force Prevention [limit-login-attempts-reloaded] < 3.3.5",
       "cvss": "3.7",
       "severity": "LOW",
       "cve": "CVE-2026-18356"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.26.16 -> 3.3.8 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "query-monitor",
     "status": "active",
     "active": true,
     "installed": "3.17.0",
     "available": "4.0.7",
     "priority": "P2",
     "vulns": [
      {
       "name": "Query Monitor [query-monitor] < 3.20.4",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-4267"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.17.0 -> 4.0.7 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "search-filter-pro",
     "status": "active",
     "active": true,
     "installed": "2.5.19",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Search & Filter Pro [search-filter-pro] < 2.5.20",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-1528"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "simple-banner",
     "status": "active",
     "active": true,
     "installed": "3.0.4",
     "available": "3.3.2",
     "priority": "P2",
     "vulns": [
      {
       "name": "Simple Banner &#8211; Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website [simple-banner] < 3.0.5",
       "cvss": "4.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-13898"
      },
      {
       "name": "Simple Banner &#8211; Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website [simple-banner] < 3.1.0",
       "cvss": "4.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-12033"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.0.4 -> 3.3.2 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "smtp2go",
     "status": "active",
     "active": true,
     "installed": "1.11.1",
     "available": "1.17.1",
     "priority": "P2",
     "vulns": [
      {
       "name": "SMTP2GO for WordPress &#8211; Email Made Easy [smtp2go] < 1.12.2",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-54011"
      },
      {
       "name": "SMTP2GO for WordPress &#8211; Email Made Easy [smtp2go] < 1.17.0",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-7621"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 1.11.1 -> 1.17.1 (skipped 6 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "gutenberg",
     "status": "inactive",
     "active": false,
     "installed": "20.1.0",
     "available": "24.0.0",
     "priority": "P2",
     "vulns": [
      {
       "name": "Gutenberg [gutenberg] < 21.9.0",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-64354"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 20.1.0 -> 24.0.0 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wordpress-seo",
     "status": "inactive",
     "active": false,
     "installed": "24.3",
     "available": "28.5",
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 26.6",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-14481"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 27.2",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-3427"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 26.9",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-1293"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 28.1",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-15425"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 24.3 -> 28.5 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "online-active-users",
     "status": "active",
     "active": true,
     "installed": "2.5",
     "available": "3.4.4",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.5 -> 3.4.4 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "prevent-browser-caching",
     "status": "active",
     "active": true,
     "installed": "2.3.5",
     "available": "3.2.1",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.3.5 -> 3.2.1 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "wpae-acf-add-on",
     "status": "active",
     "active": true,
     "installed": "1.0.5",
     "available": "2.0.0",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 1.0.5 -> 2.0.0 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "wpai-acf-add-on",
     "status": "active",
     "active": true,
     "installed": "3.3.9",
     "available": "4.0.2",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.3.9 -> 4.0.2 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "eps-301-redirects",
     "status": "active",
     "active": true,
     "installed": "2.77",
     "available": "2.85",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 2.77 -> 2.85 (skipped 8 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "admin-taxonomy-filter",
     "status": "active",
     "active": true,
     "installed": "1.0.4",
     "available": "1.0.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.0.4 -> 1.0.5"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "advanced-custom-fields-pro",
     "status": "active",
     "active": true,
     "installed": "6.3.12",
     "available": "6.8.10",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "multi-minor jump 6.3.12 -> 6.8.10 (skipped 5 minor releases)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE WITH CAPTURE \u2014 routine bump but on a sitewide-impact plugin; watch the diff closely."
    },
    {
     "plugin": "cookie-law-info",
     "status": "active",
     "active": true,
     "installed": "3.2.8",
     "available": "3.5.6",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.2.8 -> 3.5.6 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "duplicate-page",
     "status": "active",
     "active": true,
     "installed": "4.5.4",
     "available": "4.5.9",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 4.5.4 -> 4.5.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "megamenu",
     "status": "active",
     "active": true,
     "installed": "3.4.1",
     "available": "3.10.8",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.4.1 -> 3.10.8 (skipped 6 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wps-hide-login",
     "status": "active",
     "active": true,
     "installed": "1.9.17.1",
     "available": "1.9.19",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.9.17.1 -> 1.9.19"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "classic-editor",
     "status": "inactive",
     "active": false,
     "installed": "1.6.7",
     "available": "1.7.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.6.7 -> 1.7.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    }
   ],
   "p0": 0,
   "p1": 6,
   "total_updates": 24
  },
  "wpengine:bpgprd": {
   "platform": "wpengine",
   "install": "bpgprd",
   "environment": "production",
   "domain": "bpgprd.wpenginepowered.com",
   "siteurl": "https://bpgprd.wpenginepowered.com",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "genesis-block-theme",
   "updates": [
    {
     "plugin": "genesis-blocks",
     "status": "active",
     "active": true,
     "installed": "3.1.3",
     "available": "3.1.11",
     "priority": "P2",
     "vulns": [
      {
       "name": "Genesis Blocks [genesis-blocks] < 3.1.4",
       "cvss": "6.8",
       "severity": "MEDIUM",
       "cve": "CVE-2024-3901"
      },
      {
       "name": "Genesis Blocks [genesis-blocks] < 3.1.4",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-3563"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 3.1.3 -> 3.1.11"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "akismet",
     "status": "inactive",
     "active": false,
     "installed": "5.3.1",
     "available": "5.7.2",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.3.1 -> 5.7.2 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    }
   ],
   "p0": 0,
   "p1": 0,
   "total_updates": 2
  },
  "wpengine:primaticsstg": {
   "platform": "wpengine",
   "install": "primaticsstg",
   "environment": "staging",
   "domain": "primaticsstg.wpenginepowered.com",
   "siteurl": "https://primaticsstg.wpenginepowered.com",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "theme",
   "updates": [
    {
     "plugin": "advanced-custom-fields-pro",
     "status": "active",
     "active": true,
     "installed": "6.2.6.1",
     "available": "6.8.10",
     "priority": "P0",
     "vulns": [
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.2.10",
       "cvss": "9.9",
       "severity": "CRITICAL",
       "cve": "CVE-2024-34762"
      },
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.2.10",
       "cvss": "8.5",
       "severity": "HIGH",
       "cve": "CVE-2024-34761"
      },
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.3.8",
       "cvss": "6.6",
       "severity": "MEDIUM",
       "cve": "CVE-2024-9529"
      },
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.3.0",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-4565"
      }
     ],
     "vuln_count": 10,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "multi-minor jump 6.2.6.1 -> 6.8.10 (skipped 6 minor releases)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "gravityforms",
     "status": "active",
     "active": true,
     "installed": "2.8.18",
     "available": "3.1.1",
     "priority": "P0",
     "vulns": [
      {
       "name": "Gravity Forms [gravityforms] < 2.9.21",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2025-12352"
      },
      {
       "name": "Gravity Forms [gravityforms] < 2.10.1",
       "cvss": "9.6",
       "severity": "CRITICAL",
       "cve": "CVE-2026-48866"
      },
      {
       "name": "Gravity Forms [gravityforms] < 2.9.22",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2025-12974"
      },
      {
       "name": "Gravity Forms [gravityforms] < 3.0.3",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2026-19513"
      }
     ],
     "vuln_count": 17,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.8.18 -> 3.1.1 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "translatepress-multilingual",
     "status": "active",
     "active": true,
     "installed": "2.7.6",
     "available": "3.3.6",
     "priority": "P0",
     "vulns": [
      {
       "name": "TranslatePress &#8211; Translate Multilingual sites with AI Translation [translatepress-multilingual] < 3.3.3",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2026-78267"
      },
      {
       "name": "TranslatePress &#8211; Translate Multilingual sites with AI Translation [translatepress-multilingual] < 3.3.2",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2026-19632"
      },
      {
       "name": "TranslatePress &#8211; Translate Multilingual sites with AI Translation [translatepress-multilingual] < 2.10.3",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2025-58592"
      },
      {
       "name": "TranslatePress &#8211; Translate Multilingual sites with AI Translation [translatepress-multilingual] < 3.3",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-18510"
      }
     ],
     "vuln_count": 10,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.7.6 -> 3.3.6 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "popup-maker",
     "status": "active",
     "active": true,
     "installed": "1.18.5",
     "available": "1.25.0",
     "priority": "P1",
     "vulns": [
      {
       "name": "Popup Maker &#8211; Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.23.0",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-8848"
      },
      {
       "name": "Popup Maker &#8211; Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.24.0",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-28177"
      },
      {
       "name": "Popup Maker &#8211; Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.20.3",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-24746"
      },
      {
       "name": "Popup Maker &#8211; Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.20.5",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-4205"
      }
     ],
     "vuln_count": 9,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 1.18.5 -> 1.25.0 (skipped 7 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "wp-smushit",
     "status": "active",
     "active": true,
     "installed": "3.16.2",
     "available": "4.3.3",
     "priority": "P1",
     "vulns": [
      {
       "name": "Smush \u2013 Image Optimization, Compression, Lazy Load, WebP &amp; CDN [wp-smushit] < 4.3.0",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-81285"
      },
      {
       "name": "Smush \u2013 Image Optimization, Compression, Lazy Load, WebP &amp; CDN [wp-smushit] < 3.16.5",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2023-3352"
      },
      {
       "name": "Smush \u2013 Image Optimization, Compression, Lazy Load, WebP &amp; CDN [wp-smushit] < 3.17.1",
       "cvss": "4.1",
       "severity": "MEDIUM",
       "cve": "CVE-2025-22288"
      },
      {
       "name": "Smush \u2013 Image Optimization, Compression, Lazy Load, WebP &amp; CDN [wp-smushit] < 4.3.2",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-19223"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.16.2 -> 4.3.3 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "wordpress-importer",
     "status": "active",
     "active": true,
     "installed": "0.8.2",
     "available": "0.9.6",
     "priority": "P1",
     "vulns": [
      {
       "name": "WordPress Importer [wordpress-importer] < 0.8.4",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2024-13889"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 0.8.2 -> 0.9.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "insert-headers-and-footers",
     "status": "inactive",
     "active": false,
     "installed": "2.1.12",
     "available": "2.3.9",
     "priority": "P1",
     "vulns": [
      {
       "name": "WPCode &#8211; Insert Headers and Footers + Custom Code Snippets &#8211; WordPress Code Manager [insert-headers-and-footers] < 2.3.6",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-8832"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.1.12 -> 2.3.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "acf-to-rest-api",
     "status": "active",
     "active": true,
     "installed": "3.3.3",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "ACF to REST API [acf-to-rest-api] <= 3.3.4 (unfixed + closed)",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-62979"
      },
      {
       "name": "ACF to REST API [acf-to-rest-api] <= 3.3.4 (unfixed + closed)",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-12030"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "wp-mail-smtp",
     "status": "active",
     "active": true,
     "installed": "4.0.1",
     "available": "4.9.0",
     "priority": "P2",
     "vulns": [
      {
       "name": "WP Mail SMTP by WPForms &#8211; The Most Popular SMTP and Email Log Plugin [wp-mail-smtp] < 4.1.0",
       "cvss": "2.7",
       "severity": "LOW",
       "cve": "CVE-2024-6694"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 4.0.1 -> 4.9.0 (skipped 9 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "wp-migrate-db",
     "status": "active",
     "active": true,
     "installed": "2.6.10",
     "available": "2.7.11",
     "priority": "P2",
     "vulns": [
      {
       "name": "WP Migrate Lite &#8211; Migration Made Easy [wp-migrate-db] < 2.7.7",
       "cvss": "5.8",
       "severity": "MEDIUM",
       "cve": "CVE-2025-11427"
      },
      {
       "name": "WP Migrate Lite &#8211; Migration Made Easy [wp-migrate-db] < 2.7.9",
       "cvss": "4.7",
       "severity": "MEDIUM",
       "cve": "CVE-2026-49043"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.6.10 -> 2.7.11"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "duplicate-post",
     "status": "active",
     "active": true,
     "installed": "4.5",
     "available": "4.7",
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast Duplicate Post [duplicate-post] <= 4.6 (unfixed)",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-53740"
      },
      {
       "name": "Yoast Duplicate Post [duplicate-post] <= 4.6 (unfixed)",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-53739"
      },
      {
       "name": "Yoast Duplicate Post [duplicate-post] < 4.6",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-1217"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 4.5 -> 4.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "better-wp-security",
     "status": "active",
     "active": true,
     "installed": "9.3.2",
     "available": "10.0.3",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 9.3.2 -> 10.0.3 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "akismet",
     "status": "active",
     "active": true,
     "installed": "5.3.2",
     "available": "5.7.2",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.3.2 -> 5.7.2 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "force-regenerate-thumbnails",
     "status": "active",
     "active": true,
     "installed": "2.1.4",
     "available": "2.3.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.1.4 -> 2.3.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "redirection",
     "status": "active",
     "active": true,
     "installed": "5.4.2",
     "available": "5.10.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.4.2 -> 5.10.0 (skipped 6 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "simple-page-ordering",
     "status": "active",
     "active": true,
     "installed": "2.7.0",
     "available": "2.8.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.7.0 -> 2.8.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "autodescription",
     "status": "active",
     "active": true,
     "installed": "5.0.6",
     "available": "5.1.4",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 5.0.6 -> 5.1.4"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "translatepress-developer",
     "status": "active",
     "active": true,
     "installed": "1.2.4",
     "available": "1.8.7",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 1.2.4 -> 1.8.7 (skipped 6 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    }
   ],
   "p0": 3,
   "p1": 4,
   "total_updates": 17
  },
  "wpengine:galileostg1": {
   "platform": "wpengine",
   "install": "galileostg1",
   "environment": "staging",
   "domain": "galileostg1.wpenginepowered.com",
   "siteurl": "https://galileostg1.wpenginepowered.com",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "theme",
   "updates": [
    {
     "plugin": "translatepress-multilingual",
     "status": "active",
     "active": true,
     "installed": "2.8.9",
     "available": "3.3.6",
     "priority": "P0",
     "vulns": [
      {
       "name": "TranslatePress &#8211; Translate Multilingual sites with AI Translation [translatepress-multilingual] < 3.3.3",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2026-78267"
      },
      {
       "name": "TranslatePress &#8211; Translate Multilingual sites with AI Translation [translatepress-multilingual] < 3.3.2",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2026-19632"
      },
      {
       "name": "TranslatePress &#8211; Translate Multilingual sites with AI Translation [translatepress-multilingual] < 2.10.3",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2025-58592"
      },
      {
       "name": "TranslatePress &#8211; Translate Multilingual sites with AI Translation [translatepress-multilingual] < 3.3",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-18510"
      }
     ],
     "vuln_count": 10,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.8.9 -> 3.3.6 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "gravityforms",
     "status": "active",
     "active": true,
     "installed": "2.10.4",
     "available": "3.1.1",
     "priority": "P1",
     "vulns": [
      {
       "name": "Gravity Forms [gravityforms] < 3.0.3",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2026-19513"
      },
      {
       "name": "Gravity Forms [gravityforms] < 2.10.5",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-12997"
      },
      {
       "name": "Gravity Forms [gravityforms] < 3.0.0",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-16649"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.10.4 -> 3.1.1 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "popup-maker",
     "status": "active",
     "active": true,
     "installed": "1.20.2",
     "available": "1.25.0",
     "priority": "P1",
     "vulns": [
      {
       "name": "Popup Maker &#8211; Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.23.0",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-8848"
      },
      {
       "name": "Popup Maker &#8211; Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.24.0",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-28177"
      },
      {
       "name": "Popup Maker &#8211; Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.20.3",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-24746"
      },
      {
       "name": "Popup Maker &#8211; Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.20.5",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-4205"
      }
     ],
     "vuln_count": 6,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 1.20.2 -> 1.25.0 (skipped 5 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "wp-smushit",
     "status": "active",
     "active": true,
     "installed": "3.16.6",
     "available": "4.3.3",
     "priority": "P1",
     "vulns": [
      {
       "name": "Smush \u2013 Image Optimization, Compression, Lazy Load, WebP &amp; CDN [wp-smushit] < 4.3.0",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-81285"
      },
      {
       "name": "Smush \u2013 Image Optimization, Compression, Lazy Load, WebP &amp; CDN [wp-smushit] < 3.17.1",
       "cvss": "4.1",
       "severity": "MEDIUM",
       "cve": "CVE-2025-22288"
      },
      {
       "name": "Smush \u2013 Image Optimization, Compression, Lazy Load, WebP &amp; CDN [wp-smushit] < 4.3.2",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-19223"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.16.6 -> 4.3.3 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "wordpress-importer",
     "status": "active",
     "active": true,
     "installed": "0.8.3",
     "available": "0.9.6",
     "priority": "P1",
     "vulns": [
      {
       "name": "WordPress Importer [wordpress-importer] < 0.8.4",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2024-13889"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 0.8.3 -> 0.9.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "insert-headers-and-footers",
     "status": "active",
     "active": true,
     "installed": "2.2.3.1",
     "available": "2.3.9",
     "priority": "P1",
     "vulns": [
      {
       "name": "WPCode &#8211; Insert Headers and Footers + Custom Code Snippets &#8211; WordPress Code Manager [insert-headers-and-footers] < 2.3.6",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-8832"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.2.3.1 -> 2.3.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "acf-to-rest-api",
     "status": "active",
     "active": true,
     "installed": "3.3.3",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "ACF to REST API [acf-to-rest-api] <= 3.3.4 (unfixed + closed)",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-62979"
      },
      {
       "name": "ACF to REST API [acf-to-rest-api] <= 3.3.4 (unfixed + closed)",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-12030"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "complianz-gdpr",
     "status": "active",
     "active": true,
     "installed": "7.1.5",
     "available": "7.5.5",
     "priority": "P2",
     "vulns": [
      {
       "name": "Complianz GDPR/CCPA Cookie Consent Banner [complianz-gdpr] < 7.4.4",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-11185"
      },
      {
       "name": "Complianz GDPR/CCPA Cookie Consent Banner [complianz-gdpr] < 7.4.6",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-4019"
      },
      {
       "name": "Complianz GDPR/CCPA Cookie Consent Banner [complianz-gdpr] <= 7.5.1 (unfixed)",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-65498"
      },
      {
       "name": "Complianz GDPR/CCPA Cookie Consent Banner [complianz-gdpr] < 7.4.5",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-2389"
      }
     ],
     "vuln_count": 6,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 7.1.5 -> 7.5.5 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "limit-login-attempts-reloaded",
     "status": "active",
     "active": true,
     "installed": "2.26.16",
     "available": "3.3.8",
     "priority": "P2",
     "vulns": [
      {
       "name": "Limit Login Attempts Security &#8211; Login Security, 2FA, Firewall, Brute Force Prevention [limit-login-attempts-reloaded] < 3.3.5",
       "cvss": "3.7",
       "severity": "LOW",
       "cve": "CVE-2026-18356"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.26.16 -> 3.3.8 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "smtp2go",
     "status": "active",
     "active": true,
     "installed": "1.10.0",
     "available": "1.17.1",
     "priority": "P2",
     "vulns": [
      {
       "name": "SMTP2GO for WordPress &#8211; Email Made Easy [smtp2go] < 1.12.2",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-54011"
      },
      {
       "name": "SMTP2GO for WordPress &#8211; Email Made Easy [smtp2go] < 1.17.0",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-7621"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 1.10.0 -> 1.17.1 (skipped 7 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "sucuri-scanner",
     "status": "active",
     "active": true,
     "installed": "1.9.6",
     "available": "2.8",
     "priority": "P2",
     "vulns": [
      {
       "name": "Sucuri Security &#8211; Auditing, Malware Scanner and Security Hardening [sucuri-scanner] <= 2.7.3 (unfixed)",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-73033"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 1.9.6 -> 2.8 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "two-factor-2fa-via-email",
     "status": "active",
     "active": true,
     "installed": "1.9.5",
     "available": "1.9.10",
     "priority": "P2",
     "vulns": [
      {
       "name": "Two Factor (2FA) Authentication via Email [two-factor-2fa-via-email] < 1.9.9",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-13587"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.9.5 -> 1.9.10"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "duplicate-post",
     "status": "active",
     "active": true,
     "installed": "4.5",
     "available": "4.7",
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast Duplicate Post [duplicate-post] <= 4.6 (unfixed)",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-53740"
      },
      {
       "name": "Yoast Duplicate Post [duplicate-post] <= 4.6 (unfixed)",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-53739"
      },
      {
       "name": "Yoast Duplicate Post [duplicate-post] < 4.6",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-1217"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 4.5 -> 4.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "change-admin-email-setting-without-outbound-email",
     "status": "active",
     "active": true,
     "installed": "4.1",
     "available": "5.0",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 4.1 -> 5.0 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "better-wp-security",
     "status": "active",
     "active": true,
     "installed": "9.3.5",
     "available": "10.0.3",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 9.3.5 -> 10.0.3 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "advanced-custom-fields-pro",
     "status": "active",
     "active": true,
     "installed": "6.3.11",
     "available": "6.8.10",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "multi-minor jump 6.3.11 -> 6.8.10 (skipped 5 minor releases)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE WITH CAPTURE \u2014 routine bump but on a sitewide-impact plugin; watch the diff closely."
    },
    {
     "plugin": "akismet",
     "status": "active",
     "active": true,
     "installed": "5.3.5",
     "available": "5.7.2",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.3.5 -> 5.7.2 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "force-regenerate-thumbnails",
     "status": "active",
     "active": true,
     "installed": "2.2.1",
     "available": "2.3.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.2.1 -> 2.3.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "headers-security-advanced-hsts-wp",
     "status": "active",
     "active": true,
     "installed": "5.0.41",
     "available": "5.3.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.0.41 -> 5.3.5 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "redirection",
     "status": "active",
     "active": true,
     "installed": "5.5.0",
     "available": "5.10.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.5.0 -> 5.10.0 (skipped 5 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "simple-page-ordering",
     "status": "active",
     "active": true,
     "installed": "2.7.2",
     "available": "2.8.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.7.2 -> 2.8.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "autodescription",
     "status": "active",
     "active": true,
     "installed": "5.0.6",
     "available": "5.1.4",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 5.0.6 -> 5.1.4"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "translatepress-developer",
     "status": "active",
     "active": true,
     "installed": "1.4.8",
     "available": "1.8.7",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 1.4.8 -> 1.8.7 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wp-mail-smtp",
     "status": "inactive",
     "active": false,
     "installed": "4.2.0",
     "available": "4.9.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 4.2.0 -> 4.9.0 (skipped 7 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    }
   ],
   "p0": 1,
   "p1": 5,
   "total_updates": 23
  },
  "wpengine:cimatstg": {
   "platform": "wpengine",
   "install": "cimatstg",
   "environment": "staging",
   "domain": "cimatstg.wpenginepowered.com",
   "siteurl": "https://cimatstg.wpenginepowered.com",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "genesis-block-theme",
   "updates": [
    {
     "plugin": "genesis-blocks",
     "status": "active",
     "active": true,
     "installed": "3.1.5",
     "available": "3.1.11",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 3.1.5 -> 3.1.11"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "akismet",
     "status": "inactive",
     "active": false,
     "installed": "5.3.3",
     "available": "5.7.2",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.3.3 -> 5.7.2 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    }
   ],
   "p0": 0,
   "p1": 0,
   "total_updates": 2
  },
  "wpengine:ascmlsprd": {
   "platform": "wpengine",
   "install": "ascmlsprd",
   "environment": "production",
   "domain": "ascmlsprd.wpenginepowered.com",
   "siteurl": "https://ascmlsprd.wpenginepowered.com",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "hello-ascential",
   "updates": [
    {
     "plugin": "ameliabooking",
     "status": "active",
     "active": true,
     "installed": "1.2.33",
     "available": "2.4.10",
     "priority": "P0",
     "vulns": [
      {
       "name": "Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 9.6.3",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2026-9055"
      },
      {
       "name": "Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 2.4.3",
       "cvss": "9.3",
       "severity": "CRITICAL",
       "cve": "CVE-2026-57702"
      },
      {
       "name": "Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 2.4",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-48889"
      },
      {
       "name": "Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 2.1.2",
       "cvss": "7.6",
       "severity": "HIGH",
       "cve": "CVE-2026-39487"
      }
     ],
     "vuln_count": 28,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 1.2.33 -> 2.4.10 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "elementor-pro",
     "status": "active",
     "active": true,
     "installed": "3.33.2",
     "available": "3.35.1",
     "priority": "P0",
     "vulns": [
      {
       "name": "Elementor Pro [elementor-pro] < 4.2.2",
       "cvss": "9.0",
       "severity": "CRITICAL",
       "cve": "CVE-2026-32475"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "minor version bump 3.33.2 -> 3.35.1",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "wp-security-audit-log",
     "status": "active",
     "active": true,
     "installed": "5.5.1",
     "available": "5.6.6",
     "priority": "P0",
     "vulns": [
      {
       "name": "WP Activity Log [wp-security-audit-log] < 5.6.4",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2026-54806"
      },
      {
       "name": "WP Activity Log [wp-security-audit-log] < 5.6.4",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-56005"
      },
      {
       "name": "WP Activity Log [wp-security-audit-log] < 5.6.0",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-25331"
      },
      {
       "name": "WP Activity Log [wp-security-audit-log] < 5.6.3.1",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-45435"
      }
     ],
     "vuln_count": 5,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 5.5.1 -> 5.6.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "woocommerce",
     "status": "inactive",
     "active": false,
     "installed": "10.2.0",
     "available": "11.1.0",
     "priority": "P0",
     "vulns": [
      {
       "name": "WooCommerce [woocommerce] == 7.1.0 (unfixed)",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2022-50972"
      },
      {
       "name": "WooCommerce [woocommerce] < 11.0",
       "cvss": "7.6",
       "severity": "HIGH",
       "cve": "CVE-2026-57777"
      },
      {
       "name": "WooCommerce [woocommerce] < 11.1.0",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-48888"
      },
      {
       "name": "WooCommerce [woocommerce] < 10.4.3",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-15033"
      }
     ],
     "vuln_count": 5,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 10.2.0 -> 11.1.0 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "image-optimization",
     "status": "active",
     "active": true,
     "installed": "1.6.9",
     "available": "1.7.6",
     "priority": "P1",
     "vulns": [
      {
       "name": "Image Optimization &#8211; Compress Images and Convert to WebP or AVIF [image-optimization] < 1.7.5",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2026-5821"
      },
      {
       "name": "Image Optimization &#8211; Compress Images and Convert to WebP or AVIF [image-optimization] < 1.7.2",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-25387"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.6.9 -> 1.7.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "jet-menu",
     "status": "active",
     "active": true,
     "installed": "2.4.8",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "JetMenu [jet-menu] < 2.4.9.1",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2025-26953"
      },
      {
       "name": "JetMenu [jet-menu] < 2.4.11.2",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-53987"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "mainwp-child",
     "status": "active",
     "active": true,
     "installed": "6.0",
     "available": "6.2",
     "priority": "P1",
     "vulns": [
      {
       "name": "MainWP Child &#8211; Securely Connects to the MainWP Dashboard to Manage Multiple Sites [mainwp-child] < 6.1.2",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-27366"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 6.0 -> 6.2"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "shortpixel-image-optimiser",
     "status": "active",
     "active": true,
     "installed": "6.1.1",
     "available": "6.5.6",
     "priority": "P1",
     "vulns": [
      {
       "name": "ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 6.4.4",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-39471"
      },
      {
       "name": "ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 6.3.5",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-11378"
      },
      {
       "name": "ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 6.4.4",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-4335"
      },
      {
       "name": "ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 6.4.3",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-1246"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 6.1.1 -> 6.5.6 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "insert-headers-and-footers",
     "status": "active",
     "active": true,
     "installed": "2.3.0",
     "available": "2.3.9",
     "priority": "P1",
     "vulns": [
      {
       "name": "WPCode &#8211; Insert Headers and Footers + Custom Code Snippets &#8211; WordPress Code Manager [insert-headers-and-footers] < 2.3.6",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-8832"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 2.3.0 -> 2.3.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "admin-site-enhancements",
     "status": "active",
     "active": true,
     "installed": "7.9.10",
     "available": "9.1.2",
     "priority": "P2",
     "vulns": [
      {
       "name": "Admin and Site Enhancements (ASE) [admin-site-enhancements] < 8.4.1",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-32423"
      },
      {
       "name": "Admin and Site Enhancements (ASE) [admin-site-enhancements] < 8.1.0",
       "cvss": "2.7",
       "severity": "LOW",
       "cve": "CVE-2025-64255"
      },
      {
       "name": "Admin and Site Enhancements (ASE) [admin-site-enhancements] < 8.8.4",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-12083"
      },
      {
       "name": "Admin and Site Enhancements (ASE) [admin-site-enhancements] < 9.0.1",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-19615"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 7.9.10 -> 9.1.2 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "auto-alt-text",
     "status": "active",
     "active": true,
     "installed": "2.4.2",
     "available": "3.0.3",
     "priority": "P2",
     "vulns": [
      {
       "name": "Auto Alt Text [auto-alt-text] < 2.5.3",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-62866"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.4.2 -> 3.0.3 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "elementor",
     "status": "active",
     "active": true,
     "installed": "3.33.3",
     "available": "4.2.4",
     "priority": "P2",
     "vulns": [
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.35.6",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-32352"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 4.1.4",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-57619"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.33.4",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-11220"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.35.6",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-14732"
      }
     ],
     "vuln_count": 9,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.33.3 -> 4.2.4 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "mainwp-child-reports",
     "status": "active",
     "active": true,
     "installed": "2.2.6",
     "available": "2.3.1",
     "priority": "P2",
     "vulns": [
      {
       "name": "MainWP Child Reports [mainwp-child-reports] < 2.3",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-4299"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.2.6 -> 2.3.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "simple-download-monitor",
     "status": "active",
     "active": true,
     "installed": "3.9.35",
     "available": "4.1.1",
     "priority": "P2",
     "vulns": [
      {
       "name": "Simple Download Monitor [simple-download-monitor] < 4.0.6",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-2383"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.9.35 -> 4.1.1 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "smtp2go",
     "status": "active",
     "active": true,
     "installed": "1.13.1",
     "available": "1.17.1",
     "priority": "P2",
     "vulns": [
      {
       "name": "SMTP2GO for WordPress &#8211; Email Made Easy [smtp2go] < 1.17.0",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-7621"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 1.13.1 -> 1.17.1 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "duplicate-post",
     "status": "active",
     "active": true,
     "installed": "4.5",
     "available": "4.7",
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast Duplicate Post [duplicate-post] <= 4.6 (unfixed)",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-53740"
      },
      {
       "name": "Yoast Duplicate Post [duplicate-post] <= 4.6 (unfixed)",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-53739"
      },
      {
       "name": "Yoast Duplicate Post [duplicate-post] < 4.6",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-1217"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 4.5 -> 4.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "wordpress-seo",
     "status": "active",
     "active": true,
     "installed": "24.3",
     "available": "28.5",
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 26.6",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-14481"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 27.2",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-3427"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 26.9",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-1293"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 28.1",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-15425"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 24.3 -> 28.5 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "wordpress-seo-premium",
     "status": "active",
     "active": true,
     "installed": "24.3",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast SEO Premium [wordpress-seo-premium] < 27.6.1",
       "cvss": "6.6",
       "severity": "MEDIUM",
       "cve": "CVE-2026-10821"
      },
      {
       "name": "Yoast SEO Premium [wordpress-seo-premium] < 26.7",
       "cvss": "5.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-40722"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "nitropack",
     "status": "inactive",
     "active": false,
     "installed": "1.18.5",
     "available": "1.20.0",
     "priority": "P2",
     "vulns": [
      {
       "name": "NitroPack \u2013 Performance, Page Speed &amp; Cache Plugin for Core Web Vitals, CDN &amp; Image Optimization [nitropack] < 1.19.4",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-39669"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.18.5 -> 1.20.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "search-filter-pro",
     "status": "inactive",
     "active": false,
     "installed": "2.5.19",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Search & Filter Pro [search-filter-pro] < 2.5.20",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-1528"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "agile-store-locator",
     "status": "active",
     "active": true,
     "installed": "4.10.13",
     "available": "5.4.6",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 4.10.13 -> 5.4.6 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "prevent-browser-caching",
     "status": "active",
     "active": true,
     "installed": "2.3.5",
     "available": "3.2.1",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.3.5 -> 3.2.1 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "eps-301-redirects",
     "status": "active",
     "active": true,
     "installed": "2.80",
     "available": "2.85",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 2.80 -> 2.85 (skipped 5 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "advanced-custom-fields-pro",
     "status": "active",
     "active": true,
     "installed": "6.3.12",
     "available": "6.8.10",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "multi-minor jump 6.3.12 -> 6.8.10 (skipped 5 minor releases)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE WITH CAPTURE \u2014 routine bump but on a sitewide-impact plugin; watch the diff closely."
    },
    {
     "plugin": "cookie-law-info",
     "status": "active",
     "active": true,
     "installed": "3.3.5",
     "available": "3.5.6",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 3.3.5 -> 3.5.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "dynamic-content-for-elementor",
     "status": "active",
     "active": true,
     "installed": "3.3.3",
     "available": "3.4.13",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "minor version bump 3.3.3 -> 3.4.13",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE WITH CAPTURE \u2014 routine bump but on a sitewide-impact plugin; watch the diff closely."
    },
    {
     "plugin": "font-awesome",
     "status": "active",
     "active": true,
     "installed": "5.1.0",
     "available": "5.2.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 5.1.0 -> 5.2.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "headers-security-advanced-hsts-wp",
     "status": "active",
     "active": true,
     "installed": "5.0.44",
     "available": "5.3.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.0.44 -> 5.3.5 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "page-links-to",
     "status": "active",
     "active": true,
     "installed": "3.3.7",
     "available": "3.4.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 3.3.7 -> 3.4.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "patchstack",
     "status": "active",
     "active": true,
     "installed": "2.3.5",
     "available": "2.3.7",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 2.3.5 -> 2.3.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wp-all-export-pro",
     "status": "active",
     "active": true,
     "installed": "1.9.11",
     "available": "1.9.15",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.9.11 -> 1.9.15"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wpe-site-migration",
     "status": "active",
     "active": true,
     "installed": "1.7.1",
     "available": "1.8.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.7.1 -> 1.8.5"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wp-search-with-algolia",
     "status": "active",
     "active": true,
     "installed": "2.10.3",
     "available": "2.14.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 2.10.3 -> 2.14.1 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "cachebuster",
     "status": "inactive",
     "active": false,
     "installed": "1.8",
     "available": "1.10",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.8 -> 1.10"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "megamenu",
     "status": "inactive",
     "active": false,
     "installed": "3.6.2",
     "available": "3.10.8",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.6.2 -> 3.10.8 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "simple-banner",
     "status": "inactive",
     "active": false,
     "installed": "3.1.0",
     "available": "3.3.2",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 3.1.0 -> 3.3.2"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    }
   ],
   "p0": 4,
   "p1": 5,
   "total_updates": 33
  },
  "wpengine:primaticsarchv": {
   "platform": "wpengine",
   "install": "primaticsarchv",
   "environment": "development",
   "domain": "primaticsarchv.wpenginepowered.com",
   "siteurl": "https://primaticsarchv.wpenginepowered.com",
   "core": "6.4.10",
   "core_update": "7.1",
   "theme": "theme",
   "updates": [
    {
     "plugin": "advanced-custom-fields-pro",
     "status": "active",
     "active": true,
     "installed": "6.2.6.1",
     "available": "6.8.10",
     "priority": "P0",
     "vulns": [
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.2.10",
       "cvss": "9.9",
       "severity": "CRITICAL",
       "cve": "CVE-2024-34762"
      },
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.2.10",
       "cvss": "8.5",
       "severity": "HIGH",
       "cve": "CVE-2024-34761"
      },
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.3.8",
       "cvss": "6.6",
       "severity": "MEDIUM",
       "cve": "CVE-2024-9529"
      },
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.3.0",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-4565"
      }
     ],
     "vuln_count": 10,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "multi-minor jump 6.2.6.1 -> 6.8.10 (skipped 6 minor releases)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "gravityforms",
     "status": "active",
     "active": true,
     "installed": "2.8.17",
     "available": "3.1.1",
     "priority": "P0",
     "vulns": [
      {
       "name": "Gravity Forms [gravityforms] < 2.9.21",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2025-12352"
      },
      {
       "name": "Gravity Forms [gravityforms] < 2.10.1",
       "cvss": "9.6",
       "severity": "CRITICAL",
       "cve": "CVE-2026-48866"
      },
      {
       "name": "Gravity Forms [gravityforms] < 2.9.22",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2025-12974"
      },
      {
       "name": "Gravity Forms [gravityforms] < 3.0.3",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2026-19513"
      }
     ],
     "vuln_count": 17,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.8.17 -> 3.1.1 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "translatepress-multilingual",
     "status": "active",
     "active": true,
     "installed": "2.7.1",
     "available": "3.3.6",
     "priority": "P0",
     "vulns": [
      {
       "name": "TranslatePress &#8211; Translate Multilingual sites with AI Translation [translatepress-multilingual] < 3.3.3",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2026-78267"
      },
      {
       "name": "TranslatePress &#8211; Translate Multilingual sites with AI Translation [translatepress-multilingual] < 3.3.2",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2026-19632"
      },
      {
       "name": "TranslatePress &#8211; Translate Multilingual sites with AI Translation [translatepress-multilingual] < 2.10.3",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2025-58592"
      },
      {
       "name": "TranslatePress &#8211; Translate Multilingual sites with AI Translation [translatepress-multilingual] < 3.3",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-18510"
      }
     ],
     "vuln_count": 11,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.7.1 -> 3.3.6 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "popup-maker",
     "status": "active",
     "active": true,
     "installed": "1.18.2",
     "available": "1.25.0",
     "priority": "P1",
     "vulns": [
      {
       "name": "Popup Maker &#8211; Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.23.0",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-8848"
      },
      {
       "name": "Popup Maker &#8211; Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.24.0",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-28177"
      },
      {
       "name": "Popup Maker &#8211; Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.20.3",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-24746"
      },
      {
       "name": "Popup Maker &#8211; Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.20.5",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-4205"
      }
     ],
     "vuln_count": 10,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 1.18.2 -> 1.25.0 (skipped 7 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "wp-smushit",
     "status": "active",
     "active": true,
     "installed": "3.15.5",
     "available": "4.3.3",
     "priority": "P1",
     "vulns": [
      {
       "name": "Smush \u2013 Image Optimization, Compression, Lazy Load, WebP &amp; CDN [wp-smushit] < 4.3.0",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-81285"
      },
      {
       "name": "Smush \u2013 Image Optimization, Compression, Lazy Load, WebP &amp; CDN [wp-smushit] < 3.16.5",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2023-3352"
      },
      {
       "name": "Smush \u2013 Image Optimization, Compression, Lazy Load, WebP &amp; CDN [wp-smushit] < 3.17.1",
       "cvss": "4.1",
       "severity": "MEDIUM",
       "cve": "CVE-2025-22288"
      },
      {
       "name": "Smush \u2013 Image Optimization, Compression, Lazy Load, WebP &amp; CDN [wp-smushit] < 4.3.2",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-19223"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.15.5 -> 4.3.3 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "wordpress-importer",
     "status": "active",
     "active": true,
     "installed": "0.8.2",
     "available": "0.9.6",
     "priority": "P1",
     "vulns": [
      {
       "name": "WordPress Importer [wordpress-importer] < 0.8.4",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2024-13889"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 0.8.2 -> 0.9.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "insert-headers-and-footers",
     "status": "inactive",
     "active": false,
     "installed": "2.1.8",
     "available": "2.3.9",
     "priority": "P1",
     "vulns": [
      {
       "name": "WPCode &#8211; Insert Headers and Footers + Custom Code Snippets &#8211; WordPress Code Manager [insert-headers-and-footers] < 2.3.6",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-8832"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.1.8 -> 2.3.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "acf-to-rest-api",
     "status": "active",
     "active": true,
     "installed": "3.3.3",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "ACF to REST API [acf-to-rest-api] <= 3.3.4 (unfixed + closed)",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-62979"
      },
      {
       "name": "ACF to REST API [acf-to-rest-api] <= 3.3.4 (unfixed + closed)",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-12030"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "better-wp-security",
     "status": "active",
     "active": true,
     "installed": "9.3.1",
     "available": "10.0.3",
     "priority": "P2",
     "vulns": [
      {
       "name": "Kadence Security \u2013 Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 9.3.2",
       "cvss": "3.7",
       "severity": "LOW",
       "cve": "CVE-2022-44593"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 9.3.1 -> 10.0.3 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "wp-mail-smtp",
     "status": "active",
     "active": true,
     "installed": "3.11.1",
     "available": "4.9.0",
     "priority": "P2",
     "vulns": [
      {
       "name": "WP Mail SMTP by WPForms &#8211; The Most Popular SMTP and Email Log Plugin [wp-mail-smtp] < 4.1.0",
       "cvss": "2.7",
       "severity": "LOW",
       "cve": "CVE-2024-6694"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.11.1 -> 4.9.0 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "duplicate-post",
     "status": "active",
     "active": true,
     "installed": "4.5",
     "available": "4.7",
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast Duplicate Post [duplicate-post] <= 4.6 (unfixed)",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-53740"
      },
      {
       "name": "Yoast Duplicate Post [duplicate-post] <= 4.6 (unfixed)",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-53739"
      },
      {
       "name": "Yoast Duplicate Post [duplicate-post] < 4.6",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-1217"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 4.5 -> 4.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "pantheon-advanced-page-cache",
     "status": "active",
     "active": true,
     "installed": "1.4.2",
     "available": "2.1.2",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 1.4.2 -> 2.1.2 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "akismet",
     "status": "active",
     "active": true,
     "installed": "5.3.1",
     "available": "5.7.2",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.3.1 -> 5.7.2 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "force-regenerate-thumbnails",
     "status": "active",
     "active": true,
     "installed": "2.1.3",
     "available": "2.3.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.1.3 -> 2.3.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "redirection",
     "status": "active",
     "active": true,
     "installed": "5.4.2",
     "available": "5.10.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.4.2 -> 5.10.0 (skipped 6 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "simple-page-ordering",
     "status": "active",
     "active": true,
     "installed": "2.6.3",
     "available": "2.8.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.6.3 -> 2.8.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "autodescription",
     "status": "active",
     "active": true,
     "installed": "5.0.4",
     "available": "5.1.4",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 5.0.4 -> 5.1.4"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "translatepress-developer",
     "status": "active",
     "active": true,
     "installed": "1.2.4",
     "available": "1.8.7",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 1.2.4 -> 1.8.7 (skipped 6 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    }
   ],
   "p0": 3,
   "p1": 4,
   "total_updates": 17
  },
  "wpengine:p1hdev": {
   "platform": "wpengine",
   "install": "p1hdev",
   "environment": "development",
   "domain": "p1hdev.wpenginepowered.com",
   "siteurl": "http://p1hdev.wpenginepowered.com",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "bootscore-child",
   "updates": [
    {
     "plugin": "mainwp-child",
     "status": "active",
     "active": true,
     "installed": "5.4.0.1",
     "available": "6.2",
     "priority": "P1",
     "vulns": [
      {
       "name": "MainWP Child &#8211; Securely Connects to the MainWP Dashboard to Manage Multiple Sites [mainwp-child] < 6.1.2",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-27366"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 5.4.0.1 -> 6.2 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "insert-headers-and-footers",
     "status": "active",
     "active": true,
     "installed": "2.2.6",
     "available": "2.3.9",
     "priority": "P1",
     "vulns": [
      {
       "name": "WPCode &#8211; Insert Headers and Footers + Custom Code Snippets &#8211; WordPress Code Manager [insert-headers-and-footers] < 2.3.6",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-8832"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.2.6 -> 2.3.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "contact-form-7",
     "status": "active",
     "active": true,
     "installed": "6.0.4",
     "available": "6.1.7",
     "priority": "P2",
     "vulns": [
      {
       "name": "Contact Form 7 [contact-form-7] < 6.0.6",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-3247"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 6.0.4 -> 6.1.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "flamingo",
     "status": "active",
     "active": true,
     "installed": "2.5",
     "available": "2.6.4",
     "priority": "P2",
     "vulns": [
      {
       "name": "Flamingo [flamingo] < 2.6.3",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-12853"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.5 -> 2.6.4"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "stop-user-enumeration",
     "status": "active",
     "active": true,
     "installed": "1.6.3",
     "available": "1.7.8",
     "priority": "P2",
     "vulns": [
      {
       "name": "Stop User Enumeration [stop-user-enumeration] < 1.7.3",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-4302"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.6.3 -> 1.7.8"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "wp-file-manager",
     "status": "active",
     "active": true,
     "installed": "8.0.1",
     "available": "8.0.4",
     "priority": "P2",
     "vulns": [
      {
       "name": "File Manager [wp-file-manager] < 8.0.4",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-6382"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 8.0.1 -> 8.0.4"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "duplicate-post",
     "status": "active",
     "active": true,
     "installed": "4.5",
     "available": "4.7",
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast Duplicate Post [duplicate-post] <= 4.6 (unfixed)",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-53740"
      },
      {
       "name": "Yoast Duplicate Post [duplicate-post] <= 4.6 (unfixed)",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-53739"
      },
      {
       "name": "Yoast Duplicate Post [duplicate-post] < 4.6",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-1217"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 4.5 -> 4.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "wordpress-seo",
     "status": "active",
     "active": true,
     "installed": "24.6",
     "available": "28.5",
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 26.6",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-14481"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 27.2",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-3427"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 26.9",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-1293"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 28.1",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-15425"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 24.6 -> 28.5 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "prevent-browser-caching",
     "status": "active",
     "active": true,
     "installed": "2.3.5",
     "available": "3.2.1",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.3.5 -> 3.2.1 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "advanced-custom-fields-pro",
     "status": "active",
     "active": true,
     "installed": "6.3.12",
     "available": "6.8.10",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "multi-minor jump 6.3.12 -> 6.8.10 (skipped 5 minor releases)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE WITH CAPTURE \u2014 routine bump but on a sitewide-impact plugin; watch the diff closely."
    },
    {
     "plugin": "cookie-law-info",
     "status": "active",
     "active": true,
     "installed": "3.2.8",
     "available": "3.5.6",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.2.8 -> 3.5.6 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "font-awesome",
     "status": "active",
     "active": true,
     "installed": "5.0.1",
     "available": "5.2.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 5.0.1 -> 5.2.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "megamenu",
     "status": "active",
     "active": true,
     "installed": "3.4.1",
     "available": "3.10.8",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.4.1 -> 3.10.8 (skipped 6 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "redirection",
     "status": "active",
     "active": true,
     "installed": "5.5.2",
     "available": "5.10.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.5.2 -> 5.10.0 (skipped 5 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "safe-svg",
     "status": "active",
     "active": true,
     "installed": "2.3.1",
     "available": "2.5.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.3.1 -> 2.5.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "disable-wp-rest-api",
     "status": "inactive",
     "active": false,
     "installed": "2.6.4",
     "available": "2.6.9",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 2.6.4 -> 2.6.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "headers-security-advanced-hsts-wp",
     "status": "inactive",
     "active": false,
     "installed": "5.0.42",
     "available": "5.3.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.0.42 -> 5.3.5 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    }
   ],
   "p0": 0,
   "p1": 2,
   "total_updates": 17
  },
  "wpengine:galileoprd": {
   "platform": "wpengine",
   "install": "galileoprd",
   "environment": "production",
   "domain": "www.galileotp.com",
   "siteurl": "https://www.galileotp.com",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "theme",
   "updates": [
    {
     "plugin": "acf-to-rest-api",
     "status": "active",
     "active": true,
     "installed": "3.3.4",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "ACF to REST API [acf-to-rest-api] <= 3.3.4 (unfixed + closed)",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-62979"
      },
      {
       "name": "ACF to REST API [acf-to-rest-api] <= 3.3.4 (unfixed + closed)",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-12030"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    }
   ],
   "p0": 0,
   "p1": 0,
   "total_updates": 0
  },
  "wpengine:lismarprd": {
   "platform": "wpengine",
   "install": "lismarprd",
   "environment": "production",
   "domain": "www.lismar.com",
   "siteurl": "https://www.lismar.com",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "theme",
   "updates": [
    {
     "plugin": "perfmatters",
     "status": "inactive",
     "active": false,
     "installed": "2.4.0",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "Perfmatters [perfmatters] < 2.6.5",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-13251"
      },
      {
       "name": "Perfmatters [perfmatters] < 2.6.4",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-56047"
      },
      {
       "name": "Perfmatters [perfmatters] < 2.6.5",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-57671"
      },
      {
       "name": "Perfmatters [perfmatters] < 2.6.0",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-4350"
      }
     ],
     "vuln_count": 5,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "acf-to-rest-api",
     "status": "active",
     "active": true,
     "installed": "3.3.4",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "ACF to REST API [acf-to-rest-api] <= 3.3.4 (unfixed + closed)",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-62979"
      },
      {
       "name": "ACF to REST API [acf-to-rest-api] <= 3.3.4 (unfixed + closed)",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-12030"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    }
   ],
   "p0": 0,
   "p1": 1,
   "total_updates": 0
  },
  "wpengine:trustmi2025dev": {
   "platform": "wpengine",
   "install": "trustmi2025dev",
   "environment": "development",
   "domain": "trustmi2025dev.wpenginepowered.com",
   "siteurl": "https://trustmi2025dev.wpenginepowered.com",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "genesis-block-theme",
   "updates": [
    {
     "plugin": "genesis-blocks",
     "status": "active",
     "active": true,
     "installed": "3.1.5",
     "available": "3.1.11",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 3.1.5 -> 3.1.11"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "akismet",
     "status": "inactive",
     "active": false,
     "installed": "5.3.5",
     "available": "5.7.2",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.3.5 -> 5.7.2 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    }
   ],
   "p0": 0,
   "p1": 0,
   "total_updates": 2
  },
  "wpengine:p1hprd": {
   "platform": "wpengine",
   "install": "p1hprd",
   "environment": "production",
   "domain": "www.projectonehealth.org",
   "siteurl": "http://www.projectonehealth.org",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "bootscore-child",
   "updates": [
    {
     "plugin": "mainwp-child",
     "status": "active",
     "active": true,
     "installed": "6.1.1",
     "available": "6.2",
     "priority": "P1",
     "vulns": [
      {
       "name": "MainWP Child &#8211; Securely Connects to the MainWP Dashboard to Manage Multiple Sites [mainwp-child] < 6.1.2",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-27366"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 6.1.1 -> 6.2"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "admin-site-enhancements",
     "status": "active",
     "active": true,
     "installed": "8.8.3",
     "available": "9.1.2",
     "priority": "P2",
     "vulns": [
      {
       "name": "Admin and Site Enhancements (ASE) [admin-site-enhancements] < 8.8.4",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-12083"
      },
      {
       "name": "Admin and Site Enhancements (ASE) [admin-site-enhancements] < 9.0.1",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-19615"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 8.8.3 -> 9.1.2 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "flamingo",
     "status": "active",
     "active": true,
     "installed": "2.6.2",
     "available": "2.6.4",
     "priority": "P2",
     "vulns": [
      {
       "name": "Flamingo [flamingo] < 2.6.3",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-12853"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 2.6.2 -> 2.6.4"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "simple-cloudflare-turnstile",
     "status": "active",
     "active": true,
     "installed": "1.40.0",
     "available": "1.43.1",
     "priority": "P2",
     "vulns": [
      {
       "name": "Simple CAPTCHA with Cloudflare Turnstile [simple-cloudflare-turnstile] < 1.42.3",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-66632"
      },
      {
       "name": "Simple CAPTCHA with Cloudflare Turnstile [simple-cloudflare-turnstile] < 1.42.3",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-85116"
      },
      {
       "name": "Simple CAPTCHA with Cloudflare Turnstile [simple-cloudflare-turnstile] < 1.42.3",
       "cvss": "5.6",
       "severity": "MEDIUM",
       "cve": "CVE-2026-66674"
      },
      {
       "name": "Simple CAPTCHA with Cloudflare Turnstile [simple-cloudflare-turnstile] < 1.42.0",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-15239"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 1.40.0 -> 1.43.1 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "wp-security-audit-log",
     "status": "active",
     "active": true,
     "installed": "5.6.4",
     "available": "5.6.6",
     "priority": "P2",
     "vulns": [
      {
       "name": "WP Activity Log [wp-security-audit-log] < 5.6.5",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-65512"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 5.6.4 -> 5.6.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "wordpress-seo",
     "status": "active",
     "active": true,
     "installed": "27.7",
     "available": "28.5",
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 28.1",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-15425"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 27.7 -> 28.5 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "prevent-browser-caching",
     "status": "active",
     "active": true,
     "installed": "2.3.6",
     "available": "3.2.1",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.3.6 -> 3.2.1 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "advanced-custom-fields-pro",
     "status": "active",
     "active": true,
     "installed": "6.8.0.1",
     "available": "6.8.10",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "patch bump 6.8.0.1 -> 6.8.10",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE WITH CAPTURE \u2014 routine bump but on a sitewide-impact plugin; watch the diff closely."
    },
    {
     "plugin": "contact-form-7",
     "status": "active",
     "active": true,
     "installed": "6.1.6",
     "available": "6.1.7",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 6.1.6 -> 6.1.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "font-awesome",
     "status": "active",
     "active": true,
     "installed": "5.1.5",
     "available": "5.2.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 5.1.5 -> 5.2.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "headers-security-advanced-hsts-wp",
     "status": "active",
     "active": true,
     "installed": "5.3.2",
     "available": "5.3.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 5.3.2 -> 5.3.5"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "megamenu",
     "status": "active",
     "active": true,
     "installed": "3.10.5",
     "available": "3.10.8",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 3.10.5 -> 3.10.8"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "redirection",
     "status": "active",
     "active": true,
     "installed": "5.7.5",
     "available": "5.10.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.7.5 -> 5.10.0 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "simple-banner",
     "status": "active",
     "active": true,
     "installed": "3.3.0",
     "available": "3.3.2",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 3.3.0 -> 3.3.2"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "stop-user-enumeration",
     "status": "active",
     "active": true,
     "installed": "1.7.7",
     "available": "1.7.8",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.7.7 -> 1.7.8"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "insert-headers-and-footers",
     "status": "active",
     "active": true,
     "installed": "2.3.6",
     "available": "2.3.9",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 2.3.6 -> 2.3.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    }
   ],
   "p0": 0,
   "p1": 1,
   "total_updates": 16
  },
  "wpengine:ascmlssplitstg": {
   "platform": "wpengine",
   "install": "ascmlssplitstg",
   "environment": "staging",
   "domain": "ascmlssplitstg.wpenginepowered.com",
   "siteurl": "https://ascmlssplitstg.wpenginepowered.com",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "hello-ascential",
   "updates": [
    {
     "plugin": "elementor-pro",
     "status": "active",
     "active": true,
     "installed": "3.27.1",
     "available": "3.28.4",
     "priority": "P0",
     "vulns": [
      {
       "name": "Elementor Pro [elementor-pro] < 4.2.2",
       "cvss": "9.0",
       "severity": "CRITICAL",
       "cve": "CVE-2026-32475"
      },
      {
       "name": "Elementor Pro [elementor-pro] < 3.29.1",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-50555"
      },
      {
       "name": "Elementor Pro [elementor-pro] < 3.29.1",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-3076"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "minor version bump 3.27.1 -> 3.28.4",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "woocommerce",
     "status": "inactive",
     "active": false,
     "installed": "9.8.1",
     "available": "11.1.0",
     "priority": "P0",
     "vulns": [
      {
       "name": "WooCommerce [woocommerce] == 7.1.0 (unfixed)",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2022-50972"
      },
      {
       "name": "WooCommerce [woocommerce] < 11.0",
       "cvss": "7.6",
       "severity": "HIGH",
       "cve": "CVE-2026-57777"
      },
      {
       "name": "WooCommerce [woocommerce] < 11.1.0",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-48888"
      },
      {
       "name": "WooCommerce [woocommerce] < 10.4.3",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-15033"
      }
     ],
     "vuln_count": 6,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 9.8.1 -> 11.1.0 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "jet-menu",
     "status": "active",
     "active": true,
     "installed": "2.4.8",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "JetMenu [jet-menu] < 2.4.9.1",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2025-26953"
      },
      {
       "name": "JetMenu [jet-menu] < 2.4.11.2",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-53987"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "mainwp-child",
     "status": "active",
     "active": true,
     "installed": "5.4.0.5",
     "available": "6.2",
     "priority": "P1",
     "vulns": [
      {
       "name": "MainWP Child &#8211; Securely Connects to the MainWP Dashboard to Manage Multiple Sites [mainwp-child] < 6.1.2",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-27366"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 5.4.0.5 -> 6.2 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "shortpixel-image-optimiser",
     "status": "active",
     "active": true,
     "installed": "6.1.4",
     "available": "6.5.6",
     "priority": "P1",
     "vulns": [
      {
       "name": "ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 6.4.4",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-39471"
      },
      {
       "name": "ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 6.3.5",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-11378"
      },
      {
       "name": "ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 6.4.4",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-4335"
      },
      {
       "name": "ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 6.4.3",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-1246"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 6.1.4 -> 6.5.6 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "revslider",
     "status": "active",
     "active": true,
     "installed": "6.7.18",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "Slider Revolution [revslider] < 7.0.11",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-6692"
      },
      {
       "name": "Slider Revolution [revslider] < 7.1.0",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-57678"
      },
      {
       "name": "Slider Revolution [revslider] < 6.7.37",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-9217"
      },
      {
       "name": "Slider Revolution [revslider] < 6.7.38",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-10249"
      }
     ],
     "vuln_count": 9,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "updraftplus",
     "status": "active",
     "active": true,
     "installed": "1.25.3",
     "available": "1.26.7",
     "priority": "P1",
     "vulns": [
      {
       "name": "UpdraftPlus: WP Backup &amp; Migration Plugin [updraftplus] < 1.26.5",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2026-10795"
      },
      {
       "name": "UpdraftPlus: WP Backup &amp; Migration Plugin [updraftplus] < 1.26.7",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-76549"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "minor version bump 1.25.3 -> 1.26.7",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "wp-optimize",
     "status": "active",
     "active": true,
     "installed": "4.1.1",
     "available": "4.6.1",
     "priority": "P1",
     "vulns": [
      {
       "name": "WP-Optimize \u2013 Cache, Compress images, Minify &amp; Clean database to boost page speed &amp; performance [wp-optimize] < 4.5.3",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2026-7252"
      },
      {
       "name": "WP-Optimize \u2013 Cache, Compress images, Minify &amp; Clean database to boost page speed &amp; performance [wp-optimize] < 4.2.0",
       "cvss": "4.1",
       "severity": "MEDIUM",
       "cve": "CVE-2025-3951"
      },
      {
       "name": "WP-Optimize \u2013 Cache, Compress images, Minify &amp; Clean database to boost page speed &amp; performance [wp-optimize] < 4.5.1",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-2712"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "multi-minor jump 4.1.1 -> 4.6.1 (skipped 5 minor releases)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "insert-headers-and-footers",
     "status": "active",
     "active": true,
     "installed": "2.2.7",
     "available": "2.3.9",
     "priority": "P1",
     "vulns": [
      {
       "name": "WPCode &#8211; Insert Headers and Footers + Custom Code Snippets &#8211; WordPress Code Manager [insert-headers-and-footers] < 2.3.6",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-8832"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.2.7 -> 2.3.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "link-whisper",
     "status": "inactive",
     "active": false,
     "installed": "0.8.0",
     "available": "0.9.7",
     "priority": "P1",
     "vulns": [
      {
       "name": "Link Whisper Free [link-whisper] < 0.9.1",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2025-11262"
      },
      {
       "name": "Link Whisper Free [link-whisper] < 0.8.9",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2025-67927"
      },
      {
       "name": "Link Whisper Free [link-whisper] < 0.9.3",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-22357"
      },
      {
       "name": "Link Whisper Free [link-whisper] < 0.9.5",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-57333"
      }
     ],
     "vuln_count": 8,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 0.8.0 -> 0.9.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "hide-my-wp",
     "status": "inactive",
     "active": false,
     "installed": "5.4.03",
     "available": "7.0.11",
     "priority": "P1",
     "vulns": [
      {
       "name": "Hide My WP Ghost &#8211; Security &amp; Firewall [hide-my-wp] < 7.0.10",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-81806"
      },
      {
       "name": "Hide My WP Ghost &#8211; Security &amp; Firewall [hide-my-wp] <= 6.2.12 (unfixed)",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2025-69098"
      },
      {
       "name": "Hide My WP Ghost &#8211; Security &amp; Firewall [hide-my-wp] < 7.0.00",
       "cvss": "4.7",
       "severity": "MEDIUM",
       "cve": "CVE-2026-39484"
      },
      {
       "name": "Hide My WP Ghost &#8211; Security &amp; Firewall [hide-my-wp] < 7.0.07",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-59546"
      }
     ],
     "vuln_count": 5,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 5.4.03 -> 7.0.11 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wpide",
     "status": "inactive",
     "active": false,
     "installed": "3.5.2",
     "available": "3.5.9",
     "priority": "P1",
     "vulns": [
      {
       "name": "WPIDE &#8211; File Manager &amp; Code Editor [wpide] < 3.5.7",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-57766"
      },
      {
       "name": "WPIDE &#8211; File Manager &amp; Code Editor [wpide] < 3.5.8",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-66440"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 3.5.2 -> 3.5.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "alttext-ai",
     "status": "active",
     "active": true,
     "installed": "1.9.94",
     "available": "1.10.38",
     "priority": "P2",
     "vulns": [
      {
       "name": "Alt Text AI &#8211; Automatically generate image alt text for SEO and accessibility [alttext-ai] < 1.10.18",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-25348"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.9.94 -> 1.10.38"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "elementor",
     "status": "active",
     "active": true,
     "installed": "3.28.3",
     "available": "4.2.4",
     "priority": "P2",
     "vulns": [
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.29.1",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-50555"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.35.6",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-32352"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 4.1.4",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-57619"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.30.3",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-4566"
      }
     ],
     "vuln_count": 14,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.28.3 -> 4.2.4 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "limit-login-attempts-reloaded",
     "status": "active",
     "active": true,
     "installed": "2.26.18",
     "available": "3.3.8",
     "priority": "P2",
     "vulns": [
      {
       "name": "Limit Login Attempts Security &#8211; Login Security, 2FA, Firewall, Brute Force Prevention [limit-login-attempts-reloaded] < 3.3.5",
       "cvss": "3.7",
       "severity": "LOW",
       "cve": "CVE-2026-18356"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.26.18 -> 3.3.8 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "search-filter-pro",
     "status": "active",
     "active": true,
     "installed": "2.5.19",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Search & Filter Pro [search-filter-pro] < 2.5.20",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-1528"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "simple-download-monitor",
     "status": "active",
     "active": true,
     "installed": "3.9.28",
     "available": "4.1.1",
     "priority": "P2",
     "vulns": [
      {
       "name": "Simple Download Monitor [simple-download-monitor] < 3.9.35",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-58197"
      },
      {
       "name": "Simple Download Monitor [simple-download-monitor] < 3.9.34",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-8977"
      },
      {
       "name": "Simple Download Monitor [simple-download-monitor] < 4.0.6",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-2383"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.9.28 -> 4.1.1 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "smtp2go",
     "status": "active",
     "active": true,
     "installed": "1.11.1",
     "available": "1.17.1",
     "priority": "P2",
     "vulns": [
      {
       "name": "SMTP2GO for WordPress &#8211; Email Made Easy [smtp2go] < 1.12.2",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-54011"
      },
      {
       "name": "SMTP2GO for WordPress &#8211; Email Made Easy [smtp2go] < 1.17.0",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-7621"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 1.11.1 -> 1.17.1 (skipped 6 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "svg-support",
     "status": "active",
     "active": true,
     "installed": "2.5.14",
     "available": "2.6.1",
     "priority": "P2",
     "vulns": [
      {
       "name": "SVG Support [svg-support] < 2.5.15",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-48973"
      },
      {
       "name": "SVG Support [svg-support] < 2.5.17",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-13340"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.5.14 -> 2.6.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "duplicate-post",
     "status": "active",
     "active": true,
     "installed": "4.5",
     "available": "4.7",
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast Duplicate Post [duplicate-post] <= 4.6 (unfixed)",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-53740"
      },
      {
       "name": "Yoast Duplicate Post [duplicate-post] <= 4.6 (unfixed)",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-53739"
      },
      {
       "name": "Yoast Duplicate Post [duplicate-post] < 4.6",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-1217"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 4.5 -> 4.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "wordpress-seo",
     "status": "active",
     "active": true,
     "installed": "24.9",
     "available": "28.5",
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 26.6",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-14481"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 27.2",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-3427"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 26.9",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-1293"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 28.1",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-15425"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 24.9 -> 28.5 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "wordpress-seo-premium",
     "status": "active",
     "active": true,
     "installed": "24.3",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast SEO Premium [wordpress-seo-premium] < 27.6.1",
       "cvss": "6.6",
       "severity": "MEDIUM",
       "cve": "CVE-2026-10821"
      },
      {
       "name": "Yoast SEO Premium [wordpress-seo-premium] < 26.7",
       "cvss": "5.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-40722"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "debug-log-manager",
     "status": "inactive",
     "active": false,
     "installed": "2.3.5",
     "available": "2.5.2",
     "priority": "P2",
     "vulns": [
      {
       "name": "Debug Log Manager &#8211; Conveniently Monitor and Inspect Errors [debug-log-manager] < 2.5.1",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-9016"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.3.5 -> 2.5.2"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wp-discussion-board",
     "status": "inactive",
     "active": false,
     "installed": "2.5.5",
     "available": "2.6.0",
     "priority": "P2",
     "vulns": [
      {
       "name": "Discussion Board &#8211; WordPress Forum Plugin [wp-discussion-board] < 2.5.6",
       "cvss": "6.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-8483"
      },
      {
       "name": "Discussion Board &#8211; WordPress Forum Plugin [wp-discussion-board] < 2.5.8",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-69023"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.5.5 -> 2.6.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "dracula-dark-mode",
     "status": "inactive",
     "active": false,
     "installed": "1.2.7",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Dracula Dark Mode \u2013  Accessibility, Reading Mode &amp; Dark Mode for WordPress [dracula-dark-mode] < 1.2.8 (closed)",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2024-13362"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "nitropack",
     "status": "inactive",
     "active": false,
     "installed": "1.18.0",
     "available": "1.20.0",
     "priority": "P2",
     "vulns": [
      {
       "name": "NitroPack \u2013 Performance, Page Speed &amp; Cache Plugin for Core Web Vitals, CDN &amp; Image Optimization [nitropack] < 1.19.4",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-39669"
      },
      {
       "name": "NitroPack \u2013 Performance, Page Speed &amp; Cache Plugin for Core Web Vitals, CDN &amp; Image Optimization [nitropack] < 1.18.5",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2025-8778"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.18.0 -> 1.20.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "query-monitor",
     "status": "inactive",
     "active": false,
     "installed": "3.17.2",
     "available": "4.0.7",
     "priority": "P2",
     "vulns": [
      {
       "name": "Query Monitor [query-monitor] < 3.20.4",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-4267"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.17.2 -> 4.0.7 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "sucuri-scanner",
     "status": "inactive",
     "active": false,
     "installed": "1.9.9",
     "available": "2.8",
     "priority": "P2",
     "vulns": [
      {
       "name": "Sucuri Security &#8211; Auditing, Malware Scanner and Security Hardening [sucuri-scanner] <= 2.7.3 (unfixed)",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-73033"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 1.9.9 -> 2.8 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "agile-store-locator",
     "status": "active",
     "active": true,
     "installed": "4.10.13",
     "available": "5.4.6",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 4.10.13 -> 5.4.6 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "online-active-users",
     "status": "inactive",
     "active": false,
     "installed": "2.6",
     "available": "3.4.4",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.6 -> 3.4.4 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "prevent-browser-caching",
     "status": "inactive",
     "active": false,
     "installed": "2.3.5",
     "available": "3.2.1",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.3.5 -> 3.2.1 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "eps-301-redirects",
     "status": "active",
     "active": true,
     "installed": "2.79",
     "available": "2.85",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 2.79 -> 2.85 (skipped 6 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "advanced-custom-fields-pro",
     "status": "active",
     "active": true,
     "installed": "6.4.0.1",
     "available": "6.8.10",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "multi-minor jump 6.4.0.1 -> 6.8.10 (skipped 4 minor releases)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE WITH CAPTURE \u2014 routine bump but on a sitewide-impact plugin; watch the diff closely."
    },
    {
     "plugin": "cookie-law-info",
     "status": "active",
     "active": true,
     "installed": "3.2.9",
     "available": "3.5.6",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.2.9 -> 3.5.6 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "duplicate-page",
     "status": "active",
     "active": true,
     "installed": "4.5.4",
     "available": "4.5.9",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 4.5.4 -> 4.5.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "dynamic-content-for-elementor",
     "status": "active",
     "active": true,
     "installed": "3.3.3",
     "available": "3.4.13",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "minor version bump 3.3.3 -> 3.4.13",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE WITH CAPTURE \u2014 routine bump but on a sitewide-impact plugin; watch the diff closely."
    },
    {
     "plugin": "font-awesome",
     "status": "active",
     "active": true,
     "installed": "5.0.1",
     "available": "5.2.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 5.0.1 -> 5.2.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "megamenu",
     "status": "active",
     "active": true,
     "installed": "3.5",
     "available": "3.10.8",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.5 -> 3.10.8 (skipped 5 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "page-links-to",
     "status": "active",
     "active": true,
     "installed": "3.3.7",
     "available": "3.4.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 3.3.7 -> 3.4.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "post-types-order",
     "status": "active",
     "active": true,
     "installed": "2.3.4",
     "available": "2.5.3",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.3.4 -> 2.5.3"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wp-revisions-control",
     "status": "active",
     "active": true,
     "installed": "1.4.3",
     "available": "1.4.4",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.4.3 -> 1.4.4"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wp-search-with-algolia",
     "status": "active",
     "active": true,
     "installed": "2.8.3",
     "available": "2.14.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 2.8.3 -> 2.14.1 (skipped 6 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wps-hide-login",
     "status": "active",
     "active": true,
     "installed": "1.9.17.2",
     "available": "1.9.19",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.9.17.2 -> 1.9.19"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "admin-taxonomy-filter",
     "status": "inactive",
     "active": false,
     "installed": "1.0.4",
     "available": "1.0.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.0.4 -> 1.0.5"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "cachebuster",
     "status": "inactive",
     "active": false,
     "installed": "1.8",
     "available": "1.10",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.8 -> 1.10"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "search-regex",
     "status": "inactive",
     "active": false,
     "installed": "3.1.2",
     "available": "3.4.4",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.1.2 -> 3.4.4 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wp-hide-security-enhancer",
     "status": "inactive",
     "active": false,
     "installed": "2.6.3",
     "available": "2.9.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 2.6.3 -> 2.9.1 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wp-mail-smtp",
     "status": "inactive",
     "active": false,
     "installed": "4.4.0",
     "available": "4.9.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 4.4.0 -> 4.9.0 (skipped 5 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    }
   ],
   "p0": 2,
   "p1": 10,
   "total_updates": 43
  },
  "wpengine:asctmsplitstg": {
   "platform": "wpengine",
   "install": "asctmsplitstg",
   "environment": "staging",
   "domain": "asctmsplitstg.wpenginepowered.com",
   "siteurl": "https://asctmsplitstg.wpenginepowered.com",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "hello-ascential",
   "updates": [
    {
     "plugin": "elementor-pro",
     "status": "active",
     "active": true,
     "installed": "3.30.1",
     "available": "4.2.3",
     "priority": "P0",
     "vulns": [
      {
       "name": "Elementor Pro [elementor-pro] < 4.2.2",
       "cvss": "9.0",
       "severity": "CRITICAL",
       "cve": "CVE-2026-32475"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.30.1 -> 4.2.3 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "mainwp-child",
     "status": "active",
     "active": true,
     "installed": "6.0",
     "available": "6.2",
     "priority": "P1",
     "vulns": [
      {
       "name": "MainWP Child &#8211; Securely Connects to the MainWP Dashboard to Manage Multiple Sites [mainwp-child] < 6.1.2",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-27366"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 6.0 -> 6.2"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "insert-headers-and-footers",
     "status": "active",
     "active": true,
     "installed": "2.3.4",
     "available": "2.3.9",
     "priority": "P1",
     "vulns": [
      {
       "name": "WPCode &#8211; Insert Headers and Footers + Custom Code Snippets &#8211; WordPress Code Manager [insert-headers-and-footers] < 2.3.6",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-8832"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 2.3.4 -> 2.3.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "wp-optimize",
     "status": "inactive",
     "active": false,
     "installed": "4.5.0",
     "available": "4.6.1",
     "priority": "P1",
     "vulns": [
      {
       "name": "WP-Optimize \u2013 Cache, Compress images, Minify &amp; Clean database to boost page speed &amp; performance [wp-optimize] < 4.5.3",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2026-7252"
      },
      {
       "name": "WP-Optimize \u2013 Cache, Compress images, Minify &amp; Clean database to boost page speed &amp; performance [wp-optimize] < 4.5.1",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-2712"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "minor version bump 4.5.0 -> 4.6.1",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "interactive-3d-flipbook-powered-physics-engine",
     "status": "active",
     "active": true,
     "installed": "1.16.18",
     "available": "1.16.22",
     "priority": "P2",
     "vulns": [
      {
       "name": "3D FlipBook \u2013 PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery [interactive-3d-flipbook-powered-physics-engine] <= 1.16.20 (unfixed)",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-74007"
      },
      {
       "name": "3D FlipBook \u2013 PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery [interactive-3d-flipbook-powered-physics-engine] < 1.16.21",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-15758"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.16.18 -> 1.16.22"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "admin-site-enhancements",
     "status": "active",
     "active": true,
     "installed": "8.4.1",
     "available": "9.1.2",
     "priority": "P2",
     "vulns": [
      {
       "name": "Admin and Site Enhancements (ASE) [admin-site-enhancements] < 8.8.4",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-12083"
      },
      {
       "name": "Admin and Site Enhancements (ASE) [admin-site-enhancements] < 9.0.1",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-19615"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 8.4.1 -> 9.1.2 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "elementor",
     "status": "active",
     "active": true,
     "installed": "3.35.5",
     "available": "4.2.4",
     "priority": "P2",
     "vulns": [
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.35.6",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-32352"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 4.1.4",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-57619"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.35.6",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-14732"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 4.0.5",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-6127"
      }
     ],
     "vuln_count": 8,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.35.5 -> 4.2.4 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "query-monitor",
     "status": "active",
     "active": true,
     "installed": "3.20.2",
     "available": "4.0.7",
     "priority": "P2",
     "vulns": [
      {
       "name": "Query Monitor [query-monitor] < 3.20.4",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-4267"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.20.2 -> 4.0.7 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "smtp2go",
     "status": "active",
     "active": true,
     "installed": "1.14.0",
     "available": "1.17.1",
     "priority": "P2",
     "vulns": [
      {
       "name": "SMTP2GO for WordPress &#8211; Email Made Easy [smtp2go] < 1.17.0",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-7621"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 1.14.0 -> 1.17.1 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "sucuri-scanner",
     "status": "active",
     "active": true,
     "installed": "2.6",
     "available": "2.8",
     "priority": "P2",
     "vulns": [
      {
       "name": "Sucuri Security &#8211; Auditing, Malware Scanner and Security Hardening [sucuri-scanner] <= 2.7.3 (unfixed)",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-73033"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.6 -> 2.8"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "duplicate-post",
     "status": "active",
     "active": true,
     "installed": "4.5",
     "available": "4.7",
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast Duplicate Post [duplicate-post] <= 4.6 (unfixed)",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-53740"
      },
      {
       "name": "Yoast Duplicate Post [duplicate-post] <= 4.6 (unfixed)",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-53739"
      },
      {
       "name": "Yoast Duplicate Post [duplicate-post] < 4.6",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-1217"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 4.5 -> 4.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "wordpress-seo",
     "status": "active",
     "active": true,
     "installed": "27.0",
     "available": "28.5",
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 27.2",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-3427"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 28.1",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-15425"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 27.0 -> 28.5 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "wordpress-seo-premium",
     "status": "active",
     "active": true,
     "installed": "24.3",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast SEO Premium [wordpress-seo-premium] < 27.6.1",
       "cvss": "6.6",
       "severity": "MEDIUM",
       "cve": "CVE-2026-10821"
      },
      {
       "name": "Yoast SEO Premium [wordpress-seo-premium] < 26.7",
       "cvss": "5.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-40722"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "prevent-browser-caching",
     "status": "active",
     "active": true,
     "installed": "2.3.5",
     "available": "3.2.1",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.3.5 -> 3.2.1 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "weglot",
     "status": "inactive",
     "active": false,
     "installed": "5.3",
     "available": "6.2",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 5.3 -> 6.2 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "eps-301-redirects",
     "status": "active",
     "active": true,
     "installed": "2.83",
     "available": "2.85",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.83 -> 2.85"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "advanced-custom-fields-pro",
     "status": "active",
     "active": true,
     "installed": "6.7.0.2",
     "available": "6.8.10",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "minor version bump 6.7.0.2 -> 6.8.10",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE WITH CAPTURE \u2014 routine bump but on a sitewide-impact plugin; watch the diff closely."
    },
    {
     "plugin": "cookie-law-info",
     "status": "active",
     "active": true,
     "installed": "3.4.0",
     "available": "3.5.6",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 3.4.0 -> 3.5.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "headers-security-advanced-hsts-wp",
     "status": "active",
     "active": true,
     "installed": "5.2.5",
     "available": "5.3.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 5.2.5 -> 5.3.5"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "page-links-to",
     "status": "active",
     "active": true,
     "installed": "3.3.7",
     "available": "3.4.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 3.3.7 -> 3.4.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "csv-xml-import-for-acf",
     "status": "active",
     "active": true,
     "installed": "1.0.7",
     "available": "1.0.8",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.0.7 -> 1.0.8"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wpai-acf-add-on",
     "status": "active",
     "active": true,
     "installed": "4.0.1",
     "available": "4.0.2",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 4.0.1 -> 4.0.2"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wp-all-import-pro",
     "status": "active",
     "active": true,
     "installed": "5.0.3",
     "available": "5.1.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 5.0.3 -> 5.1.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wp-search-with-algolia",
     "status": "active",
     "active": true,
     "installed": "2.11.1",
     "available": "2.14.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 2.11.1 -> 2.14.1 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "view-transitions",
     "status": "inactive",
     "active": false,
     "installed": "1.2.0",
     "available": "1.2.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.2.0 -> 1.2.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    }
   ],
   "p0": 1,
   "p1": 3,
   "total_updates": 24
  },
  "wpengine:indysoftdev25": {
   "platform": "wpengine",
   "install": "indysoftdev25",
   "environment": "development",
   "domain": "indysoftdev25.wpenginepowered.com",
   "siteurl": "https://indysoftdev25.wpenginepowered.com",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "genesis-block-theme",
   "updates": [
    {
     "plugin": "genesis-blocks",
     "status": "active",
     "active": true,
     "installed": "3.1.5",
     "available": "3.1.11",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 3.1.5 -> 3.1.11"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "akismet",
     "status": "inactive",
     "active": false,
     "installed": "5.3.5",
     "available": "5.7.2",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.3.5 -> 5.7.2 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    }
   ],
   "p0": 0,
   "p1": 0,
   "total_updates": 2
  },
  "wpengine:kleinprd": {
   "platform": "wpengine",
   "install": "kleinprd",
   "environment": "production",
   "domain": "www.kleinknecht.de",
   "siteurl": "https://www.kleinknecht.de",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "theme",
   "updates": [
    {
     "plugin": "gravityforms",
     "status": "active",
     "active": true,
     "installed": "2.10.5",
     "available": "3.1.1",
     "priority": "P1",
     "vulns": [
      {
       "name": "Gravity Forms [gravityforms] < 3.0.3",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2026-19513"
      },
      {
       "name": "Gravity Forms [gravityforms] < 3.0.0",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-16649"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.10.5 -> 3.1.1 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "acf-to-rest-api",
     "status": "active",
     "active": true,
     "installed": "3.3.4",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "ACF to REST API [acf-to-rest-api] <= 3.3.4 (unfixed + closed)",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-62979"
      },
      {
       "name": "ACF to REST API [acf-to-rest-api] <= 3.3.4 (unfixed + closed)",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-12030"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "advanced-custom-fields-pro",
     "status": "active",
     "active": true,
     "installed": "6.7.0.2",
     "available": "6.8.10",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "minor version bump 6.7.0.2 -> 6.8.10",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE WITH CAPTURE \u2014 routine bump but on a sitewide-impact plugin; watch the diff closely."
    },
    {
     "plugin": "amplifi-plugins",
     "status": "active",
     "active": true,
     "installed": "3.2.1",
     "available": "3.3.7",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 3.2.1 -> 3.3.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    }
   ],
   "p0": 0,
   "p1": 1,
   "total_updates": 3
  },
  "wpengine:ascentialdev1": {
   "platform": "wpengine",
   "install": "ascentialdev1",
   "environment": "development",
   "domain": "ascentialdev1.wpenginepowered.com",
   "siteurl": "https://ascentialdev1.wpenginepowered.com",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "hello-ascential",
   "updates": [
    {
     "plugin": "elementor-pro",
     "status": "active",
     "active": true,
     "installed": "3.27.1",
     "available": null,
     "priority": "P0",
     "vulns": [
      {
       "name": "Elementor Pro [elementor-pro] < 4.2.2",
       "cvss": "9.0",
       "severity": "CRITICAL",
       "cve": "CVE-2026-32475"
      },
      {
       "name": "Elementor Pro [elementor-pro] < 3.29.1",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-50555"
      },
      {
       "name": "Elementor Pro [elementor-pro] < 3.29.1",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-3076"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "woocommerce",
     "status": "inactive",
     "active": false,
     "installed": "9.6.0",
     "available": "11.1.0",
     "priority": "P0",
     "vulns": [
      {
       "name": "WooCommerce [woocommerce] == 7.1.0 (unfixed)",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2022-50972"
      },
      {
       "name": "WooCommerce [woocommerce] < 11.0",
       "cvss": "7.6",
       "severity": "HIGH",
       "cve": "CVE-2026-57777"
      },
      {
       "name": "WooCommerce [woocommerce] < 11.1.0",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-48888"
      },
      {
       "name": "WooCommerce [woocommerce] < 10.4.3",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-15033"
      }
     ],
     "vuln_count": 7,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 9.6.0 -> 11.1.0 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "hide-my-wp",
     "status": "inactive",
     "active": false,
     "installed": "5.4.01",
     "available": "7.0.11",
     "priority": "P0",
     "vulns": [
      {
       "name": "Hide My WP Ghost &#8211; Security &amp; Firewall [hide-my-wp] < 5.4.02",
       "cvss": "9.6",
       "severity": "CRITICAL",
       "cve": "CVE-2025-26909"
      },
      {
       "name": "Hide My WP Ghost &#8211; Security &amp; Firewall [hide-my-wp] < 5.4.02",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2025-2056"
      },
      {
       "name": "Hide My WP Ghost &#8211; Security &amp; Firewall [hide-my-wp] < 7.0.10",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-81806"
      },
      {
       "name": "Hide My WP Ghost &#8211; Security &amp; Firewall [hide-my-wp] <= 6.2.12 (unfixed)",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2025-69098"
      }
     ],
     "vuln_count": 7,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 5.4.01 -> 7.0.11 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "alttext-ai",
     "status": "active",
     "active": true,
     "installed": "1.9.92",
     "available": "1.10.38",
     "priority": "P1",
     "vulns": [
      {
       "name": "Alt Text AI &#8211; Automatically generate image alt text for SEO and accessibility [alttext-ai] < 1.9.94",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2025-46232"
      },
      {
       "name": "Alt Text AI &#8211; Automatically generate image alt text for SEO and accessibility [alttext-ai] < 1.10.18",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-25348"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.9.92 -> 1.10.38"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "jet-menu",
     "status": "active",
     "active": true,
     "installed": "2.4.8",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "JetMenu [jet-menu] < 2.4.9.1",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2025-26953"
      },
      {
       "name": "JetMenu [jet-menu] < 2.4.11.2",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-53987"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "mainwp-child",
     "status": "active",
     "active": true,
     "installed": "5.4.0.2",
     "available": "6.2",
     "priority": "P1",
     "vulns": [
      {
       "name": "MainWP Child &#8211; Securely Connects to the MainWP Dashboard to Manage Multiple Sites [mainwp-child] < 6.1.2",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-27366"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 5.4.0.2 -> 6.2 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "shortpixel-image-optimiser",
     "status": "active",
     "active": true,
     "installed": "6.1.1",
     "available": "6.5.6",
     "priority": "P1",
     "vulns": [
      {
       "name": "ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 6.4.4",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-39471"
      },
      {
       "name": "ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 6.3.5",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-11378"
      },
      {
       "name": "ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 6.4.4",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-4335"
      },
      {
       "name": "ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 6.4.3",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-1246"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 6.1.1 -> 6.5.6 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "revslider",
     "status": "active",
     "active": true,
     "installed": "6.7.18",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "Slider Revolution [revslider] < 7.0.11",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-6692"
      },
      {
       "name": "Slider Revolution [revslider] < 7.1.0",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-57678"
      },
      {
       "name": "Slider Revolution [revslider] < 6.7.37",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-9217"
      },
      {
       "name": "Slider Revolution [revslider] < 6.7.38",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-10249"
      }
     ],
     "vuln_count": 9,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "insert-headers-and-footers",
     "status": "active",
     "active": true,
     "installed": "2.2.5",
     "available": "2.3.9",
     "priority": "P1",
     "vulns": [
      {
       "name": "WPCode &#8211; Insert Headers and Footers + Custom Code Snippets &#8211; WordPress Code Manager [insert-headers-and-footers] < 2.3.6",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-8832"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.2.5 -> 2.3.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "debug-log-manager",
     "status": "inactive",
     "active": false,
     "installed": "2.3.3",
     "available": "2.5.2",
     "priority": "P1",
     "vulns": [
      {
       "name": "Debug Log Manager &#8211; Conveniently Monitor and Inspect Errors [debug-log-manager] < 2.3.5",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2025-3809"
      },
      {
       "name": "Debug Log Manager &#8211; Conveniently Monitor and Inspect Errors [debug-log-manager] < 2.5.1",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-9016"
      },
      {
       "name": "Debug Log Manager &#8211; Conveniently Monitor and Inspect Errors [debug-log-manager] < 2.3.5",
       "cvss": "0.0",
       "severity": null,
       "cve": "CVE-2025-32613"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.3.3 -> 2.5.2"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "link-whisper",
     "status": "inactive",
     "active": false,
     "installed": "0.7.9",
     "available": "0.9.7",
     "priority": "P1",
     "vulns": [
      {
       "name": "Link Whisper Free [link-whisper] < 0.9.1",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2025-11262"
      },
      {
       "name": "Link Whisper Free [link-whisper] < 0.8.9",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2025-67927"
      },
      {
       "name": "Link Whisper Free [link-whisper] < 0.9.3",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-22357"
      },
      {
       "name": "Link Whisper Free [link-whisper] < 0.9.5",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-57333"
      }
     ],
     "vuln_count": 8,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 0.7.9 -> 0.9.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wp-optimize",
     "status": "inactive",
     "active": false,
     "installed": "3.8.0",
     "available": "4.6.1",
     "priority": "P1",
     "vulns": [
      {
       "name": "WP-Optimize \u2013 Cache, Compress images, Minify &amp; Clean database to boost page speed &amp; performance [wp-optimize] < 4.5.3",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2026-7252"
      },
      {
       "name": "WP-Optimize \u2013 Cache, Compress images, Minify &amp; Clean database to boost page speed &amp; performance [wp-optimize] < 4.2.0",
       "cvss": "4.1",
       "severity": "MEDIUM",
       "cve": "CVE-2025-3951"
      },
      {
       "name": "WP-Optimize \u2013 Cache, Compress images, Minify &amp; Clean database to boost page speed &amp; performance [wp-optimize] < 4.5.1",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-2712"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.8.0 -> 4.6.1 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wpide",
     "status": "inactive",
     "active": false,
     "installed": "3.5.0",
     "available": "3.5.9",
     "priority": "P1",
     "vulns": [
      {
       "name": "WPIDE &#8211; File Manager &amp; Code Editor [wpide] < 3.5.7",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-57766"
      },
      {
       "name": "WPIDE &#8211; File Manager &amp; Code Editor [wpide] < 3.5.8",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-66440"
      },
      {
       "name": "WPIDE &#8211; File Manager &amp; Code Editor [wpide] < 3.5.2",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2024-13362"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 3.5.0 -> 3.5.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "elementor",
     "status": "active",
     "active": true,
     "installed": "3.27.2",
     "available": "4.2.4",
     "priority": "P2",
     "vulns": [
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.29.1",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-50555"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.35.6",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-32352"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 4.1.4",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-57619"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.27.5",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-13445"
      }
     ],
     "vuln_count": 15,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.27.2 -> 4.2.4 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "limit-login-attempts-reloaded",
     "status": "active",
     "active": true,
     "installed": "2.26.18",
     "available": "3.3.8",
     "priority": "P2",
     "vulns": [
      {
       "name": "Limit Login Attempts Security &#8211; Login Security, 2FA, Firewall, Brute Force Prevention [limit-login-attempts-reloaded] < 3.3.5",
       "cvss": "3.7",
       "severity": "LOW",
       "cve": "CVE-2026-18356"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.26.18 -> 3.3.8 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "search-filter-pro",
     "status": "active",
     "active": true,
     "installed": "2.5.19",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Search & Filter Pro [search-filter-pro] < 2.5.20",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-1528"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "simple-download-monitor",
     "status": "active",
     "active": true,
     "installed": "3.9.26",
     "available": "4.1.1",
     "priority": "P2",
     "vulns": [
      {
       "name": "Simple Download Monitor [simple-download-monitor] < 3.9.35",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-58197"
      },
      {
       "name": "Simple Download Monitor [simple-download-monitor] < 3.9.34",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-8977"
      },
      {
       "name": "Simple Download Monitor [simple-download-monitor] < 4.0.6",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-2383"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.9.26 -> 4.1.1 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "smtp2go",
     "status": "active",
     "active": true,
     "installed": "1.11.1",
     "available": "1.17.1",
     "priority": "P2",
     "vulns": [
      {
       "name": "SMTP2GO for WordPress &#8211; Email Made Easy [smtp2go] < 1.12.2",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-54011"
      },
      {
       "name": "SMTP2GO for WordPress &#8211; Email Made Easy [smtp2go] < 1.17.0",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-7621"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 1.11.1 -> 1.17.1 (skipped 6 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "svg-support",
     "status": "active",
     "active": true,
     "installed": "2.5.8",
     "available": "2.6.1",
     "priority": "P2",
     "vulns": [
      {
       "name": "SVG Support [svg-support] < 2.5.11",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-10222"
      },
      {
       "name": "SVG Support [svg-support] < 2.5.9",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2022-23638"
      },
      {
       "name": "SVG Support [svg-support] < 2.5.15",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-48973"
      },
      {
       "name": "SVG Support [svg-support] < 2.5.17",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-13340"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.5.8 -> 2.6.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "wordpress-seo",
     "status": "active",
     "active": true,
     "installed": "24.3",
     "available": "28.5",
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 26.6",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-14481"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 27.2",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-3427"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 26.9",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-1293"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 28.1",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-15425"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 24.3 -> 28.5 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "wordpress-seo-premium",
     "status": "active",
     "active": true,
     "installed": "24.3",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast SEO Premium [wordpress-seo-premium] < 27.6.1",
       "cvss": "6.6",
       "severity": "MEDIUM",
       "cve": "CVE-2026-10821"
      },
      {
       "name": "Yoast SEO Premium [wordpress-seo-premium] < 26.7",
       "cvss": "5.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-40722"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "wp-discussion-board",
     "status": "inactive",
     "active": false,
     "installed": "2.5.5",
     "available": "2.6.0",
     "priority": "P2",
     "vulns": [
      {
       "name": "Discussion Board &#8211; WordPress Forum Plugin [wp-discussion-board] < 2.5.6",
       "cvss": "6.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-8483"
      },
      {
       "name": "Discussion Board &#8211; WordPress Forum Plugin [wp-discussion-board] < 2.5.8",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-69023"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.5.5 -> 2.6.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "dracula-dark-mode",
     "status": "inactive",
     "active": false,
     "installed": "1.2.7",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Dracula Dark Mode \u2013  Accessibility, Reading Mode &amp; Dark Mode for WordPress [dracula-dark-mode] < 1.2.8 (closed)",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2024-13362"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "goal-tracker-ga",
     "status": "inactive",
     "active": false,
     "installed": "1.1.5",
     "available": "1.1.6",
     "priority": "P2",
     "vulns": [
      {
       "name": "Goal Tracker &#8211; Custom Event Tracking for GA4 [goal-tracker-ga] < 1.1.6",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2024-13362"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.1.5 -> 1.1.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "nitropack",
     "status": "inactive",
     "active": false,
     "installed": "1.17.6",
     "available": "1.20.0",
     "priority": "P2",
     "vulns": [
      {
       "name": "NitroPack \u2013 Performance, Page Speed &amp; Cache Plugin for Core Web Vitals, CDN &amp; Image Optimization [nitropack] < 1.19.4",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-39669"
      },
      {
       "name": "NitroPack \u2013 Performance, Page Speed &amp; Cache Plugin for Core Web Vitals, CDN &amp; Image Optimization [nitropack] < 1.18.5",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2025-8778"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 1.17.6 -> 1.20.0 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "query-monitor",
     "status": "inactive",
     "active": false,
     "installed": "3.17.0",
     "available": "4.0.7",
     "priority": "P2",
     "vulns": [
      {
       "name": "Query Monitor [query-monitor] < 3.20.4",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-4267"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.17.0 -> 4.0.7 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "sucuri-scanner",
     "status": "inactive",
     "active": false,
     "installed": "1.9.8",
     "available": "2.8",
     "priority": "P2",
     "vulns": [
      {
       "name": "Sucuri Security &#8211; Auditing, Malware Scanner and Security Hardening [sucuri-scanner] <= 2.7.3 (unfixed)",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-73033"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 1.9.8 -> 2.8 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "agile-store-locator",
     "status": "active",
     "active": true,
     "installed": "4.10.13",
     "available": "5.4.6",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 4.10.13 -> 5.4.6 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "font-awesome",
     "status": "active",
     "active": true,
     "installed": "4.5.0",
     "available": "5.2.1",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 4.5.0 -> 5.2.1 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "online-active-users",
     "status": "inactive",
     "active": false,
     "installed": "2.5",
     "available": "3.4.4",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.5 -> 3.4.4 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "prevent-browser-caching",
     "status": "inactive",
     "active": false,
     "installed": "2.3.5",
     "available": "3.2.1",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.3.5 -> 3.2.1 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "eps-301-redirects",
     "status": "active",
     "active": true,
     "installed": "2.77",
     "available": "2.85",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 2.77 -> 2.85 (skipped 8 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "advanced-custom-fields-pro",
     "status": "active",
     "active": true,
     "installed": "6.3.12",
     "available": "6.8.10",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "multi-minor jump 6.3.12 -> 6.8.10 (skipped 5 minor releases)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE WITH CAPTURE \u2014 routine bump but on a sitewide-impact plugin; watch the diff closely."
    },
    {
     "plugin": "cookie-law-info",
     "status": "active",
     "active": true,
     "installed": "3.2.8",
     "available": "3.5.6",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.2.8 -> 3.5.6 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "duplicate-page",
     "status": "active",
     "active": true,
     "installed": "4.5.4",
     "available": "4.5.9",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 4.5.4 -> 4.5.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "dynamic-content-for-elementor",
     "status": "active",
     "active": true,
     "installed": "3.2.3",
     "available": "3.4.13",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "minor version bump 3.2.3 -> 3.4.13",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE WITH CAPTURE \u2014 routine bump but on a sitewide-impact plugin; watch the diff closely."
    },
    {
     "plugin": "megamenu",
     "status": "active",
     "active": true,
     "installed": "3.4.1",
     "available": "3.10.8",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.4.1 -> 3.10.8 (skipped 6 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "page-links-to",
     "status": "active",
     "active": true,
     "installed": "3.3.7",
     "available": "3.4.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 3.3.7 -> 3.4.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "post-types-order",
     "status": "active",
     "active": true,
     "installed": "2.3.3",
     "available": "2.5.3",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.3.3 -> 2.5.3"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wp-revisions-control",
     "status": "active",
     "active": true,
     "installed": "1.4.3",
     "available": "1.4.4",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.4.3 -> 1.4.4"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wp-search-with-algolia",
     "status": "active",
     "active": true,
     "installed": "2.8.2",
     "available": "2.14.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 2.8.2 -> 2.14.1 (skipped 6 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wps-hide-login",
     "status": "active",
     "active": true,
     "installed": "1.9.17.1",
     "available": "1.9.19",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.9.17.1 -> 1.9.19"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "admin-taxonomy-filter",
     "status": "inactive",
     "active": false,
     "installed": "1.0.4",
     "available": "1.0.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.0.4 -> 1.0.5"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "cachebuster",
     "status": "inactive",
     "active": false,
     "installed": "1.8",
     "available": "1.10",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.8 -> 1.10"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "search-regex",
     "status": "inactive",
     "active": false,
     "installed": "3.1.2",
     "available": "3.4.4",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.1.2 -> 3.4.4 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wp-hide-security-enhancer",
     "status": "inactive",
     "active": false,
     "installed": "2.6",
     "available": "2.9.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 2.6 -> 2.9.1 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wp-mail-smtp",
     "status": "inactive",
     "active": false,
     "installed": "4.3.0",
     "available": "4.9.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 4.3.0 -> 4.9.0 (skipped 6 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    }
   ],
   "p0": 3,
   "p1": 10,
   "total_updates": 41
  },
  "wpengine:naptstaging": {
   "platform": "wpengine",
   "install": "naptstaging",
   "environment": "development",
   "domain": "naptstaging.wpenginepowered.com",
   "siteurl": "https://naptstaging.wpenginepowered.com",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "bootscore-child",
   "updates": [
    {
     "plugin": "ajax-search-lite",
     "status": "active",
     "active": true,
     "installed": "4.12.6",
     "available": "4.14.5",
     "priority": "P0",
     "vulns": [
      {
       "name": "Ajax Search Lite &#8211; Live Search &amp; Filter [ajax-search-lite] < 4.14.5",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2026-28139"
      },
      {
       "name": "Ajax Search Lite &#8211; Live Search &amp; Filter [ajax-search-lite] < 4.13.4",
       "cvss": "5.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-48086"
      },
      {
       "name": "Ajax Search Lite &#8211; Live Search &amp; Filter [ajax-search-lite] < 4.13.2",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2025-7956"
      },
      {
       "name": "Ajax Search Lite &#8211; Live Search &amp; Filter [ajax-search-lite] < 4.14.5",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-16258"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 4.12.6 -> 4.14.5"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "elementor-pro",
     "status": "active",
     "active": true,
     "installed": "3.26.3",
     "available": null,
     "priority": "P0",
     "vulns": [
      {
       "name": "Elementor Pro [elementor-pro] < 4.2.2",
       "cvss": "9.0",
       "severity": "CRITICAL",
       "cve": "CVE-2026-32475"
      },
      {
       "name": "Elementor Pro [elementor-pro] < 3.29.1",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-50555"
      },
      {
       "name": "Elementor Pro [elementor-pro] < 3.29.1",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-3076"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "wp-security-audit-log",
     "status": "active",
     "active": true,
     "installed": "5.3.3",
     "available": "5.6.6",
     "priority": "P0",
     "vulns": [
      {
       "name": "WP Activity Log [wp-security-audit-log] < 5.6.4",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2026-54806"
      },
      {
       "name": "WP Activity Log [wp-security-audit-log] < 5.6.4",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-56005"
      },
      {
       "name": "WP Activity Log [wp-security-audit-log] < 5.6.0",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-25331"
      },
      {
       "name": "WP Activity Log [wp-security-audit-log] < 5.6.3.1",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-45435"
      }
     ],
     "vuln_count": 5,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.3.3 -> 5.6.6 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "ewww-image-optimizer",
     "status": "active",
     "active": true,
     "installed": "8.1.2",
     "available": "8.7.7",
     "priority": "P1",
     "vulns": [
      {
       "name": "EWWW Image Optimizer [ewww-image-optimizer] < 8.7.7",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-84773"
      },
      {
       "name": "EWWW Image Optimizer [ewww-image-optimizer] < 8.7.4",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-15446"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 8.1.2 -> 8.7.7 (skipped 6 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "mainwp-child",
     "status": "active",
     "active": true,
     "installed": "5.3.5",
     "available": "6.2",
     "priority": "P1",
     "vulns": [
      {
       "name": "MainWP Child &#8211; Securely Connects to the MainWP Dashboard to Manage Multiple Sites [mainwp-child] < 6.1.2",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-27366"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 5.3.5 -> 6.2 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "revslider",
     "status": "active",
     "active": true,
     "installed": "6.7.25",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "Slider Revolution [revslider] < 7.0.11",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-6692"
      },
      {
       "name": "Slider Revolution [revslider] < 7.1.0",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-57678"
      },
      {
       "name": "Slider Revolution [revslider] < 6.7.37",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-9217"
      },
      {
       "name": "Slider Revolution [revslider] < 6.7.38",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-10249"
      }
     ],
     "vuln_count": 8,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "updraftplus",
     "status": "active",
     "active": true,
     "installed": "1.25.2",
     "available": "1.26.7",
     "priority": "P1",
     "vulns": [
      {
       "name": "UpdraftPlus: WP Backup &amp; Migration Plugin [updraftplus] < 1.26.5",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2026-10795"
      },
      {
       "name": "UpdraftPlus: WP Backup &amp; Migration Plugin [updraftplus] < 1.26.7",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-76549"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "minor version bump 1.25.2 -> 1.26.7",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "wp-all-import-pro",
     "status": "active",
     "active": true,
     "installed": "4.9.7",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "WP All Import Pro [wp-all-import-pro] < 4.9.8",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2024-9664"
      },
      {
       "name": "WP All Import Pro [wp-all-import-pro] < 4.9.8",
       "cvss": "5.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-8722"
      },
      {
       "name": "WP All Import Pro [wp-all-import-pro] < 4.9.8",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2024-9661"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "insert-headers-and-footers",
     "status": "active",
     "active": true,
     "installed": "2.2.6",
     "available": "2.3.9",
     "priority": "P1",
     "vulns": [
      {
       "name": "WPCode &#8211; Insert Headers and Footers + Custom Code Snippets &#8211; WordPress Code Manager [insert-headers-and-footers] < 2.3.6",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-8832"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.2.6 -> 2.3.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "contact-form-7",
     "status": "active",
     "active": true,
     "installed": "6.0.5",
     "available": "6.1.7",
     "priority": "P2",
     "vulns": [
      {
       "name": "Contact Form 7 [contact-form-7] < 6.0.6",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-3247"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 6.0.5 -> 6.1.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "elementor",
     "status": "active",
     "active": true,
     "installed": "3.27.7",
     "available": "4.2.4",
     "priority": "P2",
     "vulns": [
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.29.1",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-50555"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.35.6",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-32352"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 4.1.4",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-57619"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.30.3",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-4566"
      }
     ],
     "vuln_count": 14,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.27.7 -> 4.2.4 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "flamingo",
     "status": "active",
     "active": true,
     "installed": "2.5",
     "available": "2.6.4",
     "priority": "P2",
     "vulns": [
      {
       "name": "Flamingo [flamingo] < 2.6.3",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-12853"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.5 -> 2.6.4"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "simple-banner",
     "status": "active",
     "active": true,
     "installed": "3.0.4",
     "available": "3.3.2",
     "priority": "P2",
     "vulns": [
      {
       "name": "Simple Banner &#8211; Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website [simple-banner] < 3.0.5",
       "cvss": "4.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-13898"
      },
      {
       "name": "Simple Banner &#8211; Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website [simple-banner] < 3.1.0",
       "cvss": "4.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-12033"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.0.4 -> 3.3.2 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "wp-letsencrypt-ssl",
     "status": "active",
     "active": true,
     "installed": "7.7.5",
     "available": "7.8.7.5",
     "priority": "P2",
     "vulns": [
      {
       "name": "WP Encryption &#8211; One Click SSL / HTTPS &amp; Free SSL Certificate, HTTPS Redirect, Security [wp-letsencrypt-ssl] < 7.8.5.11",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-3829"
      },
      {
       "name": "WP Encryption &#8211; One Click SSL / HTTPS &amp; Free SSL Certificate, HTTPS Redirect, Security [wp-letsencrypt-ssl] < 7.8.6.7",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-15786"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 7.7.5 -> 7.8.7.5"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "wp-mail-logging",
     "status": "active",
     "active": true,
     "installed": "1.14.0",
     "available": "1.16.0",
     "priority": "P2",
     "vulns": [
      {
       "name": "WP Mail Logging [wp-mail-logging] < 1.16",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-2471"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.14.0 -> 1.16.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "wordpress-seo",
     "status": "active",
     "active": true,
     "installed": "24.6",
     "available": "28.5",
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 26.6",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-14481"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 27.2",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-3427"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 26.9",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-1293"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 28.1",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-15425"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 24.6 -> 28.5 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "wpai-acf-add-on",
     "status": "active",
     "active": true,
     "installed": "3.3.9",
     "available": "4.0.2",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.3.9 -> 4.0.2 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "advanced-custom-fields-pro",
     "status": "active",
     "active": true,
     "installed": "6.3.12",
     "available": "6.8.10",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "multi-minor jump 6.3.12 -> 6.8.10 (skipped 5 minor releases)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE WITH CAPTURE \u2014 routine bump but on a sitewide-impact plugin; watch the diff closely."
    },
    {
     "plugin": "duplicate-page",
     "status": "active",
     "active": true,
     "installed": "4.5.4",
     "available": "4.5.9",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 4.5.4 -> 4.5.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "font-awesome",
     "status": "active",
     "active": true,
     "installed": "5.0.1",
     "available": "5.2.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 5.0.1 -> 5.2.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "page-links-to",
     "status": "active",
     "active": true,
     "installed": "3.3.7",
     "available": "3.4.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 3.3.7 -> 3.4.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "redirection",
     "status": "active",
     "active": true,
     "installed": "5.5.1",
     "available": "5.10.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.5.1 -> 5.10.0 (skipped 5 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "redirect-redirection",
     "status": "active",
     "active": true,
     "installed": "1.2.5",
     "available": "1.3.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.2.5 -> 1.3.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "safe-svg",
     "status": "active",
     "active": true,
     "installed": "2.3.1",
     "available": "2.5.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.3.1 -> 2.5.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wp-mail-smtp",
     "status": "active",
     "active": true,
     "installed": "4.4.0",
     "available": "4.9.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 4.4.0 -> 4.9.0 (skipped 5 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wp-migrate-db-pro",
     "status": "active",
     "active": true,
     "installed": "2.7.2",
     "available": "2.7.11",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 2.7.2 -> 2.7.11"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "akismet",
     "status": "inactive",
     "active": false,
     "installed": "5.3.7",
     "available": "5.7.2",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.3.7 -> 5.7.2 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "genesis-blocks",
     "status": "inactive",
     "active": false,
     "installed": "3.1.5",
     "available": "3.1.11",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 3.1.5 -> 3.1.11"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    }
   ],
   "p0": 3,
   "p1": 6,
   "total_updates": 25
  },
  "wpengine:kleinstg": {
   "platform": "wpengine",
   "install": "kleinstg",
   "environment": "staging",
   "domain": "kleinstg.wpenginepowered.com",
   "siteurl": "https://kleinstg.wpenginepowered.com",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "genesis-block-theme",
   "updates": [
    {
     "plugin": "genesis-blocks",
     "status": "active",
     "active": true,
     "installed": "3.1.5",
     "available": "3.1.11",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 3.1.5 -> 3.1.11"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "akismet",
     "status": "inactive",
     "active": false,
     "installed": "5.3.3",
     "available": "5.7.2",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.3.3 -> 5.7.2 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    }
   ],
   "p0": 0,
   "p1": 0,
   "total_updates": 2
  },
  "wpengine:ascmlsdev": {
   "platform": "wpengine",
   "install": "ascmlsdev",
   "environment": "development",
   "domain": "ascmlsdev.wpenginepowered.com",
   "siteurl": "https://ascmlsdev.wpenginepowered.com",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "hello-ascential",
   "updates": [
    {
     "plugin": "elementor-pro",
     "status": "active",
     "active": true,
     "installed": "3.32.2",
     "available": null,
     "priority": "P0",
     "vulns": [
      {
       "name": "Elementor Pro [elementor-pro] < 4.2.2",
       "cvss": "9.0",
       "severity": "CRITICAL",
       "cve": "CVE-2026-32475"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "wp-security-audit-log",
     "status": "active",
     "active": true,
     "installed": "5.5.1",
     "available": "5.6.6",
     "priority": "P0",
     "vulns": [
      {
       "name": "WP Activity Log [wp-security-audit-log] < 5.6.4",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2026-54806"
      },
      {
       "name": "WP Activity Log [wp-security-audit-log] < 5.6.4",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-56005"
      },
      {
       "name": "WP Activity Log [wp-security-audit-log] < 5.6.0",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-25331"
      },
      {
       "name": "WP Activity Log [wp-security-audit-log] < 5.6.3.1",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-45435"
      }
     ],
     "vuln_count": 5,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 5.5.1 -> 5.6.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "woocommerce",
     "status": "inactive",
     "active": false,
     "installed": "10.2.2",
     "available": "11.1.0",
     "priority": "P0",
     "vulns": [
      {
       "name": "WooCommerce [woocommerce] == 7.1.0 (unfixed)",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2022-50972"
      },
      {
       "name": "WooCommerce [woocommerce] < 11.0",
       "cvss": "7.6",
       "severity": "HIGH",
       "cve": "CVE-2026-57777"
      },
      {
       "name": "WooCommerce [woocommerce] < 11.1.0",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-48888"
      },
      {
       "name": "WooCommerce [woocommerce] < 10.4.3",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-15033"
      }
     ],
     "vuln_count": 5,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 10.2.2 -> 11.1.0 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "jet-menu",
     "status": "active",
     "active": true,
     "installed": "2.4.8",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "JetMenu [jet-menu] < 2.4.9.1",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2025-26953"
      },
      {
       "name": "JetMenu [jet-menu] < 2.4.11.2",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-53987"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "mainwp-child",
     "status": "active",
     "active": true,
     "installed": "5.4.0.14",
     "available": "6.2",
     "priority": "P1",
     "vulns": [
      {
       "name": "MainWP Child &#8211; Securely Connects to the MainWP Dashboard to Manage Multiple Sites [mainwp-child] < 6.1.2",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-27366"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 5.4.0.14 -> 6.2 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "insert-headers-and-footers",
     "status": "active",
     "active": true,
     "installed": "2.3.0",
     "available": "2.3.9",
     "priority": "P1",
     "vulns": [
      {
       "name": "WPCode &#8211; Insert Headers and Footers + Custom Code Snippets &#8211; WordPress Code Manager [insert-headers-and-footers] < 2.3.6",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-8832"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 2.3.0 -> 2.3.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "admin-site-enhancements",
     "status": "active",
     "active": true,
     "installed": "8.0.0",
     "available": "9.1.2",
     "priority": "P2",
     "vulns": [
      {
       "name": "Admin and Site Enhancements (ASE) [admin-site-enhancements] < 8.4.1",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-32423"
      },
      {
       "name": "Admin and Site Enhancements (ASE) [admin-site-enhancements] < 8.1.0",
       "cvss": "2.7",
       "severity": "LOW",
       "cve": "CVE-2025-64255"
      },
      {
       "name": "Admin and Site Enhancements (ASE) [admin-site-enhancements] < 8.8.4",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-12083"
      },
      {
       "name": "Admin and Site Enhancements (ASE) [admin-site-enhancements] < 9.0.1",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-19615"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 8.0.0 -> 9.1.2 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "elementor",
     "status": "active",
     "active": true,
     "installed": "3.33.3",
     "available": "4.2.4",
     "priority": "P2",
     "vulns": [
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.35.6",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-32352"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 4.1.4",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-57619"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.33.4",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-11220"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.35.6",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-14732"
      }
     ],
     "vuln_count": 9,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.33.3 -> 4.2.4 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "simple-download-monitor",
     "status": "active",
     "active": true,
     "installed": "3.9.35",
     "available": "4.1.1",
     "priority": "P2",
     "vulns": [
      {
       "name": "Simple Download Monitor [simple-download-monitor] < 4.0.6",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-2383"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.9.35 -> 4.1.1 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "smtp2go",
     "status": "active",
     "active": true,
     "installed": "1.13.1",
     "available": "1.17.1",
     "priority": "P2",
     "vulns": [
      {
       "name": "SMTP2GO for WordPress &#8211; Email Made Easy [smtp2go] < 1.17.0",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-7621"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 1.13.1 -> 1.17.1 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "duplicate-post",
     "status": "active",
     "active": true,
     "installed": "4.5",
     "available": "4.7",
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast Duplicate Post [duplicate-post] <= 4.6 (unfixed)",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-53740"
      },
      {
       "name": "Yoast Duplicate Post [duplicate-post] <= 4.6 (unfixed)",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-53739"
      },
      {
       "name": "Yoast Duplicate Post [duplicate-post] < 4.6",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-1217"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 4.5 -> 4.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "wordpress-seo",
     "status": "active",
     "active": true,
     "installed": "26.0",
     "available": "28.5",
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 26.6",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-14481"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 27.2",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-3427"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 26.9",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-1293"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 28.1",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-15425"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 26.0 -> 28.5 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "wordpress-seo-premium",
     "status": "active",
     "active": true,
     "installed": "24.3",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast SEO Premium [wordpress-seo-premium] < 27.6.1",
       "cvss": "6.6",
       "severity": "MEDIUM",
       "cve": "CVE-2026-10821"
      },
      {
       "name": "Yoast SEO Premium [wordpress-seo-premium] < 26.7",
       "cvss": "5.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-40722"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "auto-alt-text",
     "status": "inactive",
     "active": false,
     "installed": "2.5.0",
     "available": "3.0.3",
     "priority": "P2",
     "vulns": [
      {
       "name": "Auto Alt Text [auto-alt-text] < 2.5.3",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-62866"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.5.0 -> 3.0.3 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "nitropack",
     "status": "inactive",
     "active": false,
     "installed": "1.18.5",
     "available": "1.20.0",
     "priority": "P2",
     "vulns": [
      {
       "name": "NitroPack \u2013 Performance, Page Speed &amp; Cache Plugin for Core Web Vitals, CDN &amp; Image Optimization [nitropack] < 1.19.4",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-39669"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.18.5 -> 1.20.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "search-filter-pro",
     "status": "inactive",
     "active": false,
     "installed": "2.5.19",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Search & Filter Pro [search-filter-pro] < 2.5.20",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-1528"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "agile-store-locator",
     "status": "active",
     "active": true,
     "installed": "4.10.13",
     "available": "5.4.6",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 4.10.13 -> 5.4.6 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "prevent-browser-caching",
     "status": "active",
     "active": true,
     "installed": "2.3.5",
     "available": "3.2.1",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.3.5 -> 3.2.1 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "eps-301-redirects",
     "status": "active",
     "active": true,
     "installed": "2.80",
     "available": "2.85",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 2.80 -> 2.85 (skipped 5 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "advanced-custom-fields-pro",
     "status": "active",
     "active": true,
     "installed": "6.5.1",
     "available": "6.8.10",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "multi-minor jump 6.5.1 -> 6.8.10 (skipped 3 minor releases)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE WITH CAPTURE \u2014 routine bump but on a sitewide-impact plugin; watch the diff closely."
    },
    {
     "plugin": "cookie-law-info",
     "status": "active",
     "active": true,
     "installed": "3.3.5",
     "available": "3.5.6",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 3.3.5 -> 3.5.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "font-awesome",
     "status": "active",
     "active": true,
     "installed": "5.1.0",
     "available": "5.2.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 5.1.0 -> 5.2.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "headers-security-advanced-hsts-wp",
     "status": "active",
     "active": true,
     "installed": "5.0.44",
     "available": "5.3.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.0.44 -> 5.3.5 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "page-links-to",
     "status": "active",
     "active": true,
     "installed": "3.3.7",
     "available": "3.4.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 3.3.7 -> 3.4.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wp-all-export-pro",
     "status": "active",
     "active": true,
     "installed": "1.9.11",
     "available": "1.9.15",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.9.11 -> 1.9.15"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wp-search-with-algolia",
     "status": "active",
     "active": true,
     "installed": "2.10.3",
     "available": "2.14.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 2.10.3 -> 2.14.1 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "cachebuster",
     "status": "inactive",
     "active": false,
     "installed": "1.8",
     "available": "1.10",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.8 -> 1.10"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "megamenu",
     "status": "inactive",
     "active": false,
     "installed": "3.6.2",
     "available": "3.10.8",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.6.2 -> 3.10.8 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "simple-banner",
     "status": "inactive",
     "active": false,
     "installed": "3.1.1",
     "available": "3.3.2",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 3.1.1 -> 3.3.2"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    }
   ],
   "p0": 3,
   "p1": 3,
   "total_updates": 25
  },
  "wpengine:kcacwd": {
   "platform": "wpengine",
   "install": "kcacwd",
   "environment": "development",
   "domain": "kcacwd.wpenginepowered.com",
   "siteurl": "https://kcacwd.wpenginepowered.com",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "hello-kitocrosby",
   "updates": [
    {
     "plugin": "gravityforms",
     "status": "active",
     "active": true,
     "installed": "2.9.11",
     "available": null,
     "priority": "P0",
     "vulns": [
      {
       "name": "Gravity Forms [gravityforms] < 2.9.21",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2025-12352"
      },
      {
       "name": "Gravity Forms [gravityforms] < 2.10.1",
       "cvss": "9.6",
       "severity": "CRITICAL",
       "cve": "CVE-2026-48866"
      },
      {
       "name": "Gravity Forms [gravityforms] < 2.9.22",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2025-12974"
      },
      {
       "name": "Gravity Forms [gravityforms] < 3.0.3",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2026-19513"
      }
     ],
     "vuln_count": 15,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "woocommerce",
     "status": "active",
     "active": true,
     "installed": "10.7.0",
     "available": "11.1.0",
     "priority": "P0",
     "vulns": [
      {
       "name": "WooCommerce [woocommerce] == 7.1.0 (unfixed)",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2022-50972"
      },
      {
       "name": "WooCommerce [woocommerce] < 11.0",
       "cvss": "7.6",
       "severity": "HIGH",
       "cve": "CVE-2026-57777"
      },
      {
       "name": "WooCommerce [woocommerce] < 11.1.0",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-48888"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 10.7.0 -> 11.1.0 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "wp-security-audit-log",
     "status": "active",
     "active": true,
     "installed": "5.6.3",
     "available": "5.6.6",
     "priority": "P0",
     "vulns": [
      {
       "name": "WP Activity Log [wp-security-audit-log] < 5.6.4",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2026-54806"
      },
      {
       "name": "WP Activity Log [wp-security-audit-log] < 5.6.4",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-56005"
      },
      {
       "name": "WP Activity Log [wp-security-audit-log] < 5.6.3.1",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-45435"
      },
      {
       "name": "WP Activity Log [wp-security-audit-log] < 5.6.5",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-65512"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 5.6.3 -> 5.6.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "ewww-image-optimizer",
     "status": "active",
     "active": true,
     "installed": "8.5.0",
     "available": "8.7.7",
     "priority": "P1",
     "vulns": [
      {
       "name": "EWWW Image Optimizer [ewww-image-optimizer] < 8.7.7",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-84773"
      },
      {
       "name": "EWWW Image Optimizer [ewww-image-optimizer] < 8.7.4",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-15446"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 8.5.0 -> 8.7.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "leadin",
     "status": "active",
     "active": true,
     "installed": "11.3.45",
     "available": "11.3.73",
     "priority": "P1",
     "vulns": [
      {
       "name": "HubSpot All-In-One Marketing &#8211; Forms, Popups, Live Chat [leadin] < 11.3.56",
       "cvss": "7.4",
       "severity": "HIGH",
       "cve": "CVE-2026-57736"
      },
      {
       "name": "HubSpot All-In-One Marketing &#8211; Forms, Popups, Live Chat [leadin] < 11.3.64",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-9656"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 11.3.45 -> 11.3.73"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "mainwp-child",
     "status": "active",
     "active": true,
     "installed": "6.0.10",
     "available": "6.2",
     "priority": "P1",
     "vulns": [
      {
       "name": "MainWP Child &#8211; Securely Connects to the MainWP Dashboard to Manage Multiple Sites [mainwp-child] < 6.1.2",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-27366"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 6.0.10 -> 6.2"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "revslider",
     "status": "active",
     "active": true,
     "installed": "6.7.54",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "Slider Revolution [revslider] < 7.0.11",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-6692"
      },
      {
       "name": "Slider Revolution [revslider] < 7.1.0",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-57678"
      },
      {
       "name": "Slider Revolution [revslider] < 7.0.11",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-7542"
      },
      {
       "name": "Slider Revolution [revslider] < 7.0.10",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-6728"
      }
     ],
     "vuln_count": 6,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "insert-headers-and-footers",
     "status": "active",
     "active": true,
     "installed": "2.3.5",
     "available": "2.3.9",
     "priority": "P1",
     "vulns": [
      {
       "name": "WPCode &#8211; Insert Headers and Footers + Custom Code Snippets &#8211; WordPress Code Manager [insert-headers-and-footers] < 2.3.6",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-8832"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 2.3.5 -> 2.3.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "image-optimization",
     "status": "inactive",
     "active": false,
     "installed": "1.7.4",
     "available": "1.7.6",
     "priority": "P1",
     "vulns": [
      {
       "name": "Image Optimization &#8211; Compress Images and Convert to WebP or AVIF [image-optimization] < 1.7.5",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2026-5821"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.7.4 -> 1.7.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "admin-site-enhancements",
     "status": "active",
     "active": true,
     "installed": "8.7.1",
     "available": "9.1.2",
     "priority": "P2",
     "vulns": [
      {
       "name": "Admin and Site Enhancements (ASE) [admin-site-enhancements] < 8.8.4",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-12083"
      },
      {
       "name": "Admin and Site Enhancements (ASE) [admin-site-enhancements] < 9.0.1",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-19615"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 8.7.1 -> 9.1.2 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "elementor",
     "status": "active",
     "active": true,
     "installed": "4.0.4",
     "available": "4.2.4",
     "priority": "P2",
     "vulns": [
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 4.1.4",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-57619"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 4.0.5",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-6127"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 4.1.1",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-49782"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 4.1.4",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-8825"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "minor version bump 4.0.4 -> 4.2.4",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "ajax-search-for-woocommerce",
     "status": "active",
     "active": true,
     "installed": "1.33.0",
     "available": "1.34.2",
     "priority": "P2",
     "vulns": [
      {
       "name": "FiboSearch &#8211; Ajax Search for WooCommerce [ajax-search-for-woocommerce] < 1.34.0",
       "cvss": "5.9",
       "severity": "MEDIUM",
       "cve": "CVE-2026-28179"
      },
      {
       "name": "FiboSearch &#8211; Ajax Search for WooCommerce [ajax-search-for-woocommerce] < 1.34.1",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-16612"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.33.0 -> 1.34.2"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "woo-product-filter",
     "status": "active",
     "active": true,
     "installed": "3.1.7",
     "available": "3.4.4",
     "priority": "P2",
     "vulns": [
      {
       "name": "Product Filter for WooCommerce by WBW [woo-product-filter] < 3.4.3",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2026-7804"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.1.7 -> 3.4.4 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "google-site-kit",
     "status": "active",
     "active": true,
     "installed": "1.184.0",
     "available": "1.187.0",
     "priority": "P2",
     "vulns": [
      {
       "name": "Site Kit by Google &#8211; Analytics, Search Console, AdSense, Speed [google-site-kit] < 1.187.0",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-62139"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 1.184.0 -> 1.187.0 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "smtp2go",
     "status": "active",
     "active": true,
     "installed": "1.14.1",
     "available": "1.17.1",
     "priority": "P2",
     "vulns": [
      {
       "name": "SMTP2GO for WordPress &#8211; Email Made Easy [smtp2go] < 1.17.0",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-7621"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 1.14.1 -> 1.17.1 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "svg-support",
     "status": "active",
     "active": true,
     "installed": "2.5.14",
     "available": "2.6.1",
     "priority": "P2",
     "vulns": [
      {
       "name": "SVG Support [svg-support] < 2.5.15",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-48973"
      },
      {
       "name": "SVG Support [svg-support] < 2.5.17",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-13340"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.5.14 -> 2.6.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "wordpress-seo",
     "status": "active",
     "active": true,
     "installed": "27.5",
     "available": "28.5",
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 28.1",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-15425"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 27.5 -> 28.5 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "advanced-custom-fields",
     "status": "inactive",
     "active": false,
     "installed": "6.8.0",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Advanced Custom Fields (ACF\u00ae) [advanced-custom-fields] < 6.8.2",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-8382"
      },
      {
       "name": "Advanced Custom Fields (ACF\u00ae) [advanced-custom-fields] < 6.8.2",
       "cvss": null,
       "severity": null,
       "cve": ""
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "enable-media-replace",
     "status": "inactive",
     "active": false,
     "installed": "4.1.9",
     "available": "4.2.2",
     "priority": "P2",
     "vulns": [
      {
       "name": "Enable Media Replace [enable-media-replace] < 4.2.2",
       "cvss": "5.9",
       "severity": "MEDIUM",
       "cve": "CVE-2026-57722"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 4.1.9 -> 4.2.2"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "prevent-browser-caching",
     "status": "active",
     "active": true,
     "installed": "2.3.5",
     "available": "3.2.1",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.3.5 -> 3.2.1 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "weglot",
     "status": "active",
     "active": true,
     "installed": "5.4",
     "available": "6.2",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 5.4 -> 6.2 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "auto-alt-text",
     "status": "inactive",
     "active": false,
     "installed": "2.8.0",
     "available": "3.0.3",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.8.0 -> 3.0.3 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "gutenberg",
     "status": "inactive",
     "active": false,
     "installed": "23.0.1",
     "available": "24.0.0",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 23.0.1 -> 24.0.0 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "advanced-custom-fields-pro",
     "status": "active",
     "active": true,
     "installed": "6.8.0.1",
     "available": "6.8.10",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "patch bump 6.8.0.1 -> 6.8.10",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE WITH CAPTURE \u2014 routine bump but on a sitewide-impact plugin; watch the diff closely."
    },
    {
     "plugin": "https-redirection",
     "status": "active",
     "active": true,
     "installed": "2.0.0",
     "available": "2.0.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 2.0.0 -> 2.0.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "font-awesome",
     "status": "active",
     "active": true,
     "installed": "5.1.4",
     "available": "5.2.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 5.1.4 -> 5.2.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "headers-security-advanced-hsts-wp",
     "status": "active",
     "active": true,
     "installed": "5.3.2",
     "available": "5.3.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 5.3.2 -> 5.3.5"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "megamenu",
     "status": "active",
     "active": true,
     "installed": "3.9.1",
     "available": "3.10.8",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 3.9.1 -> 3.10.8"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "media-sync",
     "status": "active",
     "active": true,
     "installed": "1.5.1",
     "available": "1.5.3",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.5.1 -> 1.5.3"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wp-crontrol",
     "status": "active",
     "active": true,
     "installed": "1.21.0",
     "available": "1.21.2",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.21.0 -> 1.21.2"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "gf-hubspot",
     "status": "active",
     "active": true,
     "installed": "1.2.7",
     "available": "1.2.9",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.2.7 -> 1.2.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "akismet",
     "status": "inactive",
     "active": false,
     "installed": "5.7",
     "available": "5.7.2",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 5.7 -> 5.7.2"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "cookie-law-info",
     "status": "inactive",
     "active": false,
     "installed": "3.4.2",
     "available": "3.5.6",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 3.4.2 -> 3.5.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "duplicate-page",
     "status": "inactive",
     "active": false,
     "installed": "4.5.8",
     "available": "4.5.9",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 4.5.8 -> 4.5.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "post-types-order",
     "status": "inactive",
     "active": false,
     "installed": "2.4.6",
     "available": "2.5.3",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.4.6 -> 2.5.3"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wordpress-importer",
     "status": "inactive",
     "active": false,
     "installed": "0.9.5",
     "available": "0.9.6",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 0.9.5 -> 0.9.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "csv-xml-import-for-acf",
     "status": "inactive",
     "active": false,
     "installed": "1.0.7",
     "available": "1.0.8",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.0.7 -> 1.0.8"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wp-search-with-algolia",
     "status": "inactive",
     "active": false,
     "installed": "2.11.3",
     "available": "2.14.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 2.11.3 -> 2.14.1 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    }
   ],
   "p0": 3,
   "p1": 6,
   "total_updates": 35
  },
  "wpengine:ubprd": {
   "platform": "wpengine",
   "install": "ubprd",
   "environment": "production",
   "domain": "ubprd.wpenginepowered.com",
   "siteurl": "https://ubprd.wpenginepowered.com",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "genesis-block-theme",
   "updates": [
    {
     "plugin": "genesis-blocks",
     "status": "active",
     "active": true,
     "installed": "3.1.5",
     "available": "3.1.11",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 3.1.5 -> 3.1.11"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "akismet",
     "status": "inactive",
     "active": false,
     "installed": "5.3.3",
     "available": "5.7.2",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.3.3 -> 5.7.2 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    }
   ],
   "p0": 0,
   "p1": 0,
   "total_updates": 2
  },
  "wpengine:asctmprd": {
   "platform": "wpengine",
   "install": "asctmprd",
   "environment": "production",
   "domain": "www.ascentialtech.com",
   "siteurl": "https://www.ascentialtech.com",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "hello-ascential",
   "updates": [
    {
     "plugin": "elementor-pro",
     "status": "active",
     "active": true,
     "installed": "3.30.1",
     "available": "4.2.3",
     "priority": "P0",
     "vulns": [
      {
       "name": "Elementor Pro [elementor-pro] < 4.2.2",
       "cvss": "9.0",
       "severity": "CRITICAL",
       "cve": "CVE-2026-32475"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.30.1 -> 4.2.3 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "mainwp-child",
     "status": "active",
     "active": true,
     "installed": "6.0.10",
     "available": "6.2",
     "priority": "P1",
     "vulns": [
      {
       "name": "MainWP Child &#8211; Securely Connects to the MainWP Dashboard to Manage Multiple Sites [mainwp-child] < 6.1.2",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-27366"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 6.0.10 -> 6.2"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "interactive-3d-flipbook-powered-physics-engine",
     "status": "active",
     "active": true,
     "installed": "1.16.19",
     "available": "1.16.22",
     "priority": "P2",
     "vulns": [
      {
       "name": "3D FlipBook \u2013 PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery [interactive-3d-flipbook-powered-physics-engine] <= 1.16.20 (unfixed)",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-74007"
      },
      {
       "name": "3D FlipBook \u2013 PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery [interactive-3d-flipbook-powered-physics-engine] < 1.16.21",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-15758"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.16.19 -> 1.16.22"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "admin-site-enhancements",
     "status": "active",
     "active": true,
     "installed": "8.8.1",
     "available": "9.1.2",
     "priority": "P2",
     "vulns": [
      {
       "name": "Admin and Site Enhancements (ASE) [admin-site-enhancements] < 8.8.4",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-12083"
      },
      {
       "name": "Admin and Site Enhancements (ASE) [admin-site-enhancements] < 9.0.1",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-19615"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 8.8.1 -> 9.1.2 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "elementor",
     "status": "active",
     "active": true,
     "installed": "3.35.5",
     "available": "4.2.4",
     "priority": "P2",
     "vulns": [
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.35.6",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-32352"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 4.1.4",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-57619"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.35.6",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-14732"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 4.0.5",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-6127"
      }
     ],
     "vuln_count": 8,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.35.5 -> 4.2.4 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "sucuri-scanner",
     "status": "active",
     "active": true,
     "installed": "2.7.2",
     "available": "2.8",
     "priority": "P2",
     "vulns": [
      {
       "name": "Sucuri Security &#8211; Auditing, Malware Scanner and Security Hardening [sucuri-scanner] <= 2.7.3 (unfixed)",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-73033"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.7.2 -> 2.8"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "wp-security-audit-log",
     "status": "active",
     "active": true,
     "installed": "5.6.4",
     "available": "5.6.6",
     "priority": "P2",
     "vulns": [
      {
       "name": "WP Activity Log [wp-security-audit-log] < 5.6.5",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-65512"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 5.6.4 -> 5.6.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "wordpress-seo",
     "status": "active",
     "active": true,
     "installed": "27.7",
     "available": "28.5",
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 28.1",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-15425"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 27.7 -> 28.5 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "wordpress-seo-premium",
     "status": "active",
     "active": true,
     "installed": "24.3",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast SEO Premium [wordpress-seo-premium] < 27.6.1",
       "cvss": "6.6",
       "severity": "MEDIUM",
       "cve": "CVE-2026-10821"
      },
      {
       "name": "Yoast SEO Premium [wordpress-seo-premium] < 26.7",
       "cvss": "5.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-40722"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "duplicate-post",
     "status": "inactive",
     "active": false,
     "installed": "4.6",
     "available": "4.7",
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast Duplicate Post [duplicate-post] <= 4.6 (unfixed)",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-53740"
      },
      {
       "name": "Yoast Duplicate Post [duplicate-post] <= 4.6 (unfixed)",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-53739"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 4.6 -> 4.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "prevent-browser-caching",
     "status": "inactive",
     "active": false,
     "installed": "2.3.6",
     "available": "3.2.1",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.3.6 -> 3.2.1 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "weglot",
     "status": "inactive",
     "active": false,
     "installed": "5.5",
     "available": "6.2",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 5.5 -> 6.2 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "eps-301-redirects",
     "status": "active",
     "active": true,
     "installed": "2.84",
     "available": "2.85",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.84 -> 2.85"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "advanced-custom-fields-pro",
     "status": "active",
     "active": true,
     "installed": "6.7.0.2",
     "available": "6.8.10",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "minor version bump 6.7.0.2 -> 6.8.10",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE WITH CAPTURE \u2014 routine bump but on a sitewide-impact plugin; watch the diff closely."
    },
    {
     "plugin": "contact-form-7",
     "status": "active",
     "active": true,
     "installed": "6.1.6",
     "available": "6.1.7",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 6.1.6 -> 6.1.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "headers-security-advanced-hsts-wp",
     "status": "active",
     "active": true,
     "installed": "5.3.2",
     "available": "5.3.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 5.3.2 -> 5.3.5"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "smtp2go",
     "status": "active",
     "active": true,
     "installed": "1.17.0",
     "available": "1.17.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.17.0 -> 1.17.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "insert-headers-and-footers",
     "status": "active",
     "active": true,
     "installed": "2.3.6",
     "available": "2.3.9",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 2.3.6 -> 2.3.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wp-search-with-algolia",
     "status": "active",
     "active": true,
     "installed": "2.11.3",
     "available": "2.14.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 2.11.3 -> 2.14.1 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "cookie-law-info",
     "status": "inactive",
     "active": false,
     "installed": "3.5.1",
     "available": "3.5.6",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 3.5.1 -> 3.5.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "query-monitor",
     "status": "inactive",
     "active": false,
     "installed": "4.0.6",
     "available": "4.0.7",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 4.0.6 -> 4.0.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "view-transitions",
     "status": "inactive",
     "active": false,
     "installed": "1.2.0",
     "available": "1.2.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.2.0 -> 1.2.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wp-optimize",
     "status": "inactive",
     "active": false,
     "installed": "4.5.4",
     "available": "4.6.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "minor version bump 4.5.4 -> 4.6.1",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "csv-xml-import-for-acf",
     "status": "inactive",
     "active": false,
     "installed": "1.0.7",
     "available": "1.0.8",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.0.7 -> 1.0.8"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    }
   ],
   "p0": 1,
   "p1": 1,
   "total_updates": 23
  },
  "wpengine:amplifistg": {
   "platform": "wpengine",
   "install": "amplifistg",
   "environment": "staging",
   "domain": "amplifistg.wpenginepowered.com",
   "siteurl": "https://acwebdev1.wpenginepowered.com",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "genesis-block-theme",
   "updates": [
    {
     "plugin": "genesis-blocks",
     "status": "active",
     "active": true,
     "installed": "3.1.7",
     "available": "3.1.11",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 3.1.7 -> 3.1.11"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "akismet",
     "status": "inactive",
     "active": false,
     "installed": "5.5",
     "available": "5.7.2",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 5.5 -> 5.7.2"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    }
   ],
   "p0": 0,
   "p1": 0,
   "total_updates": 2
  },
  "wpengine:firebranddedev": {
   "platform": "wpengine",
   "install": "firebranddedev",
   "environment": "development",
   "domain": "firebranddedev.wpenginepowered.com",
   "siteurl": "http://firebranddedev.wpenginepowered.com",
   "core": "7.0.3",
   "core_update": "7.0.4",
   "theme": "Firebrand",
   "updates": [
    {
     "plugin": "woocommerce",
     "status": "active",
     "active": true,
     "installed": "11.0.1",
     "available": "11.1.0",
     "priority": "P0",
     "vulns": [
      {
       "name": "WooCommerce [woocommerce] == 7.1.0 (unfixed)",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2022-50972"
      },
      {
       "name": "WooCommerce [woocommerce] < 11.1.0",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-48888"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "minor version bump 11.0.1 -> 11.1.0",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "duracelltomi-google-tag-manager",
     "status": "active",
     "active": true,
     "installed": "1.21.1",
     "available": "2.0.2",
     "priority": "P1",
     "vulns": [
      {
       "name": "GTM4WP &#8211; A Google Tag Manager (GTM) plugin for WordPress [duracelltomi-google-tag-manager] < 1.22.4",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-16597"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 1.21.1 -> 2.0.2 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "mainwp-child",
     "status": "active",
     "active": true,
     "installed": "5.4.0.11",
     "available": "6.2",
     "priority": "P1",
     "vulns": [
      {
       "name": "MainWP Child &#8211; Securely Connects to the MainWP Dashboard to Manage Multiple Sites [mainwp-child] < 6.1.2",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-27366"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 5.4.0.11 -> 6.2 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "password-protect-page",
     "status": "active",
     "active": true,
     "installed": "1.9.12",
     "available": "1.9.24",
     "priority": "P1",
     "vulns": [
      {
       "name": "PPWP &#8211; Password Protect Pages [password-protect-page] < 1.9.19",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-0551"
      },
      {
       "name": "PPWP &#8211; Password Protect Pages [password-protect-page] <= 1.9.21 (unfixed)",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-3639"
      },
      {
       "name": "PPWP &#8211; Password Protect Pages [password-protect-page] <= 1.9.21 (unfixed)",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-9878"
      },
      {
       "name": "PPWP &#8211; Password Protect Pages [password-protect-page] < 1.9.16",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-32562"
      }
     ],
     "vuln_count": 7,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.9.12 -> 1.9.24"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "insert-headers-and-footers",
     "status": "active",
     "active": true,
     "installed": "2.2.9",
     "available": "2.3.9",
     "priority": "P1",
     "vulns": [
      {
       "name": "WPCode &#8211; Insert Headers and Footers + Custom Code Snippets &#8211; WordPress Code Manager [insert-headers-and-footers] < 2.3.6",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-8832"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.2.9 -> 2.3.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "wpforms-lite",
     "status": "active",
     "active": true,
     "installed": "1.9.6.2",
     "available": "2.0.1.1",
     "priority": "P1",
     "vulns": [
      {
       "name": "WPForms &#8211; AI Form Builder for WordPress &#8211; Contact Forms, Payment Forms, Survey Form, Quiz &amp; More [wpforms-lite] < 1.10.0.3",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2026-40764"
      },
      {
       "name": "WPForms &#8211; AI Form Builder for WordPress &#8211; Contact Forms, Payment Forms, Survey Form, Quiz &amp; More [wpforms-lite] < 1.10.0.5",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-48835"
      },
      {
       "name": "WPForms &#8211; AI Form Builder for WordPress &#8211; Contact Forms, Payment Forms, Survey Form, Quiz &amp; More [wpforms-lite] < 1.9.9.2",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-25339"
      },
      {
       "name": "WPForms &#8211; AI Form Builder for WordPress &#8211; Contact Forms, Payment Forms, Survey Form, Quiz &amp; More [wpforms-lite] == 1.7.8",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2020-36919"
      }
     ],
     "vuln_count": 9,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 1.9.6.2 -> 2.0.1.1 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "updraftplus",
     "status": "inactive",
     "active": false,
     "installed": "1.25.6",
     "available": "1.26.7",
     "priority": "P1",
     "vulns": [
      {
       "name": "UpdraftPlus: WP Backup &amp; Migration Plugin [updraftplus] < 1.26.5",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2026-10795"
      },
      {
       "name": "UpdraftPlus: WP Backup &amp; Migration Plugin [updraftplus] < 1.26.7",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-76549"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "minor version bump 1.25.6 -> 1.26.7",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wp-rocket",
     "status": "inactive",
     "active": false,
     "installed": "3.19.2.1",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "WP Rocket [wp-rocket] < 3.21.1",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-5934"
      },
      {
       "name": "WP Rocket [wp-rocket] < 3.20.0.2",
       "cvss": "5.9",
       "severity": "MEDIUM",
       "cve": "CVE-2026-28044"
      },
      {
       "name": "WP Rocket [wp-rocket] < 3.23.3.3",
       "cvss": null,
       "severity": null,
       "cve": ""
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "admin-menu-editor",
     "status": "active",
     "active": true,
     "installed": "1.14",
     "available": "1.15.2",
     "priority": "P2",
     "vulns": [
      {
       "name": "Admin Menu Editor [admin-menu-editor] < 1.14.1",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-9493"
      },
      {
       "name": "Admin Menu Editor [admin-menu-editor] < 1.15",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-32456"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.14 -> 1.15.2"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "advanced-custom-fields",
     "status": "active",
     "active": true,
     "installed": "6.4.3",
     "available": "6.8.10",
     "priority": "P2",
     "vulns": [
      {
       "name": "Advanced Custom Fields (ACF\u00ae) [advanced-custom-fields] < 6.8.2",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-8382"
      },
      {
       "name": "Advanced Custom Fields (ACF\u00ae) [advanced-custom-fields] < 6.7.1",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-4812"
      },
      {
       "name": "Advanced Custom Fields (ACF\u00ae) [advanced-custom-fields] < 6.8.2",
       "cvss": null,
       "severity": null,
       "cve": ""
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "multi-minor jump 6.4.3 -> 6.8.10 (skipped 4 minor releases)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "custom-post-type-ui",
     "status": "active",
     "active": true,
     "installed": "1.17.3",
     "available": "1.19.3",
     "priority": "P2",
     "vulns": [
      {
       "name": "Custom Post Type UI [custom-post-type-ui] < 1.18.1",
       "cvss": "4.8",
       "severity": "MEDIUM",
       "cve": "CVE-2025-12826"
      },
      {
       "name": "Custom Post Type UI [custom-post-type-ui] < 1.18.2",
       "cvss": "4.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-14056"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.17.3 -> 1.19.3"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "pdf-embedder",
     "status": "active",
     "active": true,
     "installed": "4.9.2",
     "available": "5.0.2",
     "priority": "P2",
     "vulns": [
      {
       "name": "PDF Embedder \u2013 PDF Viewer &amp; Embed PDF Files for WordPress [pdf-embedder] < 5.0.0",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-7526"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 4.9.2 -> 5.0.2 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "printful-shipping-for-woocommerce",
     "status": "active",
     "active": true,
     "installed": "2.2.11",
     "available": "2.2.12",
     "priority": "P2",
     "vulns": [
      {
       "name": "Printful Integration for WooCommerce [printful-shipping-for-woocommerce] < 2.2.12",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-12375"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 2.2.11 -> 2.2.12"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "jetpack",
     "status": "inactive",
     "active": false,
     "installed": "14.8",
     "available": "16.2",
     "priority": "P2",
     "vulns": [
      {
       "name": "Jetpack &#8211; WP Security, Backup, Speed, &amp; Growth [jetpack] >= 3.2 - < 16.1.3",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2024-10858"
      },
      {
       "name": "Jetpack &#8211; WP Security, Backup, Speed, &amp; Growth [jetpack] == 11.4",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2023-54332"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 14.8 -> 16.2 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "post-type-switcher",
     "status": "inactive",
     "active": false,
     "installed": "4.0.0",
     "available": "4.0.1",
     "priority": "P2",
     "vulns": [
      {
       "name": "Post Type Switcher [post-type-switcher] < 4.0.1",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-12524"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 4.0.0 -> 4.0.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "really-simple-csv-importer",
     "status": "inactive",
     "active": false,
     "installed": "1.3",
     "available": "1.3.1",
     "priority": "P2",
     "vulns": [
      {
       "name": "Really Simple CSV Importer [really-simple-csv-importer] < 1.3.1",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-65461"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.3 -> 1.3.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "svg-support",
     "status": "inactive",
     "active": false,
     "installed": "2.5.14",
     "available": "2.6.1",
     "priority": "P2",
     "vulns": [
      {
       "name": "SVG Support [svg-support] < 2.5.15",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-48973"
      },
      {
       "name": "SVG Support [svg-support] < 2.5.17",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-13340"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.5.14 -> 2.6.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wp-file-manager",
     "status": "inactive",
     "active": false,
     "installed": "8.0.2",
     "available": "8.0.4",
     "priority": "P2",
     "vulns": [
      {
       "name": "File Manager [wp-file-manager] < 8.0.4",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-6382"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 8.0.2 -> 8.0.4"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "pdfjs-viewer-shortcode",
     "status": "active",
     "active": true,
     "installed": "2.2.2",
     "available": "3.1.1",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.2.2 -> 3.1.1 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "userway-accessibility-widget",
     "status": "active",
     "active": true,
     "installed": "2.6.5",
     "available": "2.6.6",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 2.6.5 -> 2.6.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "akismet",
     "status": "active",
     "active": true,
     "installed": "5.7",
     "available": "5.7.2",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 5.7 -> 5.7.2"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "classic-editor",
     "status": "active",
     "active": true,
     "installed": "1.6.7",
     "available": "1.7.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.6.7 -> 1.7.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "duplicate-page",
     "status": "active",
     "active": true,
     "installed": "4.5.5",
     "available": "4.5.9",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 4.5.5 -> 4.5.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "headers-security-advanced-hsts-wp",
     "status": "active",
     "active": true,
     "installed": "5.0.44",
     "available": "5.3.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.0.44 -> 5.3.5 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "leadin",
     "status": "active",
     "active": true,
     "installed": "11.3.69",
     "available": "11.3.73",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 11.3.69 -> 11.3.73"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "molongui-authorship",
     "status": "active",
     "active": true,
     "installed": "5.2.9",
     "available": "5.2.12",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 5.2.9 -> 5.2.12"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "nginx-helper",
     "status": "active",
     "active": true,
     "installed": "2.3.3",
     "available": "2.4.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.3.3 -> 2.4.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "podcast-subscribe-buttons",
     "status": "active",
     "active": true,
     "installed": "1.5.2",
     "available": "1.5.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.5.2 -> 1.5.5"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "redirection",
     "status": "active",
     "active": true,
     "installed": "5.5.2",
     "available": "5.10.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.5.2 -> 5.10.0 (skipped 5 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "side-cart-woocommerce",
     "status": "active",
     "active": true,
     "installed": "2.6.8",
     "available": "2.8.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.6.8 -> 2.8.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "simple-author-box",
     "status": "active",
     "active": true,
     "installed": "2.58",
     "available": "2.61",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 2.58 -> 2.61 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "woocommerce-services",
     "status": "active",
     "active": true,
     "installed": "3.6.12",
     "available": "3.6.16",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 3.6.12 -> 3.6.16"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "woocommerce-payments",
     "status": "active",
     "active": true,
     "installed": "11.0.0",
     "available": "11.1.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 11.0.0 -> 11.1.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wp-mail-smtp",
     "status": "active",
     "active": true,
     "installed": "4.5.0",
     "available": "4.9.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 4.5.0 -> 4.9.0 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "yaymail",
     "status": "active",
     "active": true,
     "installed": "4.4.2",
     "available": "4.4.4",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 4.4.2 -> 4.4.4"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wordpress-seo",
     "status": "active",
     "active": true,
     "installed": "28.2",
     "available": "28.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "multi-minor jump 28.2 -> 28.5 (skipped 3 minor releases)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE WITH CAPTURE \u2014 routine bump but on a sitewide-impact plugin; watch the diff closely."
    },
    {
     "plugin": "imagify",
     "status": "inactive",
     "active": false,
     "installed": "2.2.6",
     "available": "2.3.4",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.2.6 -> 2.3.4"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "all-in-one-schemaorg-rich-snippets",
     "status": "inactive",
     "active": false,
     "installed": "1.7.4",
     "available": "1.7.9",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.7.4 -> 1.7.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    }
   ],
   "p0": 1,
   "p1": 7,
   "total_updates": 37
  },
  "wpengine:ascentialmls1": {
   "platform": "wpengine",
   "install": "ascentialmls1",
   "environment": "production",
   "domain": "ascentialmls1.wpenginepowered.com",
   "siteurl": "https://ascentialmls1.wpenginepowered.com",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "hello-ascential",
   "updates": [
    {
     "plugin": "ameliabooking",
     "status": "active",
     "active": true,
     "installed": "1.2.33",
     "available": "2.4.10",
     "priority": "P0",
     "vulns": [
      {
       "name": "Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 9.6.3",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2026-9055"
      },
      {
       "name": "Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 2.4.3",
       "cvss": "9.3",
       "severity": "CRITICAL",
       "cve": "CVE-2026-57702"
      },
      {
       "name": "Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 2.4",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-48889"
      },
      {
       "name": "Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 2.1.2",
       "cvss": "7.6",
       "severity": "HIGH",
       "cve": "CVE-2026-39487"
      }
     ],
     "vuln_count": 28,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 1.2.33 -> 2.4.10 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "elementor-pro",
     "status": "active",
     "active": true,
     "installed": "3.33.2",
     "available": "3.35.1",
     "priority": "P0",
     "vulns": [
      {
       "name": "Elementor Pro [elementor-pro] < 4.2.2",
       "cvss": "9.0",
       "severity": "CRITICAL",
       "cve": "CVE-2026-32475"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "minor version bump 3.33.2 -> 3.35.1",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "wp-security-audit-log",
     "status": "active",
     "active": true,
     "installed": "5.5.1",
     "available": "5.6.6",
     "priority": "P0",
     "vulns": [
      {
       "name": "WP Activity Log [wp-security-audit-log] < 5.6.4",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2026-54806"
      },
      {
       "name": "WP Activity Log [wp-security-audit-log] < 5.6.4",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-56005"
      },
      {
       "name": "WP Activity Log [wp-security-audit-log] < 5.6.0",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-25331"
      },
      {
       "name": "WP Activity Log [wp-security-audit-log] < 5.6.3.1",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-45435"
      }
     ],
     "vuln_count": 5,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 5.5.1 -> 5.6.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "woocommerce",
     "status": "inactive",
     "active": false,
     "installed": "10.2.0",
     "available": "11.1.0",
     "priority": "P0",
     "vulns": [
      {
       "name": "WooCommerce [woocommerce] == 7.1.0 (unfixed)",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2022-50972"
      },
      {
       "name": "WooCommerce [woocommerce] < 11.0",
       "cvss": "7.6",
       "severity": "HIGH",
       "cve": "CVE-2026-57777"
      },
      {
       "name": "WooCommerce [woocommerce] < 11.1.0",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-48888"
      },
      {
       "name": "WooCommerce [woocommerce] < 10.4.3",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-15033"
      }
     ],
     "vuln_count": 5,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 10.2.0 -> 11.1.0 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "image-optimization",
     "status": "active",
     "active": true,
     "installed": "1.6.9",
     "available": "1.7.6",
     "priority": "P1",
     "vulns": [
      {
       "name": "Image Optimization &#8211; Compress Images and Convert to WebP or AVIF [image-optimization] < 1.7.5",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2026-5821"
      },
      {
       "name": "Image Optimization &#8211; Compress Images and Convert to WebP or AVIF [image-optimization] < 1.7.2",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-25387"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.6.9 -> 1.7.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "jet-menu",
     "status": "active",
     "active": true,
     "installed": "2.4.8",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "JetMenu [jet-menu] < 2.4.9.1",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2025-26953"
      },
      {
       "name": "JetMenu [jet-menu] < 2.4.11.2",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-53987"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "mainwp-child",
     "status": "active",
     "active": true,
     "installed": "5.4.0.14",
     "available": "6.2",
     "priority": "P1",
     "vulns": [
      {
       "name": "MainWP Child &#8211; Securely Connects to the MainWP Dashboard to Manage Multiple Sites [mainwp-child] < 6.1.2",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-27366"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 5.4.0.14 -> 6.2 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "shortpixel-image-optimiser",
     "status": "active",
     "active": true,
     "installed": "6.1.1",
     "available": "6.5.6",
     "priority": "P1",
     "vulns": [
      {
       "name": "ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 6.4.4",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-39471"
      },
      {
       "name": "ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 6.3.5",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-11378"
      },
      {
       "name": "ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 6.4.4",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-4335"
      },
      {
       "name": "ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 6.4.3",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-1246"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 6.1.1 -> 6.5.6 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "insert-headers-and-footers",
     "status": "active",
     "active": true,
     "installed": "2.3.0",
     "available": "2.3.9",
     "priority": "P1",
     "vulns": [
      {
       "name": "WPCode &#8211; Insert Headers and Footers + Custom Code Snippets &#8211; WordPress Code Manager [insert-headers-and-footers] < 2.3.6",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-8832"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 2.3.0 -> 2.3.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "admin-site-enhancements",
     "status": "active",
     "active": true,
     "installed": "7.9.10",
     "available": "9.1.2",
     "priority": "P2",
     "vulns": [
      {
       "name": "Admin and Site Enhancements (ASE) [admin-site-enhancements] < 8.4.1",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-32423"
      },
      {
       "name": "Admin and Site Enhancements (ASE) [admin-site-enhancements] < 8.1.0",
       "cvss": "2.7",
       "severity": "LOW",
       "cve": "CVE-2025-64255"
      },
      {
       "name": "Admin and Site Enhancements (ASE) [admin-site-enhancements] < 8.8.4",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-12083"
      },
      {
       "name": "Admin and Site Enhancements (ASE) [admin-site-enhancements] < 9.0.1",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-19615"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 7.9.10 -> 9.1.2 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "auto-alt-text",
     "status": "active",
     "active": true,
     "installed": "2.4.2",
     "available": "3.0.3",
     "priority": "P2",
     "vulns": [
      {
       "name": "Auto Alt Text [auto-alt-text] < 2.5.3",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-62866"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.4.2 -> 3.0.3 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "elementor",
     "status": "active",
     "active": true,
     "installed": "3.33.3",
     "available": "4.2.4",
     "priority": "P2",
     "vulns": [
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.35.6",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-32352"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 4.1.4",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-57619"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.33.4",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-11220"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.35.6",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-14732"
      }
     ],
     "vuln_count": 9,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.33.3 -> 4.2.4 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "simple-download-monitor",
     "status": "active",
     "active": true,
     "installed": "3.9.35",
     "available": "4.1.1",
     "priority": "P2",
     "vulns": [
      {
       "name": "Simple Download Monitor [simple-download-monitor] < 4.0.6",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-2383"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.9.35 -> 4.1.1 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "smtp2go",
     "status": "active",
     "active": true,
     "installed": "1.13.1",
     "available": "1.17.1",
     "priority": "P2",
     "vulns": [
      {
       "name": "SMTP2GO for WordPress &#8211; Email Made Easy [smtp2go] < 1.17.0",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-7621"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 1.13.1 -> 1.17.1 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "duplicate-post",
     "status": "active",
     "active": true,
     "installed": "4.5",
     "available": "4.7",
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast Duplicate Post [duplicate-post] <= 4.6 (unfixed)",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-53740"
      },
      {
       "name": "Yoast Duplicate Post [duplicate-post] <= 4.6 (unfixed)",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-53739"
      },
      {
       "name": "Yoast Duplicate Post [duplicate-post] < 4.6",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-1217"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 4.5 -> 4.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "wordpress-seo",
     "status": "active",
     "active": true,
     "installed": "24.3",
     "available": "28.5",
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 26.6",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-14481"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 27.2",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-3427"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 26.9",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-1293"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 28.1",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-15425"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 24.3 -> 28.5 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "wordpress-seo-premium",
     "status": "active",
     "active": true,
     "installed": "24.3",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast SEO Premium [wordpress-seo-premium] < 27.6.1",
       "cvss": "6.6",
       "severity": "MEDIUM",
       "cve": "CVE-2026-10821"
      },
      {
       "name": "Yoast SEO Premium [wordpress-seo-premium] < 26.7",
       "cvss": "5.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-40722"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "nitropack",
     "status": "inactive",
     "active": false,
     "installed": "1.18.5",
     "available": "1.20.0",
     "priority": "P2",
     "vulns": [
      {
       "name": "NitroPack \u2013 Performance, Page Speed &amp; Cache Plugin for Core Web Vitals, CDN &amp; Image Optimization [nitropack] < 1.19.4",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-39669"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.18.5 -> 1.20.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "search-filter-pro",
     "status": "inactive",
     "active": false,
     "installed": "2.5.19",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Search & Filter Pro [search-filter-pro] < 2.5.20",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-1528"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "agile-store-locator",
     "status": "active",
     "active": true,
     "installed": "4.10.13",
     "available": "5.4.6",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 4.10.13 -> 5.4.6 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "prevent-browser-caching",
     "status": "active",
     "active": true,
     "installed": "2.3.5",
     "available": "3.2.1",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.3.5 -> 3.2.1 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "eps-301-redirects",
     "status": "active",
     "active": true,
     "installed": "2.80",
     "available": "2.85",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 2.80 -> 2.85 (skipped 5 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "advanced-custom-fields-pro",
     "status": "active",
     "active": true,
     "installed": "6.3.12",
     "available": "6.8.10",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "multi-minor jump 6.3.12 -> 6.8.10 (skipped 5 minor releases)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE WITH CAPTURE \u2014 routine bump but on a sitewide-impact plugin; watch the diff closely."
    },
    {
     "plugin": "cookie-law-info",
     "status": "active",
     "active": true,
     "installed": "3.3.5",
     "available": "3.5.6",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 3.3.5 -> 3.5.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "dynamic-content-for-elementor",
     "status": "active",
     "active": true,
     "installed": "3.3.3",
     "available": "3.4.13",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "minor version bump 3.3.3 -> 3.4.13",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE WITH CAPTURE \u2014 routine bump but on a sitewide-impact plugin; watch the diff closely."
    },
    {
     "plugin": "font-awesome",
     "status": "active",
     "active": true,
     "installed": "5.1.0",
     "available": "5.2.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 5.1.0 -> 5.2.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "headers-security-advanced-hsts-wp",
     "status": "active",
     "active": true,
     "installed": "5.0.44",
     "available": "5.3.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.0.44 -> 5.3.5 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "page-links-to",
     "status": "active",
     "active": true,
     "installed": "3.3.7",
     "available": "3.4.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 3.3.7 -> 3.4.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wp-all-export-pro",
     "status": "active",
     "active": true,
     "installed": "1.9.11",
     "available": "1.9.15",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.9.11 -> 1.9.15"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wpe-site-migration",
     "status": "active",
     "active": true,
     "installed": "1.7.1",
     "available": "1.8.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.7.1 -> 1.8.5"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wp-search-with-algolia",
     "status": "active",
     "active": true,
     "installed": "2.10.3",
     "available": "2.14.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 2.10.3 -> 2.14.1 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "cachebuster",
     "status": "inactive",
     "active": false,
     "installed": "1.8",
     "available": "1.10",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.8 -> 1.10"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "megamenu",
     "status": "inactive",
     "active": false,
     "installed": "3.6.2",
     "available": "3.10.8",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.6.2 -> 3.10.8 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "simple-banner",
     "status": "inactive",
     "active": false,
     "installed": "3.1.0",
     "available": "3.3.2",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 3.1.0 -> 3.3.2"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    }
   ],
   "p0": 4,
   "p1": 5,
   "total_updates": 31
  },
  "wpengine:ascmlsaspect": {
   "platform": "wpengine",
   "install": "ascmlsaspect",
   "environment": "production",
   "domain": "ascmlsaspect.wpenginepowered.com",
   "siteurl": "https://ascmlsaspect.wpenginepowered.com",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "theme",
   "updates": [
    {
     "plugin": "translatepress-multilingual",
     "status": "active",
     "active": true,
     "installed": "3.0.8",
     "available": "3.3.6",
     "priority": "P0",
     "vulns": [
      {
       "name": "TranslatePress &#8211; Translate Multilingual sites with AI Translation [translatepress-multilingual] < 3.3.3",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2026-78267"
      },
      {
       "name": "TranslatePress &#8211; Translate Multilingual sites with AI Translation [translatepress-multilingual] < 3.3.2",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2026-19632"
      },
      {
       "name": "TranslatePress &#8211; Translate Multilingual sites with AI Translation [translatepress-multilingual] < 3.3",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-18510"
      },
      {
       "name": "TranslatePress &#8211; Translate Multilingual sites with AI Translation [translatepress-multilingual] < 3.2.6",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-75981"
      }
     ],
     "vuln_count": 8,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.0.8 -> 3.3.6 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "gravityforms",
     "status": "active",
     "active": true,
     "installed": "2.10.5",
     "available": "3.1.1",
     "priority": "P1",
     "vulns": [
      {
       "name": "Gravity Forms [gravityforms] < 3.0.3",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2026-19513"
      },
      {
       "name": "Gravity Forms [gravityforms] < 3.0.0",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-16649"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.10.5 -> 3.1.1 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "mainwp-child",
     "status": "active",
     "active": true,
     "installed": "5.4.1",
     "available": "6.2",
     "priority": "P1",
     "vulns": [
      {
       "name": "MainWP Child &#8211; Securely Connects to the MainWP Dashboard to Manage Multiple Sites [mainwp-child] < 6.1.2",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-27366"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 5.4.1 -> 6.2 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "popup-maker",
     "status": "active",
     "active": true,
     "installed": "1.21.5",
     "available": "1.25.0",
     "priority": "P1",
     "vulns": [
      {
       "name": "Popup Maker &#8211; Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.23.0",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-8848"
      },
      {
       "name": "Popup Maker &#8211; Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.24.0",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-28177"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 1.21.5 -> 1.25.0 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "wp-smushit",
     "status": "active",
     "active": true,
     "installed": "3.23.4",
     "available": "4.3.3",
     "priority": "P1",
     "vulns": [
      {
       "name": "Smush \u2013 Image Optimization, Compression, Lazy Load, WebP &amp; CDN [wp-smushit] < 4.3.0",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-81285"
      },
      {
       "name": "Smush \u2013 Image Optimization, Compression, Lazy Load, WebP &amp; CDN [wp-smushit] < 4.3.2",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-19223"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.23.4 -> 4.3.3 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "insert-headers-and-footers",
     "status": "active",
     "active": true,
     "installed": "2.3.3",
     "available": "2.3.9",
     "priority": "P1",
     "vulns": [
      {
       "name": "WPCode &#8211; Insert Headers and Footers + Custom Code Snippets &#8211; WordPress Code Manager [insert-headers-and-footers] < 2.3.6",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-8832"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 2.3.3 -> 2.3.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "acf-to-rest-api",
     "status": "active",
     "active": true,
     "installed": "3.3.4",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "ACF to REST API [acf-to-rest-api] <= 3.3.4 (unfixed + closed)",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-62979"
      },
      {
       "name": "ACF to REST API [acf-to-rest-api] <= 3.3.4 (unfixed + closed)",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-12030"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "limit-login-attempts-reloaded",
     "status": "active",
     "active": true,
     "installed": "2.26.28",
     "available": "3.3.8",
     "priority": "P2",
     "vulns": [
      {
       "name": "Limit Login Attempts Security &#8211; Login Security, 2FA, Firewall, Brute Force Prevention [limit-login-attempts-reloaded] < 3.3.5",
       "cvss": "3.7",
       "severity": "LOW",
       "cve": "CVE-2026-18356"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.26.28 -> 3.3.8 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "smtp2go",
     "status": "active",
     "active": true,
     "installed": "1.14.0",
     "available": "1.17.1",
     "priority": "P2",
     "vulns": [
      {
       "name": "SMTP2GO for WordPress &#8211; Email Made Easy [smtp2go] < 1.17.0",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-7621"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 1.14.0 -> 1.17.1 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "svg-support",
     "status": "active",
     "active": true,
     "installed": "2.5.14",
     "available": "2.6.1",
     "priority": "P2",
     "vulns": [
      {
       "name": "SVG Support [svg-support] < 2.5.15",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-48973"
      },
      {
       "name": "SVG Support [svg-support] < 2.5.17",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-13340"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.5.14 -> 2.6.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "duplicate-post",
     "status": "active",
     "active": true,
     "installed": "4.5",
     "available": "4.7",
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast Duplicate Post [duplicate-post] <= 4.6 (unfixed)",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-53740"
      },
      {
       "name": "Yoast Duplicate Post [duplicate-post] <= 4.6 (unfixed)",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-53739"
      },
      {
       "name": "Yoast Duplicate Post [duplicate-post] < 4.6",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-1217"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 4.5 -> 4.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "change-admin-email-setting-without-outbound-email",
     "status": "active",
     "active": true,
     "installed": "4.1",
     "available": "5.0",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 4.1 -> 5.0 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "better-wp-security",
     "status": "active",
     "active": true,
     "installed": "9.4.4",
     "available": "10.0.3",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 9.4.4 -> 10.0.3 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "advanced-custom-fields-pro",
     "status": "active",
     "active": true,
     "installed": "6.7.0.2",
     "available": "6.8.10",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "minor version bump 6.7.0.2 -> 6.8.10",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE WITH CAPTURE \u2014 routine bump but on a sitewide-impact plugin; watch the diff closely."
    },
    {
     "plugin": "akismet",
     "status": "active",
     "active": true,
     "installed": "5.6",
     "available": "5.7.2",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 5.6 -> 5.7.2"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "code-snippets",
     "status": "active",
     "active": true,
     "installed": "3.9.5",
     "available": "3.10.2",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 3.9.5 -> 3.10.2"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "duplicate-page",
     "status": "active",
     "active": true,
     "installed": "4.5.6",
     "available": "4.5.9",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 4.5.6 -> 4.5.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "force-regenerate-thumbnails",
     "status": "active",
     "active": true,
     "installed": "2.2.2",
     "available": "2.3.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.2.2 -> 2.3.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "headers-security-advanced-hsts-wp",
     "status": "active",
     "active": true,
     "installed": "5.2.5",
     "available": "5.3.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 5.2.5 -> 5.3.5"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "redirection",
     "status": "active",
     "active": true,
     "installed": "5.6.1",
     "available": "5.10.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.6.1 -> 5.10.0 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "simple-page-ordering",
     "status": "active",
     "active": true,
     "installed": "2.7.4",
     "available": "2.8.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.7.4 -> 2.8.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "stop-user-enumeration",
     "status": "active",
     "active": true,
     "installed": "1.7.7",
     "available": "1.7.8",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.7.7 -> 1.7.8"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wordpress-importer",
     "status": "active",
     "active": true,
     "installed": "0.9.5",
     "available": "0.9.6",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 0.9.5 -> 0.9.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "cookie-law-info",
     "status": "inactive",
     "active": false,
     "installed": "3.4.0",
     "available": "3.5.6",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 3.4.0 -> 3.5.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    }
   ],
   "p0": 1,
   "p1": 5,
   "total_updates": 23
  },
  "wpengine:indysoftdev1": {
   "platform": "wpengine",
   "install": "indysoftdev1",
   "environment": "development",
   "domain": "indysoftdev1.wpenginepowered.com",
   "siteurl": "https://indysoftdev1.wpenginepowered.com",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "Indysoft",
   "updates": [
    {
     "plugin": "updraftplus",
     "status": "active",
     "active": true,
     "installed": "1.25.6",
     "available": "1.26.7",
     "priority": "P1",
     "vulns": [
      {
       "name": "UpdraftPlus: WP Backup &amp; Migration Plugin [updraftplus] < 1.26.5",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2026-10795"
      },
      {
       "name": "UpdraftPlus: WP Backup &amp; Migration Plugin [updraftplus] < 1.26.7",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-76549"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "minor version bump 1.25.6 -> 1.26.7",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "admin-site-enhancements",
     "status": "active",
     "active": true,
     "installed": "7.9.2",
     "available": "9.1.2",
     "priority": "P2",
     "vulns": [
      {
       "name": "Admin and Site Enhancements (ASE) [admin-site-enhancements] < 8.4.1",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-32423"
      },
      {
       "name": "Admin and Site Enhancements (ASE) [admin-site-enhancements] < 8.1.0",
       "cvss": "2.7",
       "severity": "LOW",
       "cve": "CVE-2025-64255"
      },
      {
       "name": "Admin and Site Enhancements (ASE) [admin-site-enhancements] < 7.9.8",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2025-9487"
      },
      {
       "name": "Admin and Site Enhancements (ASE) [admin-site-enhancements] < 8.8.4",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-12083"
      }
     ],
     "vuln_count": 5,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 7.9.2 -> 9.1.2 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "advanced-custom-fields-pro",
     "status": "active",
     "active": true,
     "installed": "6.4.3",
     "available": "6.8.10",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "multi-minor jump 6.4.3 -> 6.8.10 (skipped 4 minor releases)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE WITH CAPTURE \u2014 routine bump but on a sitewide-impact plugin; watch the diff closely."
    }
   ],
   "p0": 0,
   "p1": 1,
   "total_updates": 3
  },
  "wpengine:ascmlsprimatic": {
   "platform": "wpengine",
   "install": "ascmlsprimatic",
   "environment": "production",
   "domain": "ascmlsprimatic.wpenginepowered.com",
   "siteurl": "https://ascmlsprimatic.wpenginepowered.com",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "theme",
   "updates": [
    {
     "plugin": "translatepress-multilingual",
     "status": "active",
     "active": true,
     "installed": "3.0.8",
     "available": "3.3.6",
     "priority": "P0",
     "vulns": [
      {
       "name": "TranslatePress &#8211; Translate Multilingual sites with AI Translation [translatepress-multilingual] < 3.3.3",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2026-78267"
      },
      {
       "name": "TranslatePress &#8211; Translate Multilingual sites with AI Translation [translatepress-multilingual] < 3.3.2",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2026-19632"
      },
      {
       "name": "TranslatePress &#8211; Translate Multilingual sites with AI Translation [translatepress-multilingual] < 3.3",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-18510"
      },
      {
       "name": "TranslatePress &#8211; Translate Multilingual sites with AI Translation [translatepress-multilingual] < 3.2.6",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-75981"
      }
     ],
     "vuln_count": 8,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.0.8 -> 3.3.6 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "gravityforms",
     "status": "active",
     "active": true,
     "installed": "2.10.5",
     "available": "3.1.1",
     "priority": "P1",
     "vulns": [
      {
       "name": "Gravity Forms [gravityforms] < 3.0.3",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2026-19513"
      },
      {
       "name": "Gravity Forms [gravityforms] < 3.0.0",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-16649"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.10.5 -> 3.1.1 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "mainwp-child",
     "status": "active",
     "active": true,
     "installed": "5.4.1",
     "available": "6.2",
     "priority": "P1",
     "vulns": [
      {
       "name": "MainWP Child &#8211; Securely Connects to the MainWP Dashboard to Manage Multiple Sites [mainwp-child] < 6.1.2",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-27366"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 5.4.1 -> 6.2 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "popup-maker",
     "status": "active",
     "active": true,
     "installed": "1.21.5",
     "available": "1.25.0",
     "priority": "P1",
     "vulns": [
      {
       "name": "Popup Maker &#8211; Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.23.0",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-8848"
      },
      {
       "name": "Popup Maker &#8211; Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.24.0",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-28177"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 1.21.5 -> 1.25.0 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "wp-smushit",
     "status": "active",
     "active": true,
     "installed": "3.23.4",
     "available": "4.3.3",
     "priority": "P1",
     "vulns": [
      {
       "name": "Smush \u2013 Image Optimization, Compression, Lazy Load, WebP &amp; CDN [wp-smushit] < 4.3.0",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-81285"
      },
      {
       "name": "Smush \u2013 Image Optimization, Compression, Lazy Load, WebP &amp; CDN [wp-smushit] < 4.3.2",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-19223"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.23.4 -> 4.3.3 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "insert-headers-and-footers",
     "status": "active",
     "active": true,
     "installed": "2.3.3",
     "available": "2.3.9",
     "priority": "P1",
     "vulns": [
      {
       "name": "WPCode &#8211; Insert Headers and Footers + Custom Code Snippets &#8211; WordPress Code Manager [insert-headers-and-footers] < 2.3.6",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-8832"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 2.3.3 -> 2.3.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "acf-to-rest-api",
     "status": "active",
     "active": true,
     "installed": "3.3.4",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "ACF to REST API [acf-to-rest-api] <= 3.3.4 (unfixed + closed)",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-62979"
      },
      {
       "name": "ACF to REST API [acf-to-rest-api] <= 3.3.4 (unfixed + closed)",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-12030"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "wp-migrate-db",
     "status": "active",
     "active": true,
     "installed": "2.7.0",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "WP Migrate Lite &#8211; Migration Made Easy [wp-migrate-db] < 2.7.7",
       "cvss": "5.8",
       "severity": "MEDIUM",
       "cve": "CVE-2025-11427"
      },
      {
       "name": "WP Migrate Lite &#8211; Migration Made Easy [wp-migrate-db] < 2.7.9",
       "cvss": "4.7",
       "severity": "MEDIUM",
       "cve": "CVE-2026-49043"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "duplicate-post",
     "status": "active",
     "active": true,
     "installed": "4.5",
     "available": "4.7",
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast Duplicate Post [duplicate-post] <= 4.6 (unfixed)",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-53740"
      },
      {
       "name": "Yoast Duplicate Post [duplicate-post] <= 4.6 (unfixed)",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-53739"
      },
      {
       "name": "Yoast Duplicate Post [duplicate-post] < 4.6",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-1217"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 4.5 -> 4.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "better-wp-security",
     "status": "active",
     "active": true,
     "installed": "9.4.4",
     "available": "10.0.3",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 9.4.4 -> 10.0.3 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "advanced-custom-fields-pro",
     "status": "active",
     "active": true,
     "installed": "6.7.0.2",
     "available": "6.8.10",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "minor version bump 6.7.0.2 -> 6.8.10",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE WITH CAPTURE \u2014 routine bump but on a sitewide-impact plugin; watch the diff closely."
    },
    {
     "plugin": "akismet",
     "status": "active",
     "active": true,
     "installed": "5.6",
     "available": "5.7.2",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 5.6 -> 5.7.2"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "force-regenerate-thumbnails",
     "status": "active",
     "active": true,
     "installed": "2.2.2",
     "available": "2.3.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.2.2 -> 2.3.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "redirection",
     "status": "active",
     "active": true,
     "installed": "5.6.1",
     "available": "5.10.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.6.1 -> 5.10.0 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "simple-page-ordering",
     "status": "active",
     "active": true,
     "installed": "2.7.4",
     "available": "2.8.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.7.4 -> 2.8.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "translatepress-developer",
     "status": "active",
     "active": true,
     "installed": "1.7.3",
     "available": "1.8.7",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.7.3 -> 1.8.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wordpress-importer",
     "status": "active",
     "active": true,
     "installed": "0.9.5",
     "available": "0.9.6",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 0.9.5 -> 0.9.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wp-mail-smtp",
     "status": "active",
     "active": true,
     "installed": "4.7.1",
     "available": "4.9.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 4.7.1 -> 4.9.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    }
   ],
   "p0": 1,
   "p1": 5,
   "total_updates": 16
  },
  "wpengine:adastrusted": {
   "platform": "wpengine",
   "install": "adastrusted",
   "environment": "production",
   "domain": "adastrusted.wpenginepowered.com",
   "siteurl": "http://www.adastrustednetwork.com",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "adas",
   "updates": [
    {
     "plugin": "admin-site-enhancements",
     "status": "active",
     "active": true,
     "installed": "8.2.1",
     "available": "9.1.2",
     "priority": "P2",
     "vulns": [
      {
       "name": "Admin and Site Enhancements (ASE) [admin-site-enhancements] < 8.4.1",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-32423"
      },
      {
       "name": "Admin and Site Enhancements (ASE) [admin-site-enhancements] < 8.8.4",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-12083"
      },
      {
       "name": "Admin and Site Enhancements (ASE) [admin-site-enhancements] < 9.0.1",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-19615"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 8.2.1 -> 9.1.2 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "wp-security-audit-log",
     "status": "active",
     "active": true,
     "installed": "5.6.4",
     "available": "5.6.6",
     "priority": "P2",
     "vulns": [
      {
       "name": "WP Activity Log [wp-security-audit-log] < 5.6.5",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-65512"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 5.6.4 -> 5.6.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "advanced-custom-fields-pro",
     "status": "active",
     "active": true,
     "installed": "6.7.0.1",
     "available": "6.8.10",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "minor version bump 6.7.0.1 -> 6.8.10",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE WITH CAPTURE \u2014 routine bump but on a sitewide-impact plugin; watch the diff closely."
    }
   ],
   "p0": 0,
   "p1": 0,
   "total_updates": 3
  },
  "wpengine:storylinedev": {
   "platform": "wpengine",
   "install": "storylinedev",
   "environment": "development",
   "domain": "storylinedev.wpenginepowered.com",
   "siteurl": "http://storylinedev.wpenginepowered.com",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "hazel",
   "updates": [
    {
     "plugin": "simply-gallery-block",
     "status": "active",
     "active": true,
     "installed": "2.2.6",
     "available": null,
     "priority": "P0",
     "vulns": [
      {
       "name": "SimpLy Gallery [simply-gallery-block] < 3.3.2.1",
       "cvss": "9.9",
       "severity": "CRITICAL",
       "cve": "CVE-2026-25345"
      },
      {
       "name": "SimpLy Gallery [simply-gallery-block] < 3.0.8",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2023-0441"
      },
      {
       "name": "SimpLy Gallery [simply-gallery-block] < 3.1.5",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2023-33999"
      },
      {
       "name": "SimpLy Gallery [simply-gallery-block] < 3.3.2.2",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-63052"
      }
     ],
     "vuln_count": 13,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "woocommerce",
     "status": "active",
     "active": true,
     "installed": "9.1.3",
     "available": null,
     "priority": "P0",
     "vulns": [
      {
       "name": "WooCommerce [woocommerce] == 7.1.0 (unfixed)",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2022-50972"
      },
      {
       "name": "WooCommerce [woocommerce] < 11.0",
       "cvss": "7.6",
       "severity": "HIGH",
       "cve": "CVE-2026-57777"
      },
      {
       "name": "WooCommerce [woocommerce] < 11.1.0",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-48888"
      },
      {
       "name": "WooCommerce [woocommerce] < 10.4.3",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-15033"
      }
     ],
     "vuln_count": 9,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "cubeportfolio",
     "status": "active",
     "active": true,
     "installed": "1.16.8",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "Cube Portfolio [cubeportfolio] <= 1.16.8 (unfixed + closed)",
       "cvss": "8.5",
       "severity": "HIGH",
       "cve": "CVE-2025-52823"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "revslider",
     "status": "active",
     "active": true,
     "installed": "6.7.18",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "Slider Revolution [revslider] < 7.0.11",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-6692"
      },
      {
       "name": "Slider Revolution [revslider] < 7.1.0",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-57678"
      },
      {
       "name": "Slider Revolution [revslider] < 6.7.37",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-9217"
      },
      {
       "name": "Slider Revolution [revslider] < 6.7.38",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-10249"
      }
     ],
     "vuln_count": 9,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "Ultimate_VC_Addons",
     "status": "active",
     "active": true,
     "installed": "3.16.19",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "Ultimate Addons for Visual Composer [Ultimate_VC_Addons] < 3.19.15",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2023-46205"
      },
      {
       "name": "Ultimate Addons for Visual Composer [Ultimate_VC_Addons] < 3.19.15",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2023-46211"
      },
      {
       "name": "Ultimate Addons for Visual Composer [Ultimate_VC_Addons] < 3.21.1",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-11814"
      },
      {
       "name": "Ultimate Addons for Visual Composer [Ultimate_VC_Addons] < 3.19.20.1",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-5251"
      }
     ],
     "vuln_count": 9,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "updraftplus",
     "status": "active",
     "active": true,
     "installed": "1.25.1",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "UpdraftPlus: WP Backup &amp; Migration Plugin [updraftplus] < 1.26.5",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2026-10795"
      },
      {
       "name": "UpdraftPlus: WP Backup &amp; Migration Plugin [updraftplus] < 1.26.7",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-76549"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "insert-headers-and-footers",
     "status": "active",
     "active": true,
     "installed": "2.2.6",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "WPCode &#8211; Insert Headers and Footers + Custom Code Snippets &#8211; WordPress Code Manager [insert-headers-and-footers] < 2.3.6",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-8832"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "wpforms-lite",
     "status": "active",
     "active": true,
     "installed": "1.9.2.3",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "WPForms &#8211; AI Form Builder for WordPress &#8211; Contact Forms, Payment Forms, Survey Form, Quiz &amp; More [wpforms-lite] < 1.10.0.3",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2026-40764"
      },
      {
       "name": "WPForms &#8211; AI Form Builder for WordPress &#8211; Contact Forms, Payment Forms, Survey Form, Quiz &amp; More [wpforms-lite] < 1.10.0.5",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-48835"
      },
      {
       "name": "WPForms &#8211; AI Form Builder for WordPress &#8211; Contact Forms, Payment Forms, Survey Form, Quiz &amp; More [wpforms-lite] < 1.9.9.2",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-25339"
      },
      {
       "name": "WPForms &#8211; AI Form Builder for WordPress &#8211; Contact Forms, Payment Forms, Survey Form, Quiz &amp; More [wpforms-lite] < 1.9.3.2",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-13403"
      }
     ],
     "vuln_count": 11,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "contact-form-7",
     "status": "active",
     "active": true,
     "installed": "6.0",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Contact Form 7 [contact-form-7] < 6.0.6",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-3247"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "enable-jquery-migrate-helper",
     "status": "active",
     "active": true,
     "installed": "1.3.0",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Enable jQuery Migrate Helper [enable-jquery-migrate-helper] <= 1.4.1 (unfixed + closed)",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-3279"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "jetpack",
     "status": "active",
     "active": true,
     "installed": "13.8.2",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Jetpack &#8211; WP Security, Backup, Speed, &amp; Growth [jetpack] >= 3.2 - < 16.1.3",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2024-10858"
      },
      {
       "name": "Jetpack &#8211; WP Security, Backup, Speed, &amp; Growth [jetpack] == 11.4",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2023-54332"
      },
      {
       "name": "Jetpack &#8211; WP Security, Backup, Speed, &amp; Growth [jetpack] < 13.9.1",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2024-9926"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "google-site-kit",
     "status": "active",
     "active": true,
     "installed": "1.45.0",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Site Kit by Google &#8211; Analytics, Search Console, AdSense, Speed [google-site-kit] < 1.187.0",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-62139"
      },
      {
       "name": "Site Kit by Google &#8211; Analytics, Search Console, AdSense, Speed [google-site-kit] < 1.176.0",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-10753"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "wordpress-seo",
     "status": "active",
     "active": true,
     "installed": "22.7",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 26.6",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-14481"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 27.2",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-3427"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 26.9",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-1293"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 28.1",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-15425"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    }
   ],
   "p0": 2,
   "p1": 6,
   "total_updates": 0
  },
  "wpengine:indico2025dev": {
   "platform": "wpengine",
   "install": "indico2025dev",
   "environment": "development",
   "domain": "indico2025dev.wpenginepowered.com",
   "siteurl": "http://indico2025dev.wpenginepowered.com",
   "core": "7.0.4",
   "core_update": null,
   "theme": "bootscore-child",
   "updates": [
    {
     "plugin": "wp-security-audit-log",
     "status": "active",
     "active": true,
     "installed": "5.5.0",
     "available": null,
     "priority": "P0",
     "vulns": [
      {
       "name": "WP Activity Log [wp-security-audit-log] < 5.6.4",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2026-54806"
      },
      {
       "name": "WP Activity Log [wp-security-audit-log] < 5.6.4",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-56005"
      },
      {
       "name": "WP Activity Log [wp-security-audit-log] < 5.6.0",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-25331"
      },
      {
       "name": "WP Activity Log [wp-security-audit-log] < 5.6.3.1",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-45435"
      }
     ],
     "vuln_count": 5,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "insert-headers-and-footers",
     "status": "active",
     "active": true,
     "installed": "2.3.0",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "WPCode &#8211; Insert Headers and Footers + Custom Code Snippets &#8211; WordPress Code Manager [insert-headers-and-footers] < 2.3.6",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-8832"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "admin-site-enhancements",
     "status": "active",
     "active": true,
     "installed": "7.9.9",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Admin and Site Enhancements (ASE) [admin-site-enhancements] < 8.4.1",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-32423"
      },
      {
       "name": "Admin and Site Enhancements (ASE) [admin-site-enhancements] < 8.1.0",
       "cvss": "2.7",
       "severity": "LOW",
       "cve": "CVE-2025-64255"
      },
      {
       "name": "Admin and Site Enhancements (ASE) [admin-site-enhancements] < 8.8.4",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-12083"
      },
      {
       "name": "Admin and Site Enhancements (ASE) [admin-site-enhancements] < 9.0.1",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-19615"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "smtp2go",
     "status": "active",
     "active": true,
     "installed": "1.12.2",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "SMTP2GO for WordPress &#8211; Email Made Easy [smtp2go] < 1.17.0",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-7621"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "wordpress-seo",
     "status": "active",
     "active": true,
     "installed": "26.0",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 26.6",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-14481"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 27.2",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-3427"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 26.9",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-1293"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 28.1",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-15425"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    }
   ],
   "p0": 1,
   "p1": 1,
   "total_updates": 0
  },
  "wpengine:lismarstg": {
   "platform": "wpengine",
   "install": "lismarstg",
   "environment": "staging",
   "domain": "lismarstg.wpenginepowered.com",
   "siteurl": "https://lismarstg.wpenginepowered.com",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "theme",
   "updates": [
    {
     "plugin": "gravityforms",
     "status": "active",
     "active": true,
     "installed": "2.8.18",
     "available": "3.1.1",
     "priority": "P0",
     "vulns": [
      {
       "name": "Gravity Forms [gravityforms] < 2.9.21",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2025-12352"
      },
      {
       "name": "Gravity Forms [gravityforms] < 2.10.1",
       "cvss": "9.6",
       "severity": "CRITICAL",
       "cve": "CVE-2026-48866"
      },
      {
       "name": "Gravity Forms [gravityforms] < 2.9.22",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2025-12974"
      },
      {
       "name": "Gravity Forms [gravityforms] < 3.0.3",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2026-19513"
      }
     ],
     "vuln_count": 17,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.8.18 -> 3.1.1 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "translatepress-multilingual",
     "status": "active",
     "active": true,
     "installed": "2.8.3",
     "available": "3.3.6",
     "priority": "P0",
     "vulns": [
      {
       "name": "TranslatePress &#8211; Translate Multilingual sites with AI Translation [translatepress-multilingual] < 3.3.3",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2026-78267"
      },
      {
       "name": "TranslatePress &#8211; Translate Multilingual sites with AI Translation [translatepress-multilingual] < 3.3.2",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2026-19632"
      },
      {
       "name": "TranslatePress &#8211; Translate Multilingual sites with AI Translation [translatepress-multilingual] < 2.10.3",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2025-58592"
      },
      {
       "name": "TranslatePress &#8211; Translate Multilingual sites with AI Translation [translatepress-multilingual] < 3.3",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-18510"
      }
     ],
     "vuln_count": 10,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.8.3 -> 3.3.6 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "popup-maker",
     "status": "active",
     "active": true,
     "installed": "1.20.2",
     "available": "1.25.0",
     "priority": "P1",
     "vulns": [
      {
       "name": "Popup Maker &#8211; Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.23.0",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-8848"
      },
      {
       "name": "Popup Maker &#8211; Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.24.0",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-28177"
      },
      {
       "name": "Popup Maker &#8211; Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.20.3",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-24746"
      },
      {
       "name": "Popup Maker &#8211; Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.20.5",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-4205"
      }
     ],
     "vuln_count": 6,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 1.20.2 -> 1.25.0 (skipped 5 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "wp-smushit",
     "status": "active",
     "active": true,
     "installed": "3.16.6",
     "available": "4.3.3",
     "priority": "P1",
     "vulns": [
      {
       "name": "Smush \u2013 Image Optimization, Compression, Lazy Load, WebP &amp; CDN [wp-smushit] < 4.3.0",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-81285"
      },
      {
       "name": "Smush \u2013 Image Optimization, Compression, Lazy Load, WebP &amp; CDN [wp-smushit] < 3.17.1",
       "cvss": "4.1",
       "severity": "MEDIUM",
       "cve": "CVE-2025-22288"
      },
      {
       "name": "Smush \u2013 Image Optimization, Compression, Lazy Load, WebP &amp; CDN [wp-smushit] < 4.3.2",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-19223"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.16.6 -> 4.3.3 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "wordpress-importer",
     "status": "active",
     "active": true,
     "installed": "0.8.2",
     "available": "0.9.6",
     "priority": "P1",
     "vulns": [
      {
       "name": "WordPress Importer [wordpress-importer] < 0.8.4",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2024-13889"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 0.8.2 -> 0.9.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "insert-headers-and-footers",
     "status": "active",
     "active": true,
     "installed": "2.2.2",
     "available": "2.3.9",
     "priority": "P1",
     "vulns": [
      {
       "name": "WPCode &#8211; Insert Headers and Footers + Custom Code Snippets &#8211; WordPress Code Manager [insert-headers-and-footers] < 2.3.6",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-8832"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.2.2 -> 2.3.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "acf-to-rest-api",
     "status": "active",
     "active": true,
     "installed": "3.3.3",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "ACF to REST API [acf-to-rest-api] <= 3.3.4 (unfixed + closed)",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-62979"
      },
      {
       "name": "ACF to REST API [acf-to-rest-api] <= 3.3.4 (unfixed + closed)",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-12030"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "advanced-custom-fields-pro",
     "status": "active",
     "active": true,
     "installed": "6.3.6",
     "available": "6.8.10",
     "priority": "P2",
     "vulns": [
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.3.8",
       "cvss": "6.6",
       "severity": "MEDIUM",
       "cve": "CVE-2024-9529"
      },
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.3.9",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2024-49593"
      },
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.3.9",
       "cvss": null,
       "severity": null,
       "cve": ""
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "multi-minor jump 6.3.6 -> 6.8.10 (skipped 5 minor releases)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "limit-login-attempts-reloaded",
     "status": "active",
     "active": true,
     "installed": "2.26.13",
     "available": "3.3.8",
     "priority": "P2",
     "vulns": [
      {
       "name": "Limit Login Attempts Security &#8211; Login Security, 2FA, Firewall, Brute Force Prevention [limit-login-attempts-reloaded] < 3.3.5",
       "cvss": "3.7",
       "severity": "LOW",
       "cve": "CVE-2026-18356"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.26.13 -> 3.3.8 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "sucuri-scanner",
     "status": "active",
     "active": true,
     "installed": "1.9.4",
     "available": "2.8",
     "priority": "P2",
     "vulns": [
      {
       "name": "Sucuri Security &#8211; Auditing, Malware Scanner and Security Hardening [sucuri-scanner] <= 2.7.3 (unfixed)",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-73033"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 1.9.4 -> 2.8 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "two-factor-2fa-via-email",
     "status": "active",
     "active": true,
     "installed": "1.9.4",
     "available": "1.9.10",
     "priority": "P2",
     "vulns": [
      {
       "name": "Two Factor (2FA) Authentication via Email [two-factor-2fa-via-email] < 1.9.9",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-13587"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.9.4 -> 1.9.10"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "duplicate-post",
     "status": "active",
     "active": true,
     "installed": "4.5",
     "available": "4.7",
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast Duplicate Post [duplicate-post] <= 4.6 (unfixed)",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-53740"
      },
      {
       "name": "Yoast Duplicate Post [duplicate-post] <= 4.6 (unfixed)",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-53739"
      },
      {
       "name": "Yoast Duplicate Post [duplicate-post] < 4.6",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-1217"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 4.5 -> 4.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "change-admin-email-setting-without-outbound-email",
     "status": "active",
     "active": true,
     "installed": "3.4",
     "available": "5.0",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.4 -> 5.0 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "olympus-google-fonts",
     "status": "active",
     "active": true,
     "installed": "3.7.9",
     "available": "4.2.2",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.7.9 -> 4.2.2 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "better-wp-security",
     "status": "active",
     "active": true,
     "installed": "9.3.3",
     "available": "10.0.3",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 9.3.3 -> 10.0.3 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "host-webfonts-local",
     "status": "inactive",
     "active": false,
     "installed": "5.9.1",
     "available": "6.3.10",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 5.9.1 -> 6.3.10 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "force-regenerate-thumbnails",
     "status": "active",
     "active": true,
     "installed": "2.2.0",
     "available": "2.3.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.2.0 -> 2.3.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "headers-security-advanced-hsts-wp",
     "status": "active",
     "active": true,
     "installed": "5.0.40",
     "available": "5.3.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.0.40 -> 5.3.5 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "redirection",
     "status": "active",
     "active": true,
     "installed": "5.5.0",
     "available": "5.10.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.5.0 -> 5.10.0 (skipped 5 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "simple-page-ordering",
     "status": "active",
     "active": true,
     "installed": "2.7.2",
     "available": "2.8.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.7.2 -> 2.8.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "autodescription",
     "status": "active",
     "active": true,
     "installed": "5.0.6",
     "available": "5.1.4",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 5.0.6 -> 5.1.4"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "translatepress-developer",
     "status": "active",
     "active": true,
     "installed": "1.4.1",
     "available": "1.8.7",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 1.4.1 -> 1.8.7 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wp-mail-smtp",
     "status": "active",
     "active": true,
     "installed": "4.1.1",
     "available": "4.9.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 4.1.1 -> 4.9.0 (skipped 8 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "cookie-law-info",
     "status": "inactive",
     "active": false,
     "installed": "3.2.6",
     "available": "3.5.6",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.2.6 -> 3.5.6 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    }
   ],
   "p0": 2,
   "p1": 4,
   "total_updates": 23
  },
  "wpengine:paclinedev": {
   "platform": "wpengine",
   "install": "paclinedev",
   "environment": "development",
   "domain": "paclinedev.wpenginepowered.com",
   "siteurl": "http://paclinedev.wpenginepowered.com",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "bootscore-child",
   "updates": [
    {
     "plugin": "insert-headers-and-footers",
     "status": "active",
     "active": true,
     "installed": "2.3.5",
     "available": "2.3.9",
     "priority": "P1",
     "vulns": [
      {
       "name": "WPCode &#8211; Insert Headers and Footers + Custom Code Snippets &#8211; WordPress Code Manager [insert-headers-and-footers] < 2.3.6",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-8832"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 2.3.5 -> 2.3.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "admin-site-enhancements",
     "status": "active",
     "active": true,
     "installed": "8.6.1",
     "available": "9.1.2",
     "priority": "P2",
     "vulns": [
      {
       "name": "Admin and Site Enhancements (ASE) [admin-site-enhancements] < 8.8.4",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-12083"
      },
      {
       "name": "Admin and Site Enhancements (ASE) [admin-site-enhancements] < 9.0.1",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-19615"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 8.6.1 -> 9.1.2 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "flamingo",
     "status": "active",
     "active": true,
     "installed": "2.6.1",
     "available": "2.6.4",
     "priority": "P2",
     "vulns": [
      {
       "name": "Flamingo [flamingo] < 2.6.3",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-12853"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 2.6.1 -> 2.6.4"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "smtp2go",
     "status": "active",
     "active": true,
     "installed": "1.14.1",
     "available": "1.17.1",
     "priority": "P2",
     "vulns": [
      {
       "name": "SMTP2GO for WordPress &#8211; Email Made Easy [smtp2go] < 1.17.0",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-7621"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 1.14.1 -> 1.17.1 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "wordpress-seo",
     "status": "active",
     "active": true,
     "installed": "27.3",
     "available": "28.5",
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 28.1",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-15425"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 27.3 -> 28.5 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "advanced-custom-fields-pro",
     "status": "active",
     "active": true,
     "installed": "6.8.0.1",
     "available": "6.8.10",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "patch bump 6.8.0.1 -> 6.8.10",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE WITH CAPTURE \u2014 routine bump but on a sitewide-impact plugin; watch the diff closely."
    },
    {
     "plugin": "contact-form-7",
     "status": "active",
     "active": true,
     "installed": "6.1.5",
     "available": "6.1.7",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 6.1.5 -> 6.1.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "headers-security-advanced-hsts-wp",
     "status": "active",
     "active": true,
     "installed": "5.3.2",
     "available": "5.3.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 5.3.2 -> 5.3.5"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "view-transitions",
     "status": "active",
     "active": true,
     "installed": "1.2.0",
     "available": "1.2.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.2.0 -> 1.2.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    }
   ],
   "p0": 0,
   "p1": 1,
   "total_updates": 9
  },
  "wpengine:n101": {
   "platform": "wpengine",
   "install": "n101",
   "environment": "staging",
   "domain": "n101.wpenginepowered.com",
   "siteurl": "https://n101.wpenginepowered.com",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "Impreza-child",
   "updates": [
    {
     "plugin": "elementor-pro",
     "status": "inactive",
     "active": false,
     "installed": "4.0.1",
     "available": null,
     "priority": "P0",
     "vulns": [
      {
       "name": "Elementor Pro [elementor-pro] < 4.2.2",
       "cvss": "9.0",
       "severity": "CRITICAL",
       "cve": "CVE-2026-32475"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "all-in-one-wp-migration",
     "status": "active",
     "active": true,
     "installed": "7.105",
     "available": "7.111",
     "priority": "P1",
     "vulns": [
      {
       "name": "All-in-One WP Migration and Backup [all-in-one-wp-migration] < 7.110",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-19949"
      },
      {
       "name": "All-in-One WP Migration and Backup [all-in-one-wp-migration] < 7.106",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-12898"
      },
      {
       "name": "All-in-One WP Migration and Backup [all-in-one-wp-migration] < 7.108",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-17533"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 7.105 -> 7.111 (skipped 6 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "gravityforms",
     "status": "active",
     "active": true,
     "installed": "2.10.5",
     "available": "3.1.1",
     "priority": "P1",
     "vulns": [
      {
       "name": "Gravity Forms [gravityforms] < 3.0.3",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2026-19513"
      },
      {
       "name": "Gravity Forms [gravityforms] < 3.0.0",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-16649"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.10.5 -> 3.1.1 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "wp-smushit",
     "status": "inactive",
     "active": false,
     "installed": "3.24.0",
     "available": "4.3.3",
     "priority": "P1",
     "vulns": [
      {
       "name": "Smush \u2013 Image Optimization, Compression, Lazy Load, WebP &amp; CDN [wp-smushit] < 4.3.0",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-81285"
      },
      {
       "name": "Smush \u2013 Image Optimization, Compression, Lazy Load, WebP &amp; CDN [wp-smushit] < 4.3.2",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-19223"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.24.0 -> 4.3.3 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wp-optimize",
     "status": "inactive",
     "active": false,
     "installed": "4.5.1",
     "available": "4.6.1",
     "priority": "P1",
     "vulns": [
      {
       "name": "WP-Optimize \u2013 Cache, Compress images, Minify &amp; Clean database to boost page speed &amp; performance [wp-optimize] < 4.5.3",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2026-7252"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "minor version bump 4.5.1 -> 4.6.1",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "insert-headers-and-footers",
     "status": "inactive",
     "active": false,
     "installed": "2.3.5",
     "available": "2.3.9",
     "priority": "P1",
     "vulns": [
      {
       "name": "WPCode &#8211; Insert Headers and Footers + Custom Code Snippets &#8211; WordPress Code Manager [insert-headers-and-footers] < 2.3.6",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-8832"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 2.3.5 -> 2.3.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wp-fastest-cache",
     "status": "inactive",
     "active": false,
     "installed": "1.4.7",
     "available": "1.5.2",
     "priority": "P1",
     "vulns": [
      {
       "name": "WP Fastest Cache &#8211; WordPress Cache Plugin [wp-fastest-cache] < 1.5.1",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-74932"
      },
      {
       "name": "WP Fastest Cache &#8211; WordPress Cache Plugin [wp-fastest-cache] < 1.5.1",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-19760"
      },
      {
       "name": "WP Fastest Cache &#8211; WordPress Cache Plugin [wp-fastest-cache] < 1.5.1",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-74916"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.4.7 -> 1.5.2"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "all-in-one-wp-migration-unlimited-extension",
     "status": "active",
     "active": true,
     "installed": "2.83",
     "available": "2.87",
     "priority": "P2",
     "vulns": [
      {
       "name": "All-in-One WP Migration Unlimited Extension [all-in-one-wp-migration-unlimited-extension] < 2.84",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-5753"
      },
      {
       "name": "All-in-One WP Migration Unlimited Extension [all-in-one-wp-migration-unlimited-extension] < 2.85",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-6128"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 2.83 -> 2.87 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "styles-and-layouts-for-gravity-forms",
     "status": "active",
     "active": true,
     "installed": "5.26",
     "available": "6.1",
     "priority": "P2",
     "vulns": [
      {
       "name": "Gravity Booster &#8211; Styles &amp; Layouts for Gravity Forms [styles-and-layouts-for-gravity-forms] <= 6.0 (unfixed)",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-74004"
      },
      {
       "name": "Gravity Booster &#8211; Styles &amp; Layouts for Gravity Forms [styles-and-layouts-for-gravity-forms] < 6.0",
       "cvss": "4.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-12477"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 5.26 -> 6.1 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "wordpress-seo",
     "status": "active",
     "active": true,
     "installed": "27.4",
     "available": "28.5",
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 28.1",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-15425"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 27.4 -> 28.5 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "advanced-custom-fields",
     "status": "inactive",
     "active": false,
     "installed": "6.8.0",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Advanced Custom Fields (ACF\u00ae) [advanced-custom-fields] < 6.8.2",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-8382"
      },
      {
       "name": "Advanced Custom Fields (ACF\u00ae) [advanced-custom-fields] < 6.8.2",
       "cvss": null,
       "severity": null,
       "cve": ""
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "elementor",
     "status": "inactive",
     "active": false,
     "installed": "4.0.1",
     "available": "4.2.4",
     "priority": "P2",
     "vulns": [
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 4.1.4",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-57619"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 4.0.5",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-6127"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 4.1.1",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-49782"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 4.1.4",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-8825"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "minor version bump 4.0.1 -> 4.2.4",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "limit-login-attempts-reloaded",
     "status": "inactive",
     "active": false,
     "installed": "3.1.0",
     "available": "3.3.8",
     "priority": "P2",
     "vulns": [
      {
       "name": "Limit Login Attempts Security &#8211; Login Security, 2FA, Firewall, Brute Force Prevention [limit-login-attempts-reloaded] < 3.3.5",
       "cvss": "3.7",
       "severity": "LOW",
       "cve": "CVE-2026-18356"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 3.1.0 -> 3.3.8"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "svg-support",
     "status": "inactive",
     "active": false,
     "installed": "2.5.14",
     "available": "2.6.1",
     "priority": "P2",
     "vulns": [
      {
       "name": "SVG Support [svg-support] < 2.5.15",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-48973"
      },
      {
       "name": "SVG Support [svg-support] < 2.5.17",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-13340"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.5.14 -> 2.6.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "white-label-cms",
     "status": "inactive",
     "active": false,
     "installed": "2.7.9",
     "available": "2.7.14",
     "priority": "P2",
     "vulns": [
      {
       "name": "White Label CMS [white-label-cms] < 2.7.13",
       "cvss": "4.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-11898"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 2.7.9 -> 2.7.14"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wp-2fa",
     "status": "inactive",
     "active": false,
     "installed": "3.1.1.2",
     "available": "4.1.0",
     "priority": "P2",
     "vulns": [
      {
       "name": "WP 2FA &#8211; Two-factor authentication for WordPress [wp-2fa] < 4.1.0",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-15372"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.1.1.2 -> 4.1.0 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "disable-wp-notification",
     "status": "inactive",
     "active": false,
     "installed": "3.4",
     "available": "4.3",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.4 -> 4.3 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "hcaptcha-for-forms-and-more",
     "status": "inactive",
     "active": false,
     "installed": "4.25.0",
     "available": "5.3.0",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 4.25.0 -> 5.3.0 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "accessibility-widget",
     "status": "active",
     "active": true,
     "installed": "3.1.3",
     "available": "3.2.6",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 3.1.3 -> 3.2.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "contact-form-7",
     "status": "active",
     "active": true,
     "installed": "6.1.5",
     "available": "6.1.7",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 6.1.5 -> 6.1.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "cookie-law-info",
     "status": "active",
     "active": true,
     "installed": "3.4.0",
     "available": "3.5.6",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 3.4.0 -> 3.5.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "duplicate-page",
     "status": "active",
     "active": true,
     "installed": "4.5.7",
     "available": "4.5.9",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 4.5.7 -> 4.5.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "safe-svg",
     "status": "active",
     "active": true,
     "installed": "2.4.0",
     "available": "2.5.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.4.0 -> 2.5.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wordpress-importer",
     "status": "active",
     "active": true,
     "installed": "0.9.5",
     "available": "0.9.6",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 0.9.5 -> 0.9.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wp-add-mime-types",
     "status": "active",
     "active": true,
     "installed": "3.1.2",
     "available": "3.2.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 3.1.2 -> 3.2.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "akismet",
     "status": "inactive",
     "active": false,
     "installed": "5.6",
     "available": "5.7.2",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 5.6 -> 5.7.2"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "pojo-accessibility",
     "status": "inactive",
     "active": false,
     "installed": "4.1.0",
     "available": "4.1.4",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 4.1.0 -> 4.1.4"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "custom-post-type-ui",
     "status": "inactive",
     "active": false,
     "installed": "1.18.3",
     "available": "1.19.3",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.18.3 -> 1.19.3"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "headers-security-advanced-hsts-wp",
     "status": "inactive",
     "active": false,
     "installed": "5.3.2",
     "available": "5.3.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 5.3.2 -> 5.3.5"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "post-types-order",
     "status": "inactive",
     "active": false,
     "installed": "2.4.6",
     "available": "2.5.3",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.4.6 -> 2.5.3"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "shortpixel-image-optimiser",
     "status": "inactive",
     "active": false,
     "installed": "6.4.4",
     "available": "6.5.6",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 6.4.4 -> 6.5.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wp-mail-smtp",
     "status": "inactive",
     "active": false,
     "installed": "4.7.1",
     "available": "4.9.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 4.7.1 -> 4.9.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    }
   ],
   "p0": 1,
   "p1": 6,
   "total_updates": 30
  },
  "wpengine:pacelinedev": {
   "platform": "wpengine",
   "install": "pacelinedev",
   "environment": "development",
   "domain": "pacelinedev.wpenginepowered.com",
   "siteurl": "http://pacelinedev.wpenginepowered.com",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "bootscore-child",
   "updates": [
    {
     "plugin": "insert-headers-and-footers",
     "status": "active",
     "active": true,
     "installed": "2.3.5",
     "available": "2.3.9",
     "priority": "P1",
     "vulns": [
      {
       "name": "WPCode &#8211; Insert Headers and Footers + Custom Code Snippets &#8211; WordPress Code Manager [insert-headers-and-footers] < 2.3.6",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-8832"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 2.3.5 -> 2.3.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "admin-site-enhancements",
     "status": "active",
     "active": true,
     "installed": "8.7.0",
     "available": "9.1.2",
     "priority": "P2",
     "vulns": [
      {
       "name": "Admin and Site Enhancements (ASE) [admin-site-enhancements] < 8.8.4",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-12083"
      },
      {
       "name": "Admin and Site Enhancements (ASE) [admin-site-enhancements] < 9.0.1",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-19615"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 8.7.0 -> 9.1.2 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "flamingo",
     "status": "active",
     "active": true,
     "installed": "2.6.1",
     "available": "2.6.4",
     "priority": "P2",
     "vulns": [
      {
       "name": "Flamingo [flamingo] < 2.6.3",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-12853"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 2.6.1 -> 2.6.4"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "smtp2go",
     "status": "active",
     "active": true,
     "installed": "1.14.1",
     "available": "1.17.1",
     "priority": "P2",
     "vulns": [
      {
       "name": "SMTP2GO for WordPress &#8211; Email Made Easy [smtp2go] < 1.17.0",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-7621"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 1.14.1 -> 1.17.1 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "wordpress-seo",
     "status": "active",
     "active": true,
     "installed": "27.4",
     "available": "28.5",
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 28.1",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-15425"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 27.4 -> 28.5 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "google-site-kit",
     "status": "inactive",
     "active": false,
     "installed": "1.176.0",
     "available": "1.187.0",
     "priority": "P2",
     "vulns": [
      {
       "name": "Site Kit by Google &#8211; Analytics, Search Console, AdSense, Speed [google-site-kit] < 1.187.0",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-62139"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 1.176.0 -> 1.187.0 (skipped 11 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "advanced-custom-fields-pro",
     "status": "active",
     "active": true,
     "installed": "6.8.0.1",
     "available": "6.8.10",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "patch bump 6.8.0.1 -> 6.8.10",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE WITH CAPTURE \u2014 routine bump but on a sitewide-impact plugin; watch the diff closely."
    },
    {
     "plugin": "contact-form-7",
     "status": "active",
     "active": true,
     "installed": "6.1.5",
     "available": "6.1.7",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 6.1.5 -> 6.1.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "headers-security-advanced-hsts-wp",
     "status": "active",
     "active": true,
     "installed": "5.3.2",
     "available": "5.3.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 5.3.2 -> 5.3.5"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "view-transitions",
     "status": "active",
     "active": true,
     "installed": "1.2.0",
     "available": "1.2.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.2.0 -> 1.2.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    }
   ],
   "p0": 0,
   "p1": 1,
   "total_updates": 10
  },
  "wpengine:ascentialtest": {
   "platform": "wpengine",
   "install": "ascentialtest",
   "environment": "staging",
   "domain": "ascentialtest.wpenginepowered.com",
   "siteurl": "https://ascentialtest.wpenginepowered.com",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "hello-ascential",
   "updates": [
    {
     "plugin": "elementor-pro",
     "status": "active",
     "active": true,
     "installed": "3.21.3",
     "available": "3.23.3",
     "priority": "P0",
     "vulns": [
      {
       "name": "Elementor Pro [elementor-pro] < 4.2.2",
       "cvss": "9.0",
       "severity": "CRITICAL",
       "cve": "CVE-2026-32475"
      },
      {
       "name": "Elementor Pro [elementor-pro] < 3.25.11",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-8494"
      },
      {
       "name": "Elementor Pro [elementor-pro] < 3.29.1",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-50555"
      },
      {
       "name": "Elementor Pro [elementor-pro] < 3.29.1",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-3076"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "minor version bump 3.21.3 -> 3.23.3",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "hide-my-wp",
     "status": "inactive",
     "active": false,
     "installed": "5.2.01",
     "available": "7.0.11",
     "priority": "P0",
     "vulns": [
      {
       "name": "Hide My WP Ghost &#8211; Security &amp; Firewall [hide-my-wp] < 5.4.02",
       "cvss": "9.6",
       "severity": "CRITICAL",
       "cve": "CVE-2025-26909"
      },
      {
       "name": "Hide My WP Ghost &#8211; Security &amp; Firewall [hide-my-wp] < 5.2.02",
       "cvss": "8.6",
       "severity": "HIGH",
       "cve": "CVE-2024-6420"
      },
      {
       "name": "Hide My WP Ghost &#8211; Security &amp; Firewall [hide-my-wp] < 5.4.02",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2025-2056"
      },
      {
       "name": "Hide My WP Ghost &#8211; Security &amp; Firewall [hide-my-wp] < 7.0.10",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-81806"
      }
     ],
     "vuln_count": 10,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 5.2.01 -> 7.0.11 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "nitropack",
     "status": "inactive",
     "active": false,
     "installed": "1.15.1",
     "available": "1.20.0",
     "priority": "P0",
     "vulns": [
      {
       "name": "NitroPack \u2013 Performance, Page Speed &amp; Cache Plugin for Core Web Vitals, CDN &amp; Image Optimization [nitropack] < 1.16.8",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2024-43922"
      },
      {
       "name": "NitroPack \u2013 Performance, Page Speed &amp; Cache Plugin for Core Web Vitals, CDN &amp; Image Optimization [nitropack] < 1.17.6",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2024-11848"
      },
      {
       "name": "NitroPack \u2013 Performance, Page Speed &amp; Cache Plugin for Core Web Vitals, CDN &amp; Image Optimization [nitropack] < 1.19.4",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-39669"
      },
      {
       "name": "NitroPack \u2013 Performance, Page Speed &amp; Cache Plugin for Core Web Vitals, CDN &amp; Image Optimization [nitropack] < 1.17.6",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2024-11851"
      }
     ],
     "vuln_count": 5,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 1.15.1 -> 1.20.0 (skipped 5 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "alttext-ai",
     "status": "active",
     "active": true,
     "installed": "1.6.1",
     "available": "1.10.38",
     "priority": "P1",
     "vulns": [
      {
       "name": "Alt Text AI &#8211; Automatically generate image alt text for SEO and accessibility [alttext-ai] < 1.9.94",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2025-46232"
      },
      {
       "name": "Alt Text AI &#8211; Automatically generate image alt text for SEO and accessibility [alttext-ai] < 1.10.18",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-25348"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 1.6.1 -> 1.10.38 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "jet-menu",
     "status": "active",
     "active": true,
     "installed": "2.4.4",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "JetMenu [jet-menu] < 2.4.9.1",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2025-26953"
      },
      {
       "name": "JetMenu [jet-menu] < 2.4.11.2",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-53987"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "link-whisper",
     "status": "active",
     "active": true,
     "installed": "0.7.5",
     "available": "0.9.7",
     "priority": "P1",
     "vulns": [
      {
       "name": "Link Whisper Free [link-whisper] < 0.9.1",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2025-11262"
      },
      {
       "name": "Link Whisper Free [link-whisper] < 0.8.9",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2025-67927"
      },
      {
       "name": "Link Whisper Free [link-whisper] < 0.9.3",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-22357"
      },
      {
       "name": "Link Whisper Free [link-whisper] < 0.9.5",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-57333"
      }
     ],
     "vuln_count": 9,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 0.7.5 -> 0.9.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "shortpixel-image-optimiser",
     "status": "active",
     "active": true,
     "installed": "5.6.2",
     "available": "6.5.6",
     "priority": "P1",
     "vulns": [
      {
       "name": "ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 5.6.4",
       "cvss": "7.6",
       "severity": "HIGH",
       "cve": "CVE-2024-48043"
      },
      {
       "name": "ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 6.4.4",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-39471"
      },
      {
       "name": "ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 5.6.4",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-48044"
      },
      {
       "name": "ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 6.3.5",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-11378"
      }
     ],
     "vuln_count": 6,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 5.6.2 -> 6.5.6 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "updraftplus",
     "status": "active",
     "active": true,
     "installed": "1.24.3",
     "available": "1.26.7",
     "priority": "P1",
     "vulns": [
      {
       "name": "UpdraftPlus: WP Backup &amp; Migration Plugin [updraftplus] < 1.24.12",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2024-10957"
      },
      {
       "name": "UpdraftPlus: WP Backup &amp; Migration Plugin [updraftplus] < 1.26.5",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2026-10795"
      },
      {
       "name": "UpdraftPlus: WP Backup &amp; Migration Plugin [updraftplus] < 1.25.1",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2025-0215"
      },
      {
       "name": "UpdraftPlus: WP Backup &amp; Migration Plugin [updraftplus] < 1.26.7",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-76549"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "minor version bump 1.24.3 -> 1.26.7",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "wp-optimize",
     "status": "active",
     "active": true,
     "installed": "3.4.0",
     "available": "4.6.1",
     "priority": "P1",
     "vulns": [
      {
       "name": "WP-Optimize \u2013 Cache, Compress images, Minify &amp; Clean database to boost page speed &amp; performance [wp-optimize] < 4.5.3",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2026-7252"
      },
      {
       "name": "WP-Optimize \u2013 Cache, Compress images, Minify &amp; Clean database to boost page speed &amp; performance [wp-optimize] < 4.2.0",
       "cvss": "4.1",
       "severity": "MEDIUM",
       "cve": "CVE-2025-3951"
      },
      {
       "name": "WP-Optimize \u2013 Cache, Compress images, Minify &amp; Clean database to boost page speed &amp; performance [wp-optimize] < 4.5.1",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-2712"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.4.0 -> 4.6.1 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "wp-all-import-pro",
     "status": "active",
     "active": true,
     "installed": "4.8.8",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "WP All Import Pro [wp-all-import-pro] < 4.9.4",
       "cvss": "7.6",
       "severity": "HIGH",
       "cve": "CVE-2024-9624"
      },
      {
       "name": "WP All Import Pro [wp-all-import-pro] < 4.9.8",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2024-9664"
      },
      {
       "name": "WP All Import Pro [wp-all-import-pro] < 4.9.8",
       "cvss": "5.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-8722"
      },
      {
       "name": "WP All Import Pro [wp-all-import-pro] < 4.9.8",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2024-9661"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "insert-headers-and-footers",
     "status": "active",
     "active": true,
     "installed": "2.1.14",
     "available": "2.3.9",
     "priority": "P1",
     "vulns": [
      {
       "name": "WPCode &#8211; Insert Headers and Footers + Custom Code Snippets &#8211; WordPress Code Manager [insert-headers-and-footers] < 2.3.6",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-8832"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.1.14 -> 2.3.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "wpide",
     "status": "active",
     "active": true,
     "installed": "3.4.9",
     "available": "3.5.9",
     "priority": "P1",
     "vulns": [
      {
       "name": "WPIDE &#8211; File Manager &amp; Code Editor [wpide] < 3.5.7",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-57766"
      },
      {
       "name": "WPIDE &#8211; File Manager &amp; Code Editor [wpide] < 3.5.8",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-66440"
      },
      {
       "name": "WPIDE &#8211; File Manager &amp; Code Editor [wpide] < 3.5.2",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2024-13362"
      },
      {
       "name": "WPIDE &#8211; File Manager &amp; Code Editor [wpide] < 3.5.0",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2024-9546"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 3.4.9 -> 3.5.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "debug-log-manager",
     "status": "inactive",
     "active": false,
     "installed": "2.3.3",
     "available": "2.5.2",
     "priority": "P1",
     "vulns": [
      {
       "name": "Debug Log Manager &#8211; Conveniently Monitor and Inspect Errors [debug-log-manager] < 2.3.5",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2025-3809"
      },
      {
       "name": "Debug Log Manager &#8211; Conveniently Monitor and Inspect Errors [debug-log-manager] < 2.5.1",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-9016"
      },
      {
       "name": "Debug Log Manager &#8211; Conveniently Monitor and Inspect Errors [debug-log-manager] < 2.3.5",
       "cvss": "0.0",
       "severity": null,
       "cve": "CVE-2025-32613"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.3.3 -> 2.5.2"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wp-hide-security-enhancer",
     "status": "inactive",
     "active": false,
     "installed": "2.3.9",
     "available": "2.9.1",
     "priority": "P1",
     "vulns": [
      {
       "name": "WP Hide &amp; Security Enhancer [wp-hide-security-enhancer] < 2.5.2",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2024-11585"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 2.3.9 -> 2.9.1 (skipped 6 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "advanced-custom-fields-pro",
     "status": "active",
     "active": true,
     "installed": "6.3.1.2",
     "available": "6.8.10",
     "priority": "P2",
     "vulns": [
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.3.8",
       "cvss": "6.6",
       "severity": "MEDIUM",
       "cve": "CVE-2024-9529"
      },
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.3.6",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2024-45429"
      },
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.3.2",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-37250"
      },
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.3.9",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2024-49593"
      }
     ],
     "vuln_count": 7,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "multi-minor jump 6.3.1.2 -> 6.8.10 (skipped 5 minor releases)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "elementor",
     "status": "active",
     "active": true,
     "installed": "3.21.8",
     "available": "4.2.4",
     "priority": "P2",
     "vulns": [
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.25.11",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-54444"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.29.1",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-50555"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.35.6",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-32352"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 4.1.4",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-57619"
      }
     ],
     "vuln_count": 22,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.21.8 -> 4.2.4 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "goal-tracker-ga",
     "status": "active",
     "active": true,
     "installed": "1.1.4",
     "available": "1.1.6",
     "priority": "P2",
     "vulns": [
      {
       "name": "Goal Tracker &#8211; Custom Event Tracking for GA4 [goal-tracker-ga] < 1.1.6",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2024-13362"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.1.4 -> 1.1.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "limit-login-attempts-reloaded",
     "status": "active",
     "active": true,
     "installed": "2.26.11",
     "available": "3.3.8",
     "priority": "P2",
     "vulns": [
      {
       "name": "Limit Login Attempts Security &#8211; Login Security, 2FA, Firewall, Brute Force Prevention [limit-login-attempts-reloaded] < 3.3.5",
       "cvss": "3.7",
       "severity": "LOW",
       "cve": "CVE-2026-18356"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.26.11 -> 3.3.8 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "query-monitor",
     "status": "active",
     "active": true,
     "installed": "3.16.3",
     "available": "4.0.7",
     "priority": "P2",
     "vulns": [
      {
       "name": "Query Monitor [query-monitor] < 3.20.4",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-4267"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.16.3 -> 4.0.7 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "search-filter-pro",
     "status": "active",
     "active": true,
     "installed": "2.5.17",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Search & Filter Pro [search-filter-pro] < 2.5.18",
       "cvss": "4.8",
       "severity": "MEDIUM",
       "cve": "CVE-2024-6481"
      },
      {
       "name": "Search & Filter Pro [search-filter-pro] < 2.5.20",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-1528"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "sucuri-scanner",
     "status": "active",
     "active": true,
     "installed": "1.8.44",
     "available": "2.8",
     "priority": "P2",
     "vulns": [
      {
       "name": "Sucuri Security &#8211; Auditing, Malware Scanner and Security Hardening [sucuri-scanner] <= 2.7.3 (unfixed)",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-73033"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 1.8.44 -> 2.8 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "svg-support",
     "status": "active",
     "active": true,
     "installed": "2.5.5",
     "available": "2.6.1",
     "priority": "P2",
     "vulns": [
      {
       "name": "SVG Support [svg-support] < 2.5.11",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-10222"
      },
      {
       "name": "SVG Support [svg-support] < 2.5.9",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2022-23638"
      },
      {
       "name": "SVG Support [svg-support] < 2.5.8",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2023-6708"
      },
      {
       "name": "SVG Support [svg-support] < 2.5.15",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-48973"
      }
     ],
     "vuln_count": 5,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.5.5 -> 2.6.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "wordpress-seo",
     "status": "active",
     "active": true,
     "installed": "22.9",
     "available": "28.5",
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 26.6",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-14481"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 27.2",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-3427"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 26.9",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-1293"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 28.1",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-15425"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 22.9 -> 28.5 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "wordpress-seo-premium",
     "status": "active",
     "active": true,
     "installed": "22.9",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast SEO Premium [wordpress-seo-premium] < 27.6.1",
       "cvss": "6.6",
       "severity": "MEDIUM",
       "cve": "CVE-2026-10821"
      },
      {
       "name": "Yoast SEO Premium [wordpress-seo-premium] < 26.7",
       "cvss": "5.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-40722"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "wp-mail-smtp",
     "status": "inactive",
     "active": false,
     "installed": "4.0.1",
     "available": "4.9.0",
     "priority": "P2",
     "vulns": [
      {
       "name": "WP Mail SMTP by WPForms &#8211; The Most Popular SMTP and Email Log Plugin [wp-mail-smtp] < 4.1.0",
       "cvss": "2.7",
       "severity": "LOW",
       "cve": "CVE-2024-6694"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 4.0.1 -> 4.9.0 (skipped 9 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "font-awesome",
     "status": "active",
     "active": true,
     "installed": "4.5.0",
     "available": "5.2.1",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 4.5.0 -> 5.2.1 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "prevent-browser-caching",
     "status": "active",
     "active": true,
     "installed": "2.3.5",
     "available": "3.2.1",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.3.5 -> 3.2.1 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "wordfence",
     "status": "active",
     "active": true,
     "installed": "7.11.6",
     "available": "9.0.1",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 7.11.6 -> 9.0.1 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "wpai-acf-add-on",
     "status": "active",
     "active": true,
     "installed": "3.3.8",
     "available": "4.0.2",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.3.8 -> 4.0.2 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "eps-301-redirects",
     "status": "active",
     "active": true,
     "installed": "2.75",
     "available": "2.85",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 2.75 -> 2.85 (skipped 10 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "admin-taxonomy-filter",
     "status": "active",
     "active": true,
     "installed": "1.0.4",
     "available": "1.0.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.0.4 -> 1.0.5"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "cachebuster",
     "status": "active",
     "active": true,
     "installed": "1.6",
     "available": "1.10",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 1.6 -> 1.10 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "cookie-law-info",
     "status": "active",
     "active": true,
     "installed": "3.2.4",
     "available": "3.5.6",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.2.4 -> 3.5.6 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "duplicate-page",
     "status": "active",
     "active": true,
     "installed": "4.5.3",
     "available": "4.5.9",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 4.5.3 -> 4.5.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "headers-security-advanced-hsts-wp",
     "status": "active",
     "active": true,
     "installed": "5.0.36",
     "available": "5.3.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.0.36 -> 5.3.5 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "megamenu",
     "status": "active",
     "active": true,
     "installed": "3.3.1",
     "available": "3.10.8",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.3.1 -> 3.10.8 (skipped 7 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "page-links-to",
     "status": "active",
     "active": true,
     "installed": "3.3.7",
     "available": "3.4.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 3.3.7 -> 3.4.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "search-regex",
     "status": "active",
     "active": true,
     "installed": "3.0.8",
     "available": "3.4.4",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.0.8 -> 3.4.4 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wp-revisions-control",
     "status": "active",
     "active": true,
     "installed": "1.4.3",
     "available": "1.4.4",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.4.3 -> 1.4.4"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wp-search-with-algolia",
     "status": "active",
     "active": true,
     "installed": "2.8.1",
     "available": "2.14.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 2.8.1 -> 2.14.1 (skipped 6 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "disable-xml-rpc-api",
     "status": "inactive",
     "active": false,
     "installed": "2.1.5",
     "available": "2.1.7",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 2.1.5 -> 2.1.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    }
   ],
   "p0": 3,
   "p1": 11,
   "total_updates": 37
  },
  "wpengine:asclmlsnacs": {
   "platform": "wpengine",
   "install": "asclmlsnacs",
   "environment": "production",
   "domain": "asclmlsnacs.wpenginepowered.com",
   "siteurl": "https://asclmlsnacs.wpenginepowered.com",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "theme",
   "updates": [
    {
     "plugin": "translatepress-multilingual",
     "status": "active",
     "active": true,
     "installed": "3.0.8",
     "available": "3.3.6",
     "priority": "P0",
     "vulns": [
      {
       "name": "TranslatePress &#8211; Translate Multilingual sites with AI Translation [translatepress-multilingual] < 3.3.3",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2026-78267"
      },
      {
       "name": "TranslatePress &#8211; Translate Multilingual sites with AI Translation [translatepress-multilingual] < 3.3.2",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2026-19632"
      },
      {
       "name": "TranslatePress &#8211; Translate Multilingual sites with AI Translation [translatepress-multilingual] < 3.3",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-18510"
      },
      {
       "name": "TranslatePress &#8211; Translate Multilingual sites with AI Translation [translatepress-multilingual] < 3.2.6",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-75981"
      }
     ],
     "vuln_count": 8,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.0.8 -> 3.3.6 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "gravityforms",
     "status": "active",
     "active": true,
     "installed": "2.10.4",
     "available": "3.1.1",
     "priority": "P1",
     "vulns": [
      {
       "name": "Gravity Forms [gravityforms] < 3.0.3",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2026-19513"
      },
      {
       "name": "Gravity Forms [gravityforms] < 2.10.5",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-12997"
      },
      {
       "name": "Gravity Forms [gravityforms] < 3.0.0",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-16649"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.10.4 -> 3.1.1 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "mainwp-child",
     "status": "active",
     "active": true,
     "installed": "5.4.1",
     "available": "6.2",
     "priority": "P1",
     "vulns": [
      {
       "name": "MainWP Child &#8211; Securely Connects to the MainWP Dashboard to Manage Multiple Sites [mainwp-child] < 6.1.2",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-27366"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 5.4.1 -> 6.2 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "popup-maker",
     "status": "active",
     "active": true,
     "installed": "1.21.5",
     "available": "1.25.0",
     "priority": "P1",
     "vulns": [
      {
       "name": "Popup Maker &#8211; Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.23.0",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-8848"
      },
      {
       "name": "Popup Maker &#8211; Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.24.0",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-28177"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 1.21.5 -> 1.25.0 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "wp-smushit",
     "status": "active",
     "active": true,
     "installed": "3.23.4",
     "available": "4.3.3",
     "priority": "P1",
     "vulns": [
      {
       "name": "Smush \u2013 Image Optimization, Compression, Lazy Load, WebP &amp; CDN [wp-smushit] < 4.3.0",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-81285"
      },
      {
       "name": "Smush \u2013 Image Optimization, Compression, Lazy Load, WebP &amp; CDN [wp-smushit] < 4.3.2",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-19223"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.23.4 -> 4.3.3 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "insert-headers-and-footers",
     "status": "active",
     "active": true,
     "installed": "2.3.3",
     "available": "2.3.9",
     "priority": "P1",
     "vulns": [
      {
       "name": "WPCode &#8211; Insert Headers and Footers + Custom Code Snippets &#8211; WordPress Code Manager [insert-headers-and-footers] < 2.3.6",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-8832"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 2.3.3 -> 2.3.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "acf-to-rest-api",
     "status": "active",
     "active": true,
     "installed": "3.3.4",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "ACF to REST API [acf-to-rest-api] <= 3.3.4 (unfixed + closed)",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-62979"
      },
      {
       "name": "ACF to REST API [acf-to-rest-api] <= 3.3.4 (unfixed + closed)",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-12030"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "smtp2go",
     "status": "active",
     "active": true,
     "installed": "1.14.0",
     "available": "1.17.1",
     "priority": "P2",
     "vulns": [
      {
       "name": "SMTP2GO for WordPress &#8211; Email Made Easy [smtp2go] < 1.17.0",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-7621"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 1.14.0 -> 1.17.1 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "svg-support",
     "status": "active",
     "active": true,
     "installed": "2.5.14",
     "available": "2.6.1",
     "priority": "P2",
     "vulns": [
      {
       "name": "SVG Support [svg-support] < 2.5.15",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-48973"
      },
      {
       "name": "SVG Support [svg-support] < 2.5.17",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-13340"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.5.14 -> 2.6.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "wp-migrate-db",
     "status": "active",
     "active": true,
     "installed": "2.7.0",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "WP Migrate Lite &#8211; Migration Made Easy [wp-migrate-db] < 2.7.7",
       "cvss": "5.8",
       "severity": "MEDIUM",
       "cve": "CVE-2025-11427"
      },
      {
       "name": "WP Migrate Lite &#8211; Migration Made Easy [wp-migrate-db] < 2.7.9",
       "cvss": "4.7",
       "severity": "MEDIUM",
       "cve": "CVE-2026-49043"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "duplicate-post",
     "status": "active",
     "active": true,
     "installed": "4.5",
     "available": "4.7",
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast Duplicate Post [duplicate-post] <= 4.6 (unfixed)",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-53740"
      },
      {
       "name": "Yoast Duplicate Post [duplicate-post] <= 4.6 (unfixed)",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-53739"
      },
      {
       "name": "Yoast Duplicate Post [duplicate-post] < 4.6",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-1217"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 4.5 -> 4.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "change-admin-email-setting-without-outbound-email",
     "status": "active",
     "active": true,
     "installed": "4.1",
     "available": "5.0",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 4.1 -> 5.0 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "advanced-custom-fields-pro",
     "status": "active",
     "active": true,
     "installed": "6.7.0.2",
     "available": "6.8.10",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "minor version bump 6.7.0.2 -> 6.8.10",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE WITH CAPTURE \u2014 routine bump but on a sitewide-impact plugin; watch the diff closely."
    },
    {
     "plugin": "akismet",
     "status": "active",
     "active": true,
     "installed": "5.6",
     "available": "5.7.2",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 5.6 -> 5.7.2"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "duplicate-page",
     "status": "active",
     "active": true,
     "installed": "4.5.6",
     "available": "4.5.9",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 4.5.6 -> 4.5.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "force-regenerate-thumbnails",
     "status": "active",
     "active": true,
     "installed": "2.2.2",
     "available": "2.3.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.2.2 -> 2.3.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "headers-security-advanced-hsts-wp",
     "status": "active",
     "active": true,
     "installed": "5.2.5",
     "available": "5.3.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 5.2.5 -> 5.3.5"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "redirection",
     "status": "active",
     "active": true,
     "installed": "5.6.1",
     "available": "5.10.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.6.1 -> 5.10.0 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "simple-page-ordering",
     "status": "active",
     "active": true,
     "installed": "2.7.4",
     "available": "2.8.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.7.4 -> 2.8.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "stop-user-enumeration",
     "status": "active",
     "active": true,
     "installed": "1.7.7",
     "available": "1.7.8",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.7.7 -> 1.7.8"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wordpress-importer",
     "status": "active",
     "active": true,
     "installed": "0.9.5",
     "available": "0.9.6",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 0.9.5 -> 0.9.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "code-snippets",
     "status": "inactive",
     "active": false,
     "installed": "3.9.5",
     "available": "3.10.2",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 3.9.5 -> 3.10.2"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wp-mail-smtp",
     "status": "inactive",
     "active": false,
     "installed": "4.7.1",
     "available": "4.9.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 4.7.1 -> 4.9.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    }
   ],
   "p0": 1,
   "p1": 5,
   "total_updates": 21
  },
  "wpengine:ascmlskorvis": {
   "platform": "wpengine",
   "install": "ascmlskorvis",
   "environment": "production",
   "domain": "ascmlskorvis.wpenginepowered.com",
   "siteurl": "https://ascmlskorvis.wpenginepowered.com",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "theme",
   "updates": [
    {
     "plugin": "gravityforms",
     "status": "active",
     "active": true,
     "installed": "2.9.26",
     "available": "3.1.1",
     "priority": "P0",
     "vulns": [
      {
       "name": "Gravity Forms [gravityforms] < 2.10.1",
       "cvss": "9.6",
       "severity": "CRITICAL",
       "cve": "CVE-2026-48866"
      },
      {
       "name": "Gravity Forms [gravityforms] < 3.0.3",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2026-19513"
      },
      {
       "name": "Gravity Forms [gravityforms] < 2.10.5",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-12997"
      },
      {
       "name": "Gravity Forms [gravityforms] < 2.10.1",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-5111"
      }
     ],
     "vuln_count": 12,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.9.26 -> 3.1.1 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "translatepress-multilingual",
     "status": "active",
     "active": true,
     "installed": "3.0.8",
     "available": "3.3.6",
     "priority": "P0",
     "vulns": [
      {
       "name": "TranslatePress &#8211; Translate Multilingual sites with AI Translation [translatepress-multilingual] < 3.3.3",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2026-78267"
      },
      {
       "name": "TranslatePress &#8211; Translate Multilingual sites with AI Translation [translatepress-multilingual] < 3.3.2",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2026-19632"
      },
      {
       "name": "TranslatePress &#8211; Translate Multilingual sites with AI Translation [translatepress-multilingual] < 3.3",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-18510"
      },
      {
       "name": "TranslatePress &#8211; Translate Multilingual sites with AI Translation [translatepress-multilingual] < 3.2.6",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-75981"
      }
     ],
     "vuln_count": 8,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.0.8 -> 3.3.6 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "wp-security-audit-log",
     "status": "active",
     "active": true,
     "installed": "5.6.0",
     "available": "5.6.6",
     "priority": "P0",
     "vulns": [
      {
       "name": "WP Activity Log [wp-security-audit-log] < 5.6.4",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2026-54806"
      },
      {
       "name": "WP Activity Log [wp-security-audit-log] < 5.6.4",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-56005"
      },
      {
       "name": "WP Activity Log [wp-security-audit-log] < 5.6.3.1",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-45435"
      },
      {
       "name": "WP Activity Log [wp-security-audit-log] < 5.6.5",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-65512"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 5.6.0 -> 5.6.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "mainwp-child",
     "status": "active",
     "active": true,
     "installed": "5.4.1",
     "available": "6.2",
     "priority": "P1",
     "vulns": [
      {
       "name": "MainWP Child &#8211; Securely Connects to the MainWP Dashboard to Manage Multiple Sites [mainwp-child] < 6.1.2",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-27366"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 5.4.1 -> 6.2 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "popup-maker",
     "status": "active",
     "active": true,
     "installed": "1.21.5",
     "available": "1.25.0",
     "priority": "P1",
     "vulns": [
      {
       "name": "Popup Maker &#8211; Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.23.0",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-8848"
      },
      {
       "name": "Popup Maker &#8211; Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.24.0",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-28177"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 1.21.5 -> 1.25.0 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "wp-smushit",
     "status": "active",
     "active": true,
     "installed": "3.23.4",
     "available": "4.3.3",
     "priority": "P1",
     "vulns": [
      {
       "name": "Smush \u2013 Image Optimization, Compression, Lazy Load, WebP &amp; CDN [wp-smushit] < 4.3.0",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-81285"
      },
      {
       "name": "Smush \u2013 Image Optimization, Compression, Lazy Load, WebP &amp; CDN [wp-smushit] < 4.3.2",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-19223"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.23.4 -> 4.3.3 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "insert-headers-and-footers",
     "status": "active",
     "active": true,
     "installed": "2.3.3",
     "available": "2.3.9",
     "priority": "P1",
     "vulns": [
      {
       "name": "WPCode &#8211; Insert Headers and Footers + Custom Code Snippets &#8211; WordPress Code Manager [insert-headers-and-footers] < 2.3.6",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-8832"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 2.3.3 -> 2.3.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "acf-to-rest-api",
     "status": "active",
     "active": true,
     "installed": "3.3.4",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "ACF to REST API [acf-to-rest-api] <= 3.3.4 (unfixed + closed)",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-62979"
      },
      {
       "name": "ACF to REST API [acf-to-rest-api] <= 3.3.4 (unfixed + closed)",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-12030"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "limit-login-attempts-reloaded",
     "status": "active",
     "active": true,
     "installed": "2.26.28",
     "available": "3.3.8",
     "priority": "P2",
     "vulns": [
      {
       "name": "Limit Login Attempts Security &#8211; Login Security, 2FA, Firewall, Brute Force Prevention [limit-login-attempts-reloaded] < 3.3.5",
       "cvss": "3.7",
       "severity": "LOW",
       "cve": "CVE-2026-18356"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.26.28 -> 3.3.8 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "smtp2go",
     "status": "active",
     "active": true,
     "installed": "1.14.0",
     "available": "1.17.1",
     "priority": "P2",
     "vulns": [
      {
       "name": "SMTP2GO for WordPress &#8211; Email Made Easy [smtp2go] < 1.17.0",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-7621"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 1.14.0 -> 1.17.1 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "svg-support",
     "status": "active",
     "active": true,
     "installed": "2.5.14",
     "available": "2.6.1",
     "priority": "P2",
     "vulns": [
      {
       "name": "SVG Support [svg-support] < 2.5.15",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-48973"
      },
      {
       "name": "SVG Support [svg-support] < 2.5.17",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-13340"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.5.14 -> 2.6.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "duplicate-post",
     "status": "active",
     "active": true,
     "installed": "4.5",
     "available": "4.7",
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast Duplicate Post [duplicate-post] <= 4.6 (unfixed)",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-53740"
      },
      {
       "name": "Yoast Duplicate Post [duplicate-post] <= 4.6 (unfixed)",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-53739"
      },
      {
       "name": "Yoast Duplicate Post [duplicate-post] < 4.6",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-1217"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 4.5 -> 4.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "change-admin-email-setting-without-outbound-email",
     "status": "active",
     "active": true,
     "installed": "4.1",
     "available": "5.0",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 4.1 -> 5.0 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "advanced-custom-fields-pro",
     "status": "active",
     "active": true,
     "installed": "6.7.0.2",
     "available": "6.8.10",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "minor version bump 6.7.0.2 -> 6.8.10",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE WITH CAPTURE \u2014 routine bump but on a sitewide-impact plugin; watch the diff closely."
    },
    {
     "plugin": "code-snippets",
     "status": "active",
     "active": true,
     "installed": "3.9.5",
     "available": "3.10.2",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 3.9.5 -> 3.10.2"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "duplicate-page",
     "status": "active",
     "active": true,
     "installed": "4.5.6",
     "available": "4.5.9",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 4.5.6 -> 4.5.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "force-regenerate-thumbnails",
     "status": "active",
     "active": true,
     "installed": "2.2.2",
     "available": "2.3.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.2.2 -> 2.3.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "headers-security-advanced-hsts-wp",
     "status": "active",
     "active": true,
     "installed": "5.2.5",
     "available": "5.3.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 5.2.5 -> 5.3.5"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "redirection",
     "status": "active",
     "active": true,
     "installed": "5.6.1",
     "available": "5.10.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.6.1 -> 5.10.0 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "simple-page-ordering",
     "status": "active",
     "active": true,
     "installed": "2.7.4",
     "available": "2.8.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.7.4 -> 2.8.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "stop-user-enumeration",
     "status": "active",
     "active": true,
     "installed": "1.7.7",
     "available": "1.7.8",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.7.7 -> 1.7.8"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wordpress-importer",
     "status": "active",
     "active": true,
     "installed": "0.9.5",
     "available": "0.9.6",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 0.9.5 -> 0.9.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    }
   ],
   "p0": 3,
   "p1": 4,
   "total_updates": 21
  },
  "wpengine:hbcarbideprd": {
   "platform": "wpengine",
   "install": "hbcarbideprd",
   "environment": "production",
   "domain": "hbcarbide.com",
   "siteurl": "http://hbcarbide.com",
   "core": "7.1",
   "core_update": null,
   "theme": "logisco-child",
   "updates": [
    {
     "plugin": "revslider",
     "status": "active",
     "active": true,
     "installed": "6.7.58",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "Slider Revolution [revslider] < 7.0.11",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-6692"
      },
      {
       "name": "Slider Revolution [revslider] < 7.1.0",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-57678"
      },
      {
       "name": "Slider Revolution [revslider] < 7.0.11",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-7542"
      },
      {
       "name": "Slider Revolution [revslider] < 7.0.10",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-6728"
      }
     ],
     "vuln_count": 5,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "wp-grid-builder",
     "status": "active",
     "active": true,
     "installed": "1.5.7",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "WP Grid Builder [wp-grid-builder] < 2.3.4",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-13756"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "popup-maker",
     "status": "active",
     "active": true,
     "installed": "1.24.0",
     "available": "1.25.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.24.0 -> 1.25.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wpdatatables",
     "status": "active",
     "active": true,
     "installed": "8.0.1",
     "available": "8.0.2",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 8.0.1 -> 8.0.2"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wordpress-seo",
     "status": "active",
     "active": true,
     "installed": "28.4",
     "available": "28.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "minor version bump 28.4 -> 28.5",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE WITH CAPTURE \u2014 routine bump but on a sitewide-impact plugin; watch the diff closely."
    }
   ],
   "p0": 0,
   "p1": 2,
   "total_updates": 3
  },
  "wpengine:vlawproposal": {
   "platform": "wpengine",
   "install": "vlawproposal",
   "environment": "development",
   "domain": "vlawproposal.wpenginepowered.com",
   "siteurl": "http://vlawproposal.wpenginepowered.com",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "vlaw",
   "updates": [],
   "p0": 0,
   "p1": 0,
   "total_updates": 0
  },
  "wpengine:ttgprd": {
   "platform": "wpengine",
   "install": "ttgprd",
   "environment": "production",
   "domain": "toolingtechgroup.com",
   "siteurl": "https://toolingtechgroup.com",
   "core": "7.1",
   "core_update": null,
   "theme": "infinite-child",
   "updates": [
    {
     "plugin": "woocommerce",
     "status": "active",
     "active": true,
     "installed": "11.1.0",
     "available": null,
     "priority": "P0",
     "vulns": [
      {
       "name": "WooCommerce [woocommerce] == 7.1.0 (unfixed)",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2022-50972"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "wpdatatables",
     "status": "active",
     "active": true,
     "installed": "6.5.1.7",
     "available": null,
     "priority": "P0",
     "vulns": [
      {
       "name": "wpDataTables &#8211; WordPress Data Table, Dynamic Tables &amp; Table Charts Plugin [wpdatatables] < 7.4",
       "cvss": "9.3",
       "severity": "CRITICAL",
       "cve": "CVE-2026-49080"
      },
      {
       "name": "wpDataTables &#8211; WordPress Data Table, Dynamic Tables &amp; Table Charts Plugin [wpdatatables] < 7.4.1",
       "cvss": "9.3",
       "severity": "CRITICAL",
       "cve": "CVE-2026-54825"
      },
      {
       "name": "wpDataTables &#8211; WordPress Data Table, Dynamic Tables &amp; Table Charts Plugin [wpdatatables] < 7.5.2",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-65509"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "revslider",
     "status": "active",
     "active": true,
     "installed": "6.7.58",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "Slider Revolution [revslider] < 7.0.11",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-6692"
      },
      {
       "name": "Slider Revolution [revslider] < 7.1.0",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-57678"
      },
      {
       "name": "Slider Revolution [revslider] < 7.0.11",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-7542"
      },
      {
       "name": "Slider Revolution [revslider] < 7.0.10",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-6728"
      }
     ],
     "vuln_count": 5,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "woocommerce-jetpack",
     "status": "active",
     "active": true,
     "installed": "8.3.0",
     "available": "8.4.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 8.3.0 -> 8.4.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wordpress-seo",
     "status": "active",
     "active": true,
     "installed": "28.4",
     "available": "28.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "minor version bump 28.4 -> 28.5",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE WITH CAPTURE \u2014 routine bump but on a sitewide-impact plugin; watch the diff closely."
    }
   ],
   "p0": 2,
   "p1": 1,
   "total_updates": 2
  },
  "wpengine:asccrpsplitstg": {
   "platform": "wpengine",
   "install": "asccrpsplitstg",
   "environment": "production",
   "domain": "asccrpsplitstg.wpenginepowered.com",
   "siteurl": "https://asccrpsplitstg.wpenginepowered.com",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "hello-ascential",
   "updates": [
    {
     "plugin": "elementor-pro",
     "status": "active",
     "active": true,
     "installed": "3.27.1",
     "available": "3.31.2",
     "priority": "P0",
     "vulns": [
      {
       "name": "Elementor Pro [elementor-pro] < 4.2.2",
       "cvss": "9.0",
       "severity": "CRITICAL",
       "cve": "CVE-2026-32475"
      },
      {
       "name": "Elementor Pro [elementor-pro] < 3.29.1",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-50555"
      },
      {
       "name": "Elementor Pro [elementor-pro] < 3.29.1",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-3076"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "multi-minor jump 3.27.1 -> 3.31.2 (skipped 4 minor releases)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "woocommerce",
     "status": "inactive",
     "active": false,
     "installed": "9.6.0",
     "available": "11.1.0",
     "priority": "P0",
     "vulns": [
      {
       "name": "WooCommerce [woocommerce] == 7.1.0 (unfixed)",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2022-50972"
      },
      {
       "name": "WooCommerce [woocommerce] < 11.0",
       "cvss": "7.6",
       "severity": "HIGH",
       "cve": "CVE-2026-57777"
      },
      {
       "name": "WooCommerce [woocommerce] < 11.1.0",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-48888"
      },
      {
       "name": "WooCommerce [woocommerce] < 10.4.3",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-15033"
      }
     ],
     "vuln_count": 7,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 9.6.0 -> 11.1.0 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "hide-my-wp",
     "status": "inactive",
     "active": false,
     "installed": "5.4.01",
     "available": "7.0.11",
     "priority": "P0",
     "vulns": [
      {
       "name": "Hide My WP Ghost &#8211; Security &amp; Firewall [hide-my-wp] < 5.4.02",
       "cvss": "9.6",
       "severity": "CRITICAL",
       "cve": "CVE-2025-26909"
      },
      {
       "name": "Hide My WP Ghost &#8211; Security &amp; Firewall [hide-my-wp] < 5.4.02",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2025-2056"
      },
      {
       "name": "Hide My WP Ghost &#8211; Security &amp; Firewall [hide-my-wp] < 7.0.10",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-81806"
      },
      {
       "name": "Hide My WP Ghost &#8211; Security &amp; Firewall [hide-my-wp] <= 6.2.12 (unfixed)",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2025-69098"
      }
     ],
     "vuln_count": 7,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 5.4.01 -> 7.0.11 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "jet-menu",
     "status": "active",
     "active": true,
     "installed": "2.4.8",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "JetMenu [jet-menu] < 2.4.9.1",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2025-26953"
      },
      {
       "name": "JetMenu [jet-menu] < 2.4.11.2",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-53987"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "mainwp-child",
     "status": "active",
     "active": true,
     "installed": "5.3.5",
     "available": "6.2",
     "priority": "P1",
     "vulns": [
      {
       "name": "MainWP Child &#8211; Securely Connects to the MainWP Dashboard to Manage Multiple Sites [mainwp-child] < 6.1.2",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-27366"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 5.3.5 -> 6.2 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "shortpixel-image-optimiser",
     "status": "active",
     "active": true,
     "installed": "6.1.1",
     "available": "6.5.6",
     "priority": "P1",
     "vulns": [
      {
       "name": "ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 6.4.4",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-39471"
      },
      {
       "name": "ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 6.3.5",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-11378"
      },
      {
       "name": "ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 6.4.4",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-4335"
      },
      {
       "name": "ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 6.4.3",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-1246"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 6.1.1 -> 6.5.6 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "revslider",
     "status": "active",
     "active": true,
     "installed": "6.7.18",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "Slider Revolution [revslider] < 7.0.11",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-6692"
      },
      {
       "name": "Slider Revolution [revslider] < 7.1.0",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-57678"
      },
      {
       "name": "Slider Revolution [revslider] < 6.7.37",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-9217"
      },
      {
       "name": "Slider Revolution [revslider] < 6.7.38",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-10249"
      }
     ],
     "vuln_count": 9,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "insert-headers-and-footers",
     "status": "active",
     "active": true,
     "installed": "2.2.5",
     "available": "2.3.9",
     "priority": "P1",
     "vulns": [
      {
       "name": "WPCode &#8211; Insert Headers and Footers + Custom Code Snippets &#8211; WordPress Code Manager [insert-headers-and-footers] < 2.3.6",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-8832"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.2.5 -> 2.3.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "debug-log-manager",
     "status": "inactive",
     "active": false,
     "installed": "2.3.3",
     "available": "2.5.2",
     "priority": "P1",
     "vulns": [
      {
       "name": "Debug Log Manager &#8211; Conveniently Monitor and Inspect Errors [debug-log-manager] < 2.3.5",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2025-3809"
      },
      {
       "name": "Debug Log Manager &#8211; Conveniently Monitor and Inspect Errors [debug-log-manager] < 2.5.1",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-9016"
      },
      {
       "name": "Debug Log Manager &#8211; Conveniently Monitor and Inspect Errors [debug-log-manager] < 2.3.5",
       "cvss": "0.0",
       "severity": null,
       "cve": "CVE-2025-32613"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.3.3 -> 2.5.2"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "link-whisper",
     "status": "inactive",
     "active": false,
     "installed": "0.7.9",
     "available": "0.9.7",
     "priority": "P1",
     "vulns": [
      {
       "name": "Link Whisper Free [link-whisper] < 0.9.1",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2025-11262"
      },
      {
       "name": "Link Whisper Free [link-whisper] < 0.8.9",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2025-67927"
      },
      {
       "name": "Link Whisper Free [link-whisper] < 0.9.3",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-22357"
      },
      {
       "name": "Link Whisper Free [link-whisper] < 0.9.5",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-57333"
      }
     ],
     "vuln_count": 8,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 0.7.9 -> 0.9.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "updraftplus",
     "status": "inactive",
     "active": false,
     "installed": "1.25.1",
     "available": "1.26.7",
     "priority": "P1",
     "vulns": [
      {
       "name": "UpdraftPlus: WP Backup &amp; Migration Plugin [updraftplus] < 1.26.5",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2026-10795"
      },
      {
       "name": "UpdraftPlus: WP Backup &amp; Migration Plugin [updraftplus] < 1.26.7",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-76549"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "minor version bump 1.25.1 -> 1.26.7",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wp-optimize",
     "status": "inactive",
     "active": false,
     "installed": "3.8.0",
     "available": "4.6.1",
     "priority": "P1",
     "vulns": [
      {
       "name": "WP-Optimize \u2013 Cache, Compress images, Minify &amp; Clean database to boost page speed &amp; performance [wp-optimize] < 4.5.3",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2026-7252"
      },
      {
       "name": "WP-Optimize \u2013 Cache, Compress images, Minify &amp; Clean database to boost page speed &amp; performance [wp-optimize] < 4.2.0",
       "cvss": "4.1",
       "severity": "MEDIUM",
       "cve": "CVE-2025-3951"
      },
      {
       "name": "WP-Optimize \u2013 Cache, Compress images, Minify &amp; Clean database to boost page speed &amp; performance [wp-optimize] < 4.5.1",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-2712"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.8.0 -> 4.6.1 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wpide",
     "status": "inactive",
     "active": false,
     "installed": "3.5.0",
     "available": "3.5.9",
     "priority": "P1",
     "vulns": [
      {
       "name": "WPIDE &#8211; File Manager &amp; Code Editor [wpide] < 3.5.7",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-57766"
      },
      {
       "name": "WPIDE &#8211; File Manager &amp; Code Editor [wpide] < 3.5.8",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-66440"
      },
      {
       "name": "WPIDE &#8211; File Manager &amp; Code Editor [wpide] < 3.5.2",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2024-13362"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 3.5.0 -> 3.5.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "elementor",
     "status": "active",
     "active": true,
     "installed": "3.27.2",
     "available": "4.2.4",
     "priority": "P2",
     "vulns": [
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.29.1",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-50555"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.35.6",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-32352"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 4.1.4",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-57619"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.27.5",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-13445"
      }
     ],
     "vuln_count": 15,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.27.2 -> 4.2.4 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "limit-login-attempts-reloaded",
     "status": "active",
     "active": true,
     "installed": "2.26.18",
     "available": "3.3.8",
     "priority": "P2",
     "vulns": [
      {
       "name": "Limit Login Attempts Security &#8211; Login Security, 2FA, Firewall, Brute Force Prevention [limit-login-attempts-reloaded] < 3.3.5",
       "cvss": "3.7",
       "severity": "LOW",
       "cve": "CVE-2026-18356"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.26.18 -> 3.3.8 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "search-filter-pro",
     "status": "active",
     "active": true,
     "installed": "2.5.19",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Search & Filter Pro [search-filter-pro] < 2.5.20",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-1528"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "simple-banner",
     "status": "active",
     "active": true,
     "installed": "3.0.6",
     "available": "3.3.2",
     "priority": "P2",
     "vulns": [
      {
       "name": "Simple Banner &#8211; Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website [simple-banner] < 3.1.0",
       "cvss": "4.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-12033"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.0.6 -> 3.3.2 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "simple-download-monitor",
     "status": "active",
     "active": true,
     "installed": "3.9.26",
     "available": "4.1.1",
     "priority": "P2",
     "vulns": [
      {
       "name": "Simple Download Monitor [simple-download-monitor] < 3.9.35",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-58197"
      },
      {
       "name": "Simple Download Monitor [simple-download-monitor] < 3.9.34",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-8977"
      },
      {
       "name": "Simple Download Monitor [simple-download-monitor] < 4.0.6",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-2383"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.9.26 -> 4.1.1 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "smtp2go",
     "status": "active",
     "active": true,
     "installed": "1.11.1",
     "available": "1.17.1",
     "priority": "P2",
     "vulns": [
      {
       "name": "SMTP2GO for WordPress &#8211; Email Made Easy [smtp2go] < 1.12.2",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-54011"
      },
      {
       "name": "SMTP2GO for WordPress &#8211; Email Made Easy [smtp2go] < 1.17.0",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-7621"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 1.11.1 -> 1.17.1 (skipped 6 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "stop-user-enumeration",
     "status": "active",
     "active": true,
     "installed": "1.6.3",
     "available": "1.7.8",
     "priority": "P2",
     "vulns": [
      {
       "name": "Stop User Enumeration [stop-user-enumeration] < 1.7.3",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-4302"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.6.3 -> 1.7.8"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "svg-support",
     "status": "active",
     "active": true,
     "installed": "2.5.8",
     "available": "2.6.1",
     "priority": "P2",
     "vulns": [
      {
       "name": "SVG Support [svg-support] < 2.5.11",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-10222"
      },
      {
       "name": "SVG Support [svg-support] < 2.5.9",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2022-23638"
      },
      {
       "name": "SVG Support [svg-support] < 2.5.15",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-48973"
      },
      {
       "name": "SVG Support [svg-support] < 2.5.17",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-13340"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.5.8 -> 2.6.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "duplicate-post",
     "status": "active",
     "active": true,
     "installed": "4.5",
     "available": "4.7",
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast Duplicate Post [duplicate-post] <= 4.6 (unfixed)",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-53740"
      },
      {
       "name": "Yoast Duplicate Post [duplicate-post] <= 4.6 (unfixed)",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-53739"
      },
      {
       "name": "Yoast Duplicate Post [duplicate-post] < 4.6",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-1217"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 4.5 -> 4.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "wordpress-seo",
     "status": "active",
     "active": true,
     "installed": "24.3",
     "available": "28.5",
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 26.6",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-14481"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 27.2",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-3427"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 26.9",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-1293"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 28.1",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-15425"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 24.3 -> 28.5 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "wordpress-seo-premium",
     "status": "active",
     "active": true,
     "installed": "24.3",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast SEO Premium [wordpress-seo-premium] < 27.6.1",
       "cvss": "6.6",
       "severity": "MEDIUM",
       "cve": "CVE-2026-10821"
      },
      {
       "name": "Yoast SEO Premium [wordpress-seo-premium] < 26.7",
       "cvss": "5.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-40722"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "wp-discussion-board",
     "status": "inactive",
     "active": false,
     "installed": "2.5.5",
     "available": "2.6.0",
     "priority": "P2",
     "vulns": [
      {
       "name": "Discussion Board &#8211; WordPress Forum Plugin [wp-discussion-board] < 2.5.6",
       "cvss": "6.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-8483"
      },
      {
       "name": "Discussion Board &#8211; WordPress Forum Plugin [wp-discussion-board] < 2.5.8",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-69023"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.5.5 -> 2.6.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "dracula-dark-mode",
     "status": "inactive",
     "active": false,
     "installed": "1.2.7",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Dracula Dark Mode \u2013  Accessibility, Reading Mode &amp; Dark Mode for WordPress [dracula-dark-mode] < 1.2.8 (closed)",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2024-13362"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "goal-tracker-ga",
     "status": "inactive",
     "active": false,
     "installed": "1.1.5",
     "available": "1.1.6",
     "priority": "P2",
     "vulns": [
      {
       "name": "Goal Tracker &#8211; Custom Event Tracking for GA4 [goal-tracker-ga] < 1.1.6",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2024-13362"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.1.5 -> 1.1.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "nitropack",
     "status": "inactive",
     "active": false,
     "installed": "1.17.6",
     "available": "1.20.0",
     "priority": "P2",
     "vulns": [
      {
       "name": "NitroPack \u2013 Performance, Page Speed &amp; Cache Plugin for Core Web Vitals, CDN &amp; Image Optimization [nitropack] < 1.19.4",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-39669"
      },
      {
       "name": "NitroPack \u2013 Performance, Page Speed &amp; Cache Plugin for Core Web Vitals, CDN &amp; Image Optimization [nitropack] < 1.18.5",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2025-8778"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 1.17.6 -> 1.20.0 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "query-monitor",
     "status": "inactive",
     "active": false,
     "installed": "3.17.0",
     "available": "4.0.7",
     "priority": "P2",
     "vulns": [
      {
       "name": "Query Monitor [query-monitor] < 3.20.4",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-4267"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.17.0 -> 4.0.7 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "sucuri-scanner",
     "status": "inactive",
     "active": false,
     "installed": "1.9.8",
     "available": "2.8",
     "priority": "P2",
     "vulns": [
      {
       "name": "Sucuri Security &#8211; Auditing, Malware Scanner and Security Hardening [sucuri-scanner] <= 2.7.3 (unfixed)",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-73033"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 1.9.8 -> 2.8 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "agile-store-locator",
     "status": "active",
     "active": true,
     "installed": "4.10.13",
     "available": "5.4.6",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 4.10.13 -> 5.4.6 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "font-awesome",
     "status": "active",
     "active": true,
     "installed": "4.5.0",
     "available": "5.2.1",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 4.5.0 -> 5.2.1 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "wpai-acf-add-on",
     "status": "active",
     "active": true,
     "installed": "3.3.9",
     "available": "4.0.2",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.3.9 -> 4.0.2 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "online-active-users",
     "status": "inactive",
     "active": false,
     "installed": "2.5",
     "available": "3.4.4",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.5 -> 3.4.4 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "prevent-browser-caching",
     "status": "inactive",
     "active": false,
     "installed": "2.3.5",
     "available": "3.2.1",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.3.5 -> 3.2.1 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "eps-301-redirects",
     "status": "active",
     "active": true,
     "installed": "2.77",
     "available": "2.85",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 2.77 -> 2.85 (skipped 8 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "advanced-custom-fields-pro",
     "status": "active",
     "active": true,
     "installed": "6.3.12",
     "available": "6.8.10",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "multi-minor jump 6.3.12 -> 6.8.10 (skipped 5 minor releases)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE WITH CAPTURE \u2014 routine bump but on a sitewide-impact plugin; watch the diff closely."
    },
    {
     "plugin": "cookie-law-info",
     "status": "active",
     "active": true,
     "installed": "3.2.8",
     "available": "3.5.6",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.2.8 -> 3.5.6 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "dynamic-content-for-elementor",
     "status": "active",
     "active": true,
     "installed": "3.2.3",
     "available": "3.4.13",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "minor version bump 3.2.3 -> 3.4.13",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE WITH CAPTURE \u2014 routine bump but on a sitewide-impact plugin; watch the diff closely."
    },
    {
     "plugin": "headers-security-advanced-hsts-wp",
     "status": "active",
     "active": true,
     "installed": "5.0.44",
     "available": "5.3.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 5.0.44 -> 5.3.5 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "megamenu",
     "status": "active",
     "active": true,
     "installed": "3.4.1",
     "available": "3.10.8",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.4.1 -> 3.10.8 (skipped 6 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "page-links-to",
     "status": "active",
     "active": true,
     "installed": "3.3.7",
     "available": "3.4.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 3.3.7 -> 3.4.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "post-types-order",
     "status": "active",
     "active": true,
     "installed": "2.3.3",
     "available": "2.5.3",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.3.3 -> 2.5.3"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "view-transitions",
     "status": "active",
     "active": true,
     "installed": "1.1.1",
     "available": "1.2.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.1.1 -> 1.2.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wp-revisions-control",
     "status": "active",
     "active": true,
     "installed": "1.4.3",
     "available": "1.4.4",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.4.3 -> 1.4.4"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wp-search-with-algolia",
     "status": "active",
     "active": true,
     "installed": "2.8.2",
     "available": "2.14.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 2.8.2 -> 2.14.1 (skipped 6 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wps-hide-login",
     "status": "active",
     "active": true,
     "installed": "1.9.17.1",
     "available": "1.9.19",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.9.17.1 -> 1.9.19"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "admin-taxonomy-filter",
     "status": "inactive",
     "active": false,
     "installed": "1.0.4",
     "available": "1.0.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.0.4 -> 1.0.5"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "cachebuster",
     "status": "inactive",
     "active": false,
     "installed": "1.8",
     "available": "1.10",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.8 -> 1.10"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "duplicate-page",
     "status": "inactive",
     "active": false,
     "installed": "4.5.4",
     "available": "4.5.9",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 4.5.4 -> 4.5.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "search-regex",
     "status": "inactive",
     "active": false,
     "installed": "3.1.2",
     "available": "3.4.4",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.1.2 -> 3.4.4 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wp-hide-security-enhancer",
     "status": "inactive",
     "active": false,
     "installed": "2.6",
     "available": "2.9.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 2.6 -> 2.9.1 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wp-mail-smtp",
     "status": "inactive",
     "active": false,
     "installed": "4.3.0",
     "available": "4.9.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 4.3.0 -> 4.9.0 (skipped 6 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    }
   ],
   "p0": 3,
   "p1": 10,
   "total_updates": 48
  },
  "wpengine:ascentialdev": {
   "platform": "wpengine",
   "install": "ascentialdev",
   "environment": "development",
   "domain": "ascentialdev.wpenginepowered.com",
   "siteurl": "https://ascentialdev.wpenginepowered.com",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "hello-ascential",
   "updates": [
    {
     "plugin": "elementor-pro",
     "status": "active",
     "active": true,
     "installed": "3.27.1",
     "available": "3.27.3",
     "priority": "P0",
     "vulns": [
      {
       "name": "Elementor Pro [elementor-pro] < 4.2.2",
       "cvss": "9.0",
       "severity": "CRITICAL",
       "cve": "CVE-2026-32475"
      },
      {
       "name": "Elementor Pro [elementor-pro] < 3.29.1",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-50555"
      },
      {
       "name": "Elementor Pro [elementor-pro] < 3.29.1",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-3076"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "patch bump 3.27.1 -> 3.27.3",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "woocommerce",
     "status": "inactive",
     "active": false,
     "installed": "9.6.0",
     "available": "11.1.0",
     "priority": "P0",
     "vulns": [
      {
       "name": "WooCommerce [woocommerce] == 7.1.0 (unfixed)",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2022-50972"
      },
      {
       "name": "WooCommerce [woocommerce] < 11.0",
       "cvss": "7.6",
       "severity": "HIGH",
       "cve": "CVE-2026-57777"
      },
      {
       "name": "WooCommerce [woocommerce] < 11.1.0",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-48888"
      },
      {
       "name": "WooCommerce [woocommerce] < 10.4.3",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-15033"
      }
     ],
     "vuln_count": 7,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 9.6.0 -> 11.1.0 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "hide-my-wp",
     "status": "inactive",
     "active": false,
     "installed": "5.4.01",
     "available": "7.0.11",
     "priority": "P0",
     "vulns": [
      {
       "name": "Hide My WP Ghost &#8211; Security &amp; Firewall [hide-my-wp] < 5.4.02",
       "cvss": "9.6",
       "severity": "CRITICAL",
       "cve": "CVE-2025-26909"
      },
      {
       "name": "Hide My WP Ghost &#8211; Security &amp; Firewall [hide-my-wp] < 5.4.02",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2025-2056"
      },
      {
       "name": "Hide My WP Ghost &#8211; Security &amp; Firewall [hide-my-wp] < 7.0.10",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-81806"
      },
      {
       "name": "Hide My WP Ghost &#8211; Security &amp; Firewall [hide-my-wp] <= 6.2.12 (unfixed)",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2025-69098"
      }
     ],
     "vuln_count": 7,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 5.4.01 -> 7.0.11 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "alttext-ai",
     "status": "active",
     "active": true,
     "installed": "1.9.8",
     "available": "1.10.38",
     "priority": "P1",
     "vulns": [
      {
       "name": "Alt Text AI &#8211; Automatically generate image alt text for SEO and accessibility [alttext-ai] < 1.9.94",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2025-46232"
      },
      {
       "name": "Alt Text AI &#8211; Automatically generate image alt text for SEO and accessibility [alttext-ai] < 1.10.18",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-25348"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.9.8 -> 1.10.38"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "jet-menu",
     "status": "active",
     "active": true,
     "installed": "2.4.8",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "JetMenu [jet-menu] < 2.4.9.1",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2025-26953"
      },
      {
       "name": "JetMenu [jet-menu] < 2.4.11.2",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-53987"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "mainwp-child",
     "status": "active",
     "active": true,
     "installed": "5.3.4",
     "available": "6.2",
     "priority": "P1",
     "vulns": [
      {
       "name": "MainWP Child &#8211; Securely Connects to the MainWP Dashboard to Manage Multiple Sites [mainwp-child] < 6.1.2",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-27366"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 5.3.4 -> 6.2 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "shortpixel-image-optimiser",
     "status": "active",
     "active": true,
     "installed": "6.1.1",
     "available": "6.5.6",
     "priority": "P1",
     "vulns": [
      {
       "name": "ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 6.4.4",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-39471"
      },
      {
       "name": "ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 6.3.5",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-11378"
      },
      {
       "name": "ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 6.4.4",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-4335"
      },
      {
       "name": "ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 6.4.3",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-1246"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 6.1.1 -> 6.5.6 (skipped 4 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "revslider",
     "status": "active",
     "active": true,
     "installed": "6.7.18",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "Slider Revolution [revslider] < 7.0.11",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-6692"
      },
      {
       "name": "Slider Revolution [revslider] < 7.1.0",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-57678"
      },
      {
       "name": "Slider Revolution [revslider] < 6.7.37",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-9217"
      },
      {
       "name": "Slider Revolution [revslider] < 6.7.38",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-10249"
      }
     ],
     "vuln_count": 9,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "updraftplus",
     "status": "active",
     "active": true,
     "installed": "1.25.1",
     "available": "1.26.7",
     "priority": "P1",
     "vulns": [
      {
       "name": "UpdraftPlus: WP Backup &amp; Migration Plugin [updraftplus] < 1.26.5",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2026-10795"
      },
      {
       "name": "UpdraftPlus: WP Backup &amp; Migration Plugin [updraftplus] < 1.26.7",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-76549"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "minor version bump 1.25.1 -> 1.26.7",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "insert-headers-and-footers",
     "status": "active",
     "active": true,
     "installed": "2.2.5",
     "available": "2.3.9",
     "priority": "P1",
     "vulns": [
      {
       "name": "WPCode &#8211; Insert Headers and Footers + Custom Code Snippets &#8211; WordPress Code Manager [insert-headers-and-footers] < 2.3.6",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-8832"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.2.5 -> 2.3.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "debug-log-manager",
     "status": "inactive",
     "active": false,
     "installed": "2.3.3",
     "available": "2.5.2",
     "priority": "P1",
     "vulns": [
      {
       "name": "Debug Log Manager &#8211; Conveniently Monitor and Inspect Errors [debug-log-manager] < 2.3.5",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2025-3809"
      },
      {
       "name": "Debug Log Manager &#8211; Conveniently Monitor and Inspect Errors [debug-log-manager] < 2.5.1",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-9016"
      },
      {
       "name": "Debug Log Manager &#8211; Conveniently Monitor and Inspect Errors [debug-log-manager] < 2.3.5",
       "cvss": "0.0",
       "severity": null,
       "cve": "CVE-2025-32613"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.3.3 -> 2.5.2"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "link-whisper",
     "status": "inactive",
     "active": false,
     "installed": "0.7.9",
     "available": "0.9.7",
     "priority": "P1",
     "vulns": [
      {
       "name": "Link Whisper Free [link-whisper] < 0.9.1",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2025-11262"
      },
      {
       "name": "Link Whisper Free [link-whisper] < 0.8.9",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2025-67927"
      },
      {
       "name": "Link Whisper Free [link-whisper] < 0.9.3",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-22357"
      },
      {
       "name": "Link Whisper Free [link-whisper] < 0.9.5",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-57333"
      }
     ],
     "vuln_count": 8,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 0.7.9 -> 0.9.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wp-optimize",
     "status": "inactive",
     "active": false,
     "installed": "3.8.0",
     "available": "4.6.1",
     "priority": "P1",
     "vulns": [
      {
       "name": "WP-Optimize \u2013 Cache, Compress images, Minify &amp; Clean database to boost page speed &amp; performance [wp-optimize] < 4.5.3",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2026-7252"
      },
      {
       "name": "WP-Optimize \u2013 Cache, Compress images, Minify &amp; Clean database to boost page speed &amp; performance [wp-optimize] < 4.2.0",
       "cvss": "4.1",
       "severity": "MEDIUM",
       "cve": "CVE-2025-3951"
      },
      {
       "name": "WP-Optimize \u2013 Cache, Compress images, Minify &amp; Clean database to boost page speed &amp; performance [wp-optimize] < 4.5.1",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-2712"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.8.0 -> 4.6.1 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wpide",
     "status": "inactive",
     "active": false,
     "installed": "3.5.0",
     "available": "3.5.9",
     "priority": "P1",
     "vulns": [
      {
       "name": "WPIDE &#8211; File Manager &amp; Code Editor [wpide] < 3.5.7",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-57766"
      },
      {
       "name": "WPIDE &#8211; File Manager &amp; Code Editor [wpide] < 3.5.8",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-66440"
      },
      {
       "name": "WPIDE &#8211; File Manager &amp; Code Editor [wpide] < 3.5.2",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2024-13362"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 3.5.0 -> 3.5.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "elementor",
     "status": "active",
     "active": true,
     "installed": "3.27.2",
     "available": "4.2.4",
     "priority": "P2",
     "vulns": [
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.29.1",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-50555"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.35.6",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-32352"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 4.1.4",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-57619"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.27.5",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-13445"
      }
     ],
     "vuln_count": 15,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.27.2 -> 4.2.4 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "limit-login-attempts-reloaded",
     "status": "active",
     "active": true,
     "installed": "2.26.16",
     "available": "3.3.8",
     "priority": "P2",
     "vulns": [
      {
       "name": "Limit Login Attempts Security &#8211; Login Security, 2FA, Firewall, Brute Force Prevention [limit-login-attempts-reloaded] < 3.3.5",
       "cvss": "3.7",
       "severity": "LOW",
       "cve": "CVE-2026-18356"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.26.16 -> 3.3.8 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "query-monitor",
     "status": "active",
     "active": true,
     "installed": "3.17.0",
     "available": "4.0.7",
     "priority": "P2",
     "vulns": [
      {
       "name": "Query Monitor [query-monitor] < 3.20.4",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-4267"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.17.0 -> 4.0.7 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "search-filter-pro",
     "status": "active",
     "active": true,
     "installed": "2.5.19",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Search & Filter Pro [search-filter-pro] < 2.5.20",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-1528"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "simple-download-monitor",
     "status": "active",
     "active": true,
     "installed": "3.9.26",
     "available": "4.1.1",
     "priority": "P2",
     "vulns": [
      {
       "name": "Simple Download Monitor [simple-download-monitor] < 3.9.35",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-58197"
      },
      {
       "name": "Simple Download Monitor [simple-download-monitor] < 3.9.34",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-8977"
      },
      {
       "name": "Simple Download Monitor [simple-download-monitor] < 4.0.6",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-2383"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.9.26 -> 4.1.1 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "smtp2go",
     "status": "active",
     "active": true,
     "installed": "1.11.1",
     "available": "1.17.1",
     "priority": "P2",
     "vulns": [
      {
       "name": "SMTP2GO for WordPress &#8211; Email Made Easy [smtp2go] < 1.12.2",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-54011"
      },
      {
       "name": "SMTP2GO for WordPress &#8211; Email Made Easy [smtp2go] < 1.17.0",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-7621"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 1.11.1 -> 1.17.1 (skipped 6 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "svg-support",
     "status": "active",
     "active": true,
     "installed": "2.5.8",
     "available": "2.6.1",
     "priority": "P2",
     "vulns": [
      {
       "name": "SVG Support [svg-support] < 2.5.11",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-10222"
      },
      {
       "name": "SVG Support [svg-support] < 2.5.9",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2022-23638"
      },
      {
       "name": "SVG Support [svg-support] < 2.5.15",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-48973"
      },
      {
       "name": "SVG Support [svg-support] < 2.5.17",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-13340"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.5.8 -> 2.6.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "wordpress-seo",
     "status": "active",
     "active": true,
     "installed": "24.3",
     "available": "28.5",
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 26.6",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-14481"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 27.2",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-3427"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 26.9",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-1293"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 28.1",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-15425"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 24.3 -> 28.5 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "wordpress-seo-premium",
     "status": "active",
     "active": true,
     "installed": "24.3",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast SEO Premium [wordpress-seo-premium] < 27.6.1",
       "cvss": "6.6",
       "severity": "MEDIUM",
       "cve": "CVE-2026-10821"
      },
      {
       "name": "Yoast SEO Premium [wordpress-seo-premium] < 26.7",
       "cvss": "5.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-40722"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "wp-discussion-board",
     "status": "inactive",
     "active": false,
     "installed": "2.5.5",
     "available": "2.6.0",
     "priority": "P2",
     "vulns": [
      {
       "name": "Discussion Board &#8211; WordPress Forum Plugin [wp-discussion-board] < 2.5.6",
       "cvss": "6.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-8483"
      },
      {
       "name": "Discussion Board &#8211; WordPress Forum Plugin [wp-discussion-board] < 2.5.8",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-69023"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.5.5 -> 2.6.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "dracula-dark-mode",
     "status": "inactive",
     "active": false,
     "installed": "1.2.7",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Dracula Dark Mode \u2013  Accessibility, Reading Mode &amp; Dark Mode for WordPress [dracula-dark-mode] < 1.2.8 (closed)",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2024-13362"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "goal-tracker-ga",
     "status": "inactive",
     "active": false,
     "installed": "1.1.5",
     "available": "1.1.6",
     "priority": "P2",
     "vulns": [
      {
       "name": "Goal Tracker &#8211; Custom Event Tracking for GA4 [goal-tracker-ga] < 1.1.6",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2024-13362"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.1.5 -> 1.1.6"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "nitropack",
     "status": "inactive",
     "active": false,
     "installed": "1.17.6",
     "available": "1.20.0",
     "priority": "P2",
     "vulns": [
      {
       "name": "NitroPack \u2013 Performance, Page Speed &amp; Cache Plugin for Core Web Vitals, CDN &amp; Image Optimization [nitropack] < 1.19.4",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-39669"
      },
      {
       "name": "NitroPack \u2013 Performance, Page Speed &amp; Cache Plugin for Core Web Vitals, CDN &amp; Image Optimization [nitropack] < 1.18.5",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2025-8778"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 1.17.6 -> 1.20.0 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "sucuri-scanner",
     "status": "inactive",
     "active": false,
     "installed": "1.9.8",
     "available": "2.8",
     "priority": "P2",
     "vulns": [
      {
       "name": "Sucuri Security &#8211; Auditing, Malware Scanner and Security Hardening [sucuri-scanner] <= 2.7.3 (unfixed)",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-73033"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 1.9.8 -> 2.8 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "agile-store-locator",
     "status": "active",
     "active": true,
     "installed": "4.10.13",
     "available": "5.4.6",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 4.10.13 -> 5.4.6 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "font-awesome",
     "status": "active",
     "active": true,
     "installed": "4.5.0",
     "available": "5.2.1",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 4.5.0 -> 5.2.1 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "wpai-acf-add-on",
     "status": "active",
     "active": true,
     "installed": "3.3.9",
     "available": "4.0.2",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 3.3.9 -> 4.0.2 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "HOLD / STAGE FIRST \u2014 major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod."
    },
    {
     "plugin": "online-active-users",
     "status": "inactive",
     "active": false,
     "installed": "2.5",
     "available": "3.4.4",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.5 -> 3.4.4 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "prevent-browser-caching",
     "status": "inactive",
     "active": false,
     "installed": "2.3.5",
     "available": "3.2.1",
     "priority": "P3",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.3.5 -> 3.2.1 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "eps-301-redirects",
     "status": "active",
     "active": true,
     "installed": "2.77",
     "available": "2.85",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 2.77 -> 2.85 (skipped 8 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "advanced-custom-fields-pro",
     "status": "active",
     "active": true,
     "installed": "6.3.12",
     "available": "6.8.10",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "multi-minor jump 6.3.12 -> 6.8.10 (skipped 5 minor releases)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE WITH CAPTURE \u2014 routine bump but on a sitewide-impact plugin; watch the diff closely."
    },
    {
     "plugin": "cookie-law-info",
     "status": "active",
     "active": true,
     "installed": "3.2.8",
     "available": "3.5.6",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.2.8 -> 3.5.6 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "duplicate-page",
     "status": "active",
     "active": true,
     "installed": "4.5.4",
     "available": "4.5.9",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 4.5.4 -> 4.5.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "dynamic-content-for-elementor",
     "status": "active",
     "active": true,
     "installed": "3.2.3",
     "available": "3.4.13",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "minor version bump 3.2.3 -> 3.4.13",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE WITH CAPTURE \u2014 routine bump but on a sitewide-impact plugin; watch the diff closely."
    },
    {
     "plugin": "megamenu",
     "status": "active",
     "active": true,
     "installed": "3.4.1",
     "available": "3.10.8",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.4.1 -> 3.10.8 (skipped 6 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "page-links-to",
     "status": "active",
     "active": true,
     "installed": "3.3.7",
     "available": "3.4.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 3.3.7 -> 3.4.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "post-types-order",
     "status": "active",
     "active": true,
     "installed": "2.3.3",
     "available": "2.5.3",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.3.3 -> 2.5.3"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wp-revisions-control",
     "status": "active",
     "active": true,
     "installed": "1.4.3",
     "available": "1.4.4",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.4.3 -> 1.4.4"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wp-search-with-algolia",
     "status": "active",
     "active": true,
     "installed": "2.8.2",
     "available": "2.14.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 2.8.2 -> 2.14.1 (skipped 6 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wps-hide-login",
     "status": "active",
     "active": true,
     "installed": "1.9.17.1",
     "available": "1.9.19",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.9.17.1 -> 1.9.19"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "admin-taxonomy-filter",
     "status": "inactive",
     "active": false,
     "installed": "1.0.4",
     "available": "1.0.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.0.4 -> 1.0.5"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "cachebuster",
     "status": "inactive",
     "active": false,
     "installed": "1.8",
     "available": "1.10",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.8 -> 1.10"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "search-regex",
     "status": "inactive",
     "active": false,
     "installed": "3.1.2",
     "available": "3.4.4",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 3.1.2 -> 3.4.4 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wp-hide-security-enhancer",
     "status": "inactive",
     "active": false,
     "installed": "2.6",
     "available": "2.9.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 2.6 -> 2.9.1 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wp-mail-smtp",
     "status": "inactive",
     "active": false,
     "installed": "4.3.0",
     "available": "4.9.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 4.3.0 -> 4.9.0 (skipped 6 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    }
   ],
   "p0": 3,
   "p1": 11,
   "total_updates": 44
  },
  "wpengine:norwestdev1stg": {
   "platform": "wpengine",
   "install": "norwestdev1stg",
   "environment": "staging",
   "domain": "norwestdev1stg.wpenginepowered.com",
   "siteurl": "https://norwestdev1stg.wpenginepowered.com",
   "core": "7.0.4",
   "core_update": null,
   "theme": "brand-nav-child-theme",
   "updates": [
    {
     "plugin": "elementor-pro",
     "status": "active",
     "active": true,
     "installed": "3.23.3",
     "available": null,
     "priority": "P0",
     "vulns": [
      {
       "name": "Elementor Pro [elementor-pro] < 4.2.2",
       "cvss": "9.0",
       "severity": "CRITICAL",
       "cve": "CVE-2026-32475"
      },
      {
       "name": "Elementor Pro [elementor-pro] < 3.25.11",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-8494"
      },
      {
       "name": "Elementor Pro [elementor-pro] < 3.29.1",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-50555"
      },
      {
       "name": "Elementor Pro [elementor-pro] < 3.29.1",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-3076"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "revisionary",
     "status": "active",
     "active": true,
     "installed": "3.6.2",
     "available": null,
     "priority": "P0",
     "vulns": [
      {
       "name": "PublishPress Revisions: Duplicate Posts, Submit, Approve and Schedule Content Changes [revisionary] < 3.7.24",
       "cvss": "9.3",
       "severity": "CRITICAL",
       "cve": "CVE-2026-32539"
      },
      {
       "name": "PublishPress Revisions: Duplicate Posts, Submit, Approve and Schedule Content Changes [revisionary] < 3.7.23",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-25322"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "ewww-image-optimizer",
     "status": "active",
     "active": true,
     "installed": "8.1.3",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "EWWW Image Optimizer [ewww-image-optimizer] < 8.7.7",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2026-84773"
      },
      {
       "name": "EWWW Image Optimizer [ewww-image-optimizer] < 8.7.4",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-15446"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "link-whisper",
     "status": "active",
     "active": true,
     "installed": "0.8.0",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "Link Whisper Free [link-whisper] < 0.9.1",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2025-11262"
      },
      {
       "name": "Link Whisper Free [link-whisper] < 0.8.9",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2025-67927"
      },
      {
       "name": "Link Whisper Free [link-whisper] < 0.9.3",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-22357"
      },
      {
       "name": "Link Whisper Free [link-whisper] < 0.9.5",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-57333"
      }
     ],
     "vuln_count": 8,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "mainwp-child",
     "status": "active",
     "active": true,
     "installed": "5.4.0.4",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "MainWP Child &#8211; Securely Connects to the MainWP Dashboard to Manage Multiple Sites [mainwp-child] < 6.1.2",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-27366"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "one-user-avatar",
     "status": "active",
     "active": true,
     "installed": "2.5.0",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "One User Avatar | User Profile Picture [one-user-avatar] < 2.5.5",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-18983"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "revslider",
     "status": "active",
     "active": true,
     "installed": "6.7.18",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "Slider Revolution [revslider] < 7.0.11",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-6692"
      },
      {
       "name": "Slider Revolution [revslider] < 7.1.0",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-57678"
      },
      {
       "name": "Slider Revolution [revslider] < 6.7.37",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-9217"
      },
      {
       "name": "Slider Revolution [revslider] < 6.7.38",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-10249"
      }
     ],
     "vuln_count": 9,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "wp-optimize",
     "status": "active",
     "active": true,
     "installed": "4.1.1",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "WP-Optimize \u2013 Cache, Compress images, Minify &amp; Clean database to boost page speed &amp; performance [wp-optimize] < 4.5.3",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2026-7252"
      },
      {
       "name": "WP-Optimize \u2013 Cache, Compress images, Minify &amp; Clean database to boost page speed &amp; performance [wp-optimize] < 4.2.0",
       "cvss": "4.1",
       "severity": "MEDIUM",
       "cve": "CVE-2025-3951"
      },
      {
       "name": "WP-Optimize \u2013 Cache, Compress images, Minify &amp; Clean database to boost page speed &amp; performance [wp-optimize] < 4.5.1",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-2712"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "insert-headers-and-footers",
     "status": "active",
     "active": true,
     "installed": "2.2.7",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "WPCode &#8211; Insert Headers and Footers + Custom Code Snippets &#8211; WordPress Code Manager [insert-headers-and-footers] < 2.3.6",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-8832"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "codepress-admin-columns",
     "status": "inactive",
     "active": false,
     "installed": "4.7.7",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "Admin Columns [codepress-admin-columns] < 7.0.19",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-7654"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "perfmatters",
     "status": "inactive",
     "active": false,
     "installed": "2.4.0",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "Perfmatters [perfmatters] < 2.6.5",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2026-13251"
      },
      {
       "name": "Perfmatters [perfmatters] < 2.6.4",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-56047"
      },
      {
       "name": "Perfmatters [perfmatters] < 2.6.5",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-57671"
      },
      {
       "name": "Perfmatters [perfmatters] < 2.6.0",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-4350"
      }
     ],
     "vuln_count": 5,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "updraftplus",
     "status": "inactive",
     "active": false,
     "installed": "1.25.3",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "UpdraftPlus: WP Backup &amp; Migration Plugin [updraftplus] < 1.26.5",
       "cvss": "8.1",
       "severity": "HIGH",
       "cve": "CVE-2026-10795"
      },
      {
       "name": "UpdraftPlus: WP Backup &amp; Migration Plugin [updraftplus] < 1.26.7",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-76549"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "wpvivid-backuprestore",
     "status": "inactive",
     "active": false,
     "installed": "0.9.114",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "WPvivid \u2014 Backup, Migration &amp; Staging [wpvivid-backuprestore] < 0.9.117",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2025-5961"
      },
      {
       "name": "WPvivid \u2014 Backup, Migration &amp; Staging [wpvivid-backuprestore] < 0.9.132",
       "cvss": "4.9",
       "severity": "MEDIUM",
       "cve": "CVE-2026-17555"
      },
      {
       "name": "WPvivid \u2014 Backup, Migration &amp; Staging [wpvivid-backuprestore] < 0.9.129",
       "cvss": "3.8",
       "severity": "LOW",
       "cve": "CVE-2025-12656"
      },
      {
       "name": "WPvivid \u2014 Backup, Migration &amp; Staging [wpvivid-backuprestore] < 0.9.121",
       "cvss": "2.7",
       "severity": "LOW",
       "cve": "CVE-2025-12654"
      }
     ],
     "vuln_count": 10,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "admin-site-enhancements",
     "status": "active",
     "active": true,
     "installed": "7.9.9",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Admin and Site Enhancements (ASE) [admin-site-enhancements] < 8.4.1",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-32423"
      },
      {
       "name": "Admin and Site Enhancements (ASE) [admin-site-enhancements] < 8.1.0",
       "cvss": "2.7",
       "severity": "LOW",
       "cve": "CVE-2025-64255"
      },
      {
       "name": "Admin and Site Enhancements (ASE) [admin-site-enhancements] < 8.8.4",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-12083"
      },
      {
       "name": "Admin and Site Enhancements (ASE) [admin-site-enhancements] < 9.0.1",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-19615"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "am-lottieplayer",
     "status": "active",
     "active": true,
     "installed": "3.5.2",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "AM LottiePlayer [am-lottieplayer] < 3.5.4",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-1529"
      },
      {
       "name": "AM LottiePlayer [am-lottieplayer] <= 3.6.0 (unfixed)",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2025-1794"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "elementor",
     "status": "active",
     "active": true,
     "installed": "3.23.4",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.25.11",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-54444"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.29.1",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-50555"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 3.35.6",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-32352"
      },
      {
       "name": "Elementor Website Builder &#8211; more than just a page builder [elementor] < 4.1.4",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-57619"
      }
     ],
     "vuln_count": 20,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "search-filter-pro",
     "status": "active",
     "active": true,
     "installed": "2.5.14",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Search & Filter Pro [search-filter-pro] < 2.5.18",
       "cvss": "4.8",
       "severity": "MEDIUM",
       "cve": "CVE-2024-6481"
      },
      {
       "name": "Search & Filter Pro [search-filter-pro] < 2.5.20",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-1528"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "search-exclude",
     "status": "active",
     "active": true,
     "installed": "2.4.7",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Search Exclude [search-exclude] < 2.5.0",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-2821"
      },
      {
       "name": "Search Exclude [search-exclude] < 2.5.8",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-10646"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "simple-banner",
     "status": "active",
     "active": true,
     "installed": "3.0.6",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Simple Banner &#8211; Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website [simple-banner] < 3.1.0",
       "cvss": "4.4",
       "severity": "MEDIUM",
       "cve": "CVE-2025-12033"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "sticky-header-effects-for-elementor",
     "status": "active",
     "active": true,
     "installed": "1.7.8",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Sticky Header Effects for Elementor [sticky-header-effects-for-elementor] < 2.1.3",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-58251"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "svg-support",
     "status": "active",
     "active": true,
     "installed": "2.5.14",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "SVG Support [svg-support] < 2.5.15",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-48973"
      },
      {
       "name": "SVG Support [svg-support] < 2.5.17",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-13340"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "duplicate-post",
     "status": "active",
     "active": true,
     "installed": "4.5",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast Duplicate Post [duplicate-post] <= 4.6 (unfixed)",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-53740"
      },
      {
       "name": "Yoast Duplicate Post [duplicate-post] <= 4.6 (unfixed)",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-53739"
      },
      {
       "name": "Yoast Duplicate Post [duplicate-post] < 4.6",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-1217"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "wordpress-seo",
     "status": "active",
     "active": true,
     "installed": "24.8.1",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 26.6",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-14481"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 27.2",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-3427"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 26.9",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-1293"
      },
      {
       "name": "Yoast SEO &#8211; Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 28.1",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-15425"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "wordpress-seo-premium",
     "status": "active",
     "active": true,
     "installed": "24.8",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Yoast SEO Premium [wordpress-seo-premium] < 27.6.1",
       "cvss": "6.6",
       "severity": "MEDIUM",
       "cve": "CVE-2026-10821"
      },
      {
       "name": "Yoast SEO Premium [wordpress-seo-premium] < 26.7",
       "cvss": "5.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-40722"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    }
   ],
   "p0": 2,
   "p1": 11,
   "total_updates": 0
  },
  "wpengine:iscopeprd": {
   "platform": "wpengine",
   "install": "iscopeprd",
   "environment": "production",
   "domain": "industry-scope.com",
   "siteurl": "https://industry-scope.com",
   "core": "7.1",
   "core_update": null,
   "theme": "infinite-child",
   "updates": [
    {
     "plugin": "revslider",
     "status": "active",
     "active": true,
     "installed": "6.7.58",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "Slider Revolution [revslider] < 7.0.11",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-6692"
      },
      {
       "name": "Slider Revolution [revslider] < 7.1.0",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-57678"
      },
      {
       "name": "Slider Revolution [revslider] < 7.0.11",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-7542"
      },
      {
       "name": "Slider Revolution [revslider] < 7.0.10",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-6728"
      }
     ],
     "vuln_count": 5,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "really-simple-ssl",
     "status": "active",
     "active": true,
     "installed": "9.8.1",
     "available": "9.8.3",
     "priority": "P2",
     "vulns": [
      {
       "name": "Really Simple Security &#8211; Simple and Performant Security (formerly Really Simple SSL) [really-simple-ssl] < 9.8.2",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-82519"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "patch bump 9.8.1 -> 9.8.3",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "admin-site-enhancements",
     "status": "active",
     "active": true,
     "installed": "9.1.1",
     "available": "9.1.2",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 9.1.1 -> 9.1.2"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "popup-maker",
     "status": "active",
     "active": true,
     "installed": "1.24.0",
     "available": "1.25.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.24.0 -> 1.25.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "sucuri-scanner",
     "status": "active",
     "active": true,
     "installed": "2.7.4",
     "available": "2.8",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 2.7.4 -> 2.8"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wp-fastest-cache",
     "status": "active",
     "active": true,
     "installed": "1.5.1",
     "available": "1.5.2",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.5.1 -> 1.5.2"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wordpress-seo",
     "status": "active",
     "active": true,
     "installed": "28.4",
     "available": "28.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "minor version bump 28.4 -> 28.5",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE WITH CAPTURE \u2014 routine bump but on a sitewide-impact plugin; watch the diff closely."
    }
   ],
   "p0": 0,
   "p1": 1,
   "total_updates": 6
  },
  "wpengine:reliableexprd": {
   "platform": "wpengine",
   "install": "reliableexprd",
   "environment": "production",
   "domain": "reliableexteriorpro.com",
   "siteurl": "https://reliableexteriorpro.com",
   "core": "7.1",
   "core_update": null,
   "theme": "arki-child",
   "updates": [
    {
     "plugin": "revslider",
     "status": "active",
     "active": true,
     "installed": "6.7.58",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "Slider Revolution [revslider] < 7.0.11",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-6692"
      },
      {
       "name": "Slider Revolution [revslider] < 7.1.0",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-57678"
      },
      {
       "name": "Slider Revolution [revslider] < 7.0.11",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-7542"
      },
      {
       "name": "Slider Revolution [revslider] < 7.0.10",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-6728"
      }
     ],
     "vuln_count": 5,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "wp-seo-structured-data-schema",
     "status": "active",
     "active": true,
     "installed": "2.8.1",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "WP SEO Structured Data Schema [wp-seo-structured-data-schema] <= 2.8.1 (unfixed + closed)",
       "cvss": "4.9",
       "severity": "MEDIUM",
       "cve": "CVE-2026-3604"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "wordpress-seo",
     "status": "active",
     "active": true,
     "installed": "28.4",
     "available": "28.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "minor version bump 28.4 -> 28.5",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE WITH CAPTURE \u2014 routine bump but on a sitewide-impact plugin; watch the diff closely."
    }
   ],
   "p0": 0,
   "p1": 1,
   "total_updates": 1
  },
  "wpengine:nvppantheonarc": {
   "platform": "wpengine",
   "install": "nvppantheonarc",
   "environment": "production",
   "domain": "nvppantheonarc.wpenginepowered.com",
   "siteurl": "http://nvppantheonarc.wpenginepowered.com",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "nvp",
   "updates": [
    {
     "plugin": "advanced-custom-fields-pro",
     "status": "active",
     "active": true,
     "installed": "5.3.8.1",
     "available": "6.8.10",
     "priority": "P0",
     "vulns": [
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.2.10",
       "cvss": "9.9",
       "severity": "CRITICAL",
       "cve": "CVE-2024-34762"
      },
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 5.12.3",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2022-2594"
      },
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 5.12.5",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2023-1196"
      },
      {
       "name": "Advanced Custom Field Pro [advanced-custom-fields-pro] < 6.2.10",
       "cvss": "8.5",
       "severity": "HIGH",
       "cve": "CVE-2024-34761"
      }
     ],
     "vuln_count": 19,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 5.3.8.1 -> 6.8.10 (API/behavior changes expected)",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "contact-form-7",
     "status": "active",
     "active": true,
     "installed": "5.0.2",
     "available": "6.1.7",
     "priority": "P0",
     "vulns": [
      {
       "name": "Contact Form 7 [contact-form-7] < 5.3.2",
       "cvss": "10.0",
       "severity": "CRITICAL",
       "cve": "CVE-2020-35489"
      },
      {
       "name": "Contact Form 7 [contact-form-7] < 5.0.4",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2018-20979"
      },
      {
       "name": "Contact Form 7 [contact-form-7] < 5.8.4",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2023-6449"
      },
      {
       "name": "Contact Form 7 [contact-form-7] < 5.9.2",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2024-2242"
      }
     ],
     "vuln_count": 8,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 5.0.2 -> 6.1.7 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "wp-file-manager",
     "status": "inactive",
     "active": false,
     "installed": "5.4",
     "available": "8.0.4",
     "priority": "P0",
     "vulns": [
      {
       "name": "File Manager [wp-file-manager] < 7.2.2",
       "cvss": "9.9",
       "severity": "CRITICAL",
       "cve": "CVE-2023-6825"
      },
      {
       "name": "File Manager [wp-file-manager] < 6.9",
       "cvss": "9.8",
       "severity": "CRITICAL",
       "cve": "CVE-2020-25213"
      },
      {
       "name": "File Manager [wp-file-manager] < 7.2.5",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2024-1538"
      },
      {
       "name": "File Manager [wp-file-manager] < 6.5",
       "cvss": "7.5",
       "severity": "HIGH",
       "cve": "CVE-2020-24312"
      }
     ],
     "vuln_count": 9,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 5.4 -> 8.0.4 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "wp-editor",
     "status": "active",
     "active": true,
     "installed": "1.2.6.3",
     "available": "1.2.9.3",
     "priority": "P1",
     "vulns": [
      {
       "name": "WP Editor [wp-editor] < 1.2.9.3",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-3772"
      },
      {
       "name": "WP Editor [wp-editor] < 1.2.7",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2021-24151"
      },
      {
       "name": "WP Editor [wp-editor] < 1.2.9.1",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2022-2446"
      },
      {
       "name": "WP Editor [wp-editor] < 1.2.9.2",
       "cvss": "7.2",
       "severity": "HIGH",
       "cve": "CVE-2025-3294"
      }
     ],
     "vuln_count": 8,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.2.6.3 -> 1.2.9.3"
     ],
     "fix_available": true,
     "recommendation": "UPDATE THIS RUN \u2014 known high-severity CVE hits this exact version."
    },
    {
     "plugin": "admin-custom-login",
     "status": "inactive",
     "active": false,
     "installed": "2.6.1",
     "available": "3.6.8",
     "priority": "P1",
     "vulns": [
      {
       "name": "Admin Custom Login [admin-custom-login] < 3.2.8",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2021-34628"
      },
      {
       "name": "Admin Custom Login [admin-custom-login] < 3.6.5",
       "cvss": "4.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-2487"
      }
     ],
     "vuln_count": 2,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.6.1 -> 3.6.8 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    },
    {
     "plugin": "contact-form-7-dynamic-text-extension",
     "status": "active",
     "active": true,
     "installed": "2.0.2.1",
     "available": "5.0.7",
     "priority": "P2",
     "vulns": [
      {
       "name": "DTX &#8211; Dynamic Text Extension for Contact Form 7 [contact-form-7-dynamic-text-extension] <= 5.0.3 (unfixed)",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2025-13146"
      },
      {
       "name": "DTX &#8211; Dynamic Text Extension for Contact Form 7 [contact-form-7-dynamic-text-extension] <= 5.0.5 (unfixed)",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2025-63068"
      },
      {
       "name": "DTX &#8211; Dynamic Text Extension for Contact Form 7 [contact-form-7-dynamic-text-extension] < 5.0.6",
       "cvss": "4.4",
       "severity": "MEDIUM",
       "cve": "CVE-2026-5116"
      },
      {
       "name": "DTX &#8211; Dynamic Text Extension for Contact Form 7 [contact-form-7-dynamic-text-extension] < 4.2.0",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2023-6630"
      }
     ],
     "vuln_count": 11,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 2.0.2.1 -> 5.0.7 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "popups",
     "status": "active",
     "active": true,
     "installed": "1.9.3.1",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Popups &#8211; WordPress Popup [popups] <= 1.9.3.8 (closed)",
       "cvss": "4.8",
       "severity": "MEDIUM",
       "cve": "CVE-2022-2305"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "svg-support",
     "status": "active",
     "active": true,
     "installed": "2.3.15",
     "available": "2.6.1",
     "priority": "P2",
     "vulns": [
      {
       "name": "SVG Support [svg-support] < 2.5.11",
       "cvss": "6.4",
       "severity": "MEDIUM",
       "cve": "CVE-2024-10222"
      },
      {
       "name": "SVG Support [svg-support] < 2.5.9",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2022-23638"
      },
      {
       "name": "SVG Support [svg-support] < 2.5",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2022-1755"
      },
      {
       "name": "SVG Support [svg-support] < 2.5.2",
       "cvss": "5.4",
       "severity": "MEDIUM",
       "cve": "CVE-2022-4022"
      }
     ],
     "vuln_count": 8,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "multi-minor jump 2.3.15 -> 2.6.1 (skipped 3 minor releases)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    }
   ],
   "p0": 3,
   "p1": 2,
   "total_updates": 7
  },
  "wpengine:rocksolidprd": {
   "platform": "wpengine",
   "install": "rocksolidprd",
   "environment": "production",
   "domain": "rocksolidprd.wpenginepowered.com",
   "siteurl": "https://rocksolid-mi.com",
   "core": "7.1",
   "core_update": null,
   "theme": "rock-solid",
   "updates": [
    {
     "plugin": "wordpress-seo",
     "status": "active",
     "active": true,
     "installed": "28.4",
     "available": "28.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "minor version bump 28.4 -> 28.5",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE WITH CAPTURE \u2014 routine bump but on a sitewide-impact plugin; watch the diff closely."
    }
   ],
   "p0": 0,
   "p1": 0,
   "total_updates": 1
  },
  "wpengine:parkpridedev1": {
   "platform": "wpengine",
   "install": "parkpridedev1",
   "environment": "development",
   "domain": "parkpridedev1.wpenginepowered.com",
   "siteurl": "http://parkpridedev1.wpenginepowered.com",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "parkpride",
   "updates": [],
   "p0": 0,
   "p1": 0,
   "total_updates": 0
  },
  "wpengine:burkeadasprd": {
   "platform": "wpengine",
   "install": "burkeadasprd",
   "environment": "production",
   "domain": "www.burkeadas.com",
   "siteurl": "https://www.burkeadas.com",
   "core": "7.0.4",
   "core_update": "7.1",
   "theme": "ascential-tms",
   "updates": [
    {
     "plugin": "admin-site-enhancements",
     "status": "active",
     "active": true,
     "installed": "8.8.6",
     "available": "9.1.2",
     "priority": "P2",
     "vulns": [
      {
       "name": "Admin and Site Enhancements (ASE) [admin-site-enhancements] < 9.0.1",
       "cvss": null,
       "severity": null,
       "cve": "CVE-2026-19615"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "MAJOR version jump 8.8.6 -> 9.1.2 (API/behavior changes expected)"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "amplifi-plugins",
     "status": "active",
     "active": true,
     "installed": "3.1.0",
     "available": "3.3.7",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 3.1.0 -> 3.3.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "mainwp-child",
     "status": "active",
     "active": true,
     "installed": "6.1.2",
     "available": "6.2",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 6.1.2 -> 6.2"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "insert-headers-and-footers",
     "status": "active",
     "active": true,
     "installed": "2.3.6",
     "available": "2.3.9",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 2.3.6 -> 2.3.9"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    }
   ],
   "p0": 0,
   "p1": 0,
   "total_updates": 4
  },
  "wpengine:troy4037prd": {
   "platform": "wpengine",
   "install": "troy4037prd",
   "environment": "production",
   "domain": "troy4037prd.wpenginepowered.com",
   "siteurl": "https://troyvfwpost4037.com",
   "core": "7.1",
   "core_update": null,
   "theme": "infinite-child",
   "updates": [
    {
     "plugin": "goodlayers-core",
     "status": "active",
     "active": true,
     "installed": "1.8.9",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "Good Layers [goodlayers-core] < 2.1.7",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2025-59580"
      },
      {
       "name": "Good Layers [goodlayers-core] < 2.1.3",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-12163"
      },
      {
       "name": "Good Layers [goodlayers-core] < 2.0.8",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2024-11200"
      },
      {
       "name": "Good Layers [goodlayers-core] < 2.0.10",
       "cvss": "5.9",
       "severity": "MEDIUM",
       "cve": "CVE-2024-11357"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "revslider",
     "status": "active",
     "active": true,
     "installed": "6.7.58",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "Slider Revolution [revslider] < 7.0.11",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-6692"
      },
      {
       "name": "Slider Revolution [revslider] < 7.1.0",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-57678"
      },
      {
       "name": "Slider Revolution [revslider] < 7.0.11",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-7542"
      },
      {
       "name": "Slider Revolution [revslider] < 7.0.10",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-6728"
      }
     ],
     "vuln_count": 5,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "wordpress-seo",
     "status": "active",
     "active": true,
     "installed": "28.4",
     "available": "28.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "minor version bump 28.4 -> 28.5",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE WITH CAPTURE \u2014 routine bump but on a sitewide-impact plugin; watch the diff closely."
    }
   ],
   "p0": 0,
   "p1": 2,
   "total_updates": 1
  },
  "wpengine:mlsdevamplifi": {
   "platform": "wpengine",
   "install": "mlsdevamplifi",
   "environment": "development",
   "domain": "mlsdevamplifi.wpenginepowered.com",
   "siteurl": "https://mlsdevamplifi.wpenginepowered.com",
   "core": "7.0.3",
   "core_update": "7.0.4",
   "theme": "twentytwentyfive",
   "updates": [
    {
     "plugin": "akismet",
     "status": "inactive",
     "active": false,
     "installed": "5.7",
     "available": "5.7.2",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 5.7 -> 5.7.2"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    }
   ],
   "p0": 0,
   "p1": 0,
   "total_updates": 1
  },
  "wpengine:vismfgprd": {
   "platform": "wpengine",
   "install": "vismfgprd",
   "environment": "production",
   "domain": "vismfgprd.wpenginepowered.com",
   "siteurl": "https://visionarymfgsolutions.com",
   "core": "7.1",
   "core_update": null,
   "theme": "infinite-child",
   "updates": [
    {
     "plugin": "goodlayers-core",
     "status": "active",
     "active": true,
     "installed": "1.7.6",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "Good Layers [goodlayers-core] < 2.1.7",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2025-59580"
      },
      {
       "name": "Good Layers [goodlayers-core] < 2.1.3",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2024-12163"
      },
      {
       "name": "Good Layers [goodlayers-core] < 2.0.8",
       "cvss": "6.1",
       "severity": "MEDIUM",
       "cve": "CVE-2024-11200"
      },
      {
       "name": "Good Layers [goodlayers-core] < 2.0.10",
       "cvss": "5.9",
       "severity": "MEDIUM",
       "cve": "CVE-2024-11357"
      }
     ],
     "vuln_count": 4,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "admin-post-navigation",
     "status": "active",
     "active": true,
     "installed": "2.1",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Admin Post Navigation [admin-post-navigation] <= 2.1 (unfixed + closed)",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2024-6549"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "wordpress-seo",
     "status": "active",
     "active": true,
     "installed": "28.4",
     "available": "28.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "minor version bump 28.4 -> 28.5",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE WITH CAPTURE \u2014 routine bump but on a sitewide-impact plugin; watch the diff closely."
    }
   ],
   "p0": 0,
   "p1": 1,
   "total_updates": 1
  },
  "wpengine:bilsingprd": {
   "platform": "wpengine",
   "install": "bilsingprd",
   "environment": "production",
   "domain": "bilsing-automation.com",
   "siteurl": "https://bilsing-automation.com",
   "core": "7.1",
   "core_update": null,
   "theme": "logisco-child",
   "updates": [
    {
     "plugin": "revslider",
     "status": "active",
     "active": true,
     "installed": "6.7.58",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "Slider Revolution [revslider] < 7.0.11",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-6692"
      },
      {
       "name": "Slider Revolution [revslider] < 7.1.0",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-57678"
      },
      {
       "name": "Slider Revolution [revslider] < 7.0.11",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-7542"
      },
      {
       "name": "Slider Revolution [revslider] < 7.0.10",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-6728"
      }
     ],
     "vuln_count": 5,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "admin-post-navigation",
     "status": "active",
     "active": true,
     "installed": "2.1",
     "available": null,
     "priority": "P2",
     "vulns": [
      {
       "name": "Admin Post Navigation [admin-post-navigation] <= 2.1 (unfixed + closed)",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2024-6549"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "No update offered for this version \u2014 likely an expired premium licence or a removed plugin. Worth a look."
    },
    {
     "plugin": "all-in-one-seo-pack-pro",
     "status": "active",
     "active": true,
     "installed": "5.0.0.1",
     "available": "5.0.1.1",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 5.0.0.1 -> 5.0.1.1"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "formidable",
     "status": "active",
     "active": true,
     "installed": "6.34",
     "available": "6.35",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 6.34 -> 6.35"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "google-analytics-for-wordpress",
     "status": "active",
     "active": true,
     "installed": "11.2.0",
     "available": "11.3.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 11.2.0 -> 11.3.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "popup-maker",
     "status": "active",
     "active": true,
     "installed": "1.24.0",
     "available": "1.25.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.24.0 -> 1.25.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wp-fastest-cache",
     "status": "inactive",
     "active": false,
     "installed": "1.5.1",
     "available": "1.5.2",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.5.1 -> 1.5.2"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    }
   ],
   "p0": 0,
   "p1": 1,
   "total_updates": 5
  },
  "wpengine:ihmprd": {
   "platform": "wpengine",
   "install": "ihmprd",
   "environment": "production",
   "domain": "ihmprd.wpenginepowered.com",
   "siteurl": "https://ihmprd.wpenginepowered.com",
   "core": "7.1",
   "core_update": null,
   "theme": "ihatemarketing",
   "updates": [
    {
     "plugin": "advanced-custom-fields",
     "status": "active",
     "active": true,
     "installed": "6.8.9",
     "available": "6.8.10",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "patch bump 6.8.9 -> 6.8.10",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE WITH CAPTURE \u2014 routine bump but on a sitewide-impact plugin; watch the diff closely."
    },
    {
     "plugin": "limit-login-attempts-reloaded",
     "status": "active",
     "active": true,
     "installed": "3.3.7",
     "available": "3.3.8",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 3.3.7 -> 3.3.8"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    }
   ],
   "p0": 0,
   "p1": 0,
   "total_updates": 2
  },
  "wpengine:starsuprd": {
   "platform": "wpengine",
   "install": "starsuprd",
   "environment": "production",
   "domain": "www.star-su.com",
   "siteurl": "http://www.star-su.com",
   "core": "7.1",
   "core_update": null,
   "theme": "arki-child",
   "updates": [
    {
     "plugin": "wpdatatables",
     "status": "active",
     "active": true,
     "installed": "6.5.1.7",
     "available": null,
     "priority": "P0",
     "vulns": [
      {
       "name": "wpDataTables &#8211; WordPress Data Table, Dynamic Tables &amp; Table Charts Plugin [wpdatatables] < 7.4",
       "cvss": "9.3",
       "severity": "CRITICAL",
       "cve": "CVE-2026-49080"
      },
      {
       "name": "wpDataTables &#8211; WordPress Data Table, Dynamic Tables &amp; Table Charts Plugin [wpdatatables] < 7.4.1",
       "cvss": "9.3",
       "severity": "CRITICAL",
       "cve": "CVE-2026-54825"
      },
      {
       "name": "wpDataTables &#8211; WordPress Data Table, Dynamic Tables &amp; Table Charts Plugin [wpdatatables] < 7.5.2",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-65509"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "revslider",
     "status": "active",
     "active": true,
     "installed": "6.7.58",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "Slider Revolution [revslider] < 7.0.11",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-6692"
      },
      {
       "name": "Slider Revolution [revslider] < 7.1.0",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-57678"
      },
      {
       "name": "Slider Revolution [revslider] < 7.0.11",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-7542"
      },
      {
       "name": "Slider Revolution [revslider] < 7.0.10",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-6728"
      }
     ],
     "vuln_count": 5,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "all-in-one-wp-migration",
     "status": "active",
     "active": true,
     "installed": "7.110",
     "available": "7.111",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 7.110 -> 7.111"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    }
   ],
   "p0": 1,
   "p1": 1,
   "total_updates": 1
  },
  "wpengine:bilsingwerkprd": {
   "platform": "wpengine",
   "install": "bilsingwerkprd",
   "environment": "production",
   "domain": "bilsing-werkzeugbau.com",
   "siteurl": "https://bilsing-werkzeugbau.com",
   "core": "7.1",
   "core_update": null,
   "theme": "onepagepro-child",
   "updates": [
    {
     "plugin": "revslider",
     "status": "active",
     "active": true,
     "installed": "6.7.58",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "Slider Revolution [revslider] < 7.0.11",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-6692"
      },
      {
       "name": "Slider Revolution [revslider] < 7.1.0",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-57678"
      },
      {
       "name": "Slider Revolution [revslider] < 7.0.11",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-7542"
      },
      {
       "name": "Slider Revolution [revslider] < 7.0.10",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-6728"
      }
     ],
     "vuln_count": 5,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "formidable",
     "status": "active",
     "active": true,
     "installed": "6.34",
     "available": "6.35",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 6.34 -> 6.35"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "popup-maker",
     "status": "active",
     "active": true,
     "installed": "1.24.0",
     "available": "1.25.0",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 1.24.0 -> 1.25.0"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wp-fastest-cache",
     "status": "active",
     "active": true,
     "installed": "1.5.1",
     "available": "1.5.2",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 1.5.1 -> 1.5.2"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "wordpress-seo",
     "status": "active",
     "active": true,
     "installed": "28.4",
     "available": "28.5",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "minor version bump 28.4 -> 28.5",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE WITH CAPTURE \u2014 routine bump but on a sitewide-impact plugin; watch the diff closely."
    }
   ],
   "p0": 0,
   "p1": 1,
   "total_updates": 4
  },
  "wpengine:starcutterprd": {
   "platform": "wpengine",
   "install": "starcutterprd",
   "environment": "production",
   "domain": "starcutter.com",
   "siteurl": "https://starcutter.com",
   "core": "7.1",
   "core_update": null,
   "theme": "arki-child",
   "updates": [
    {
     "plugin": "wpdatatables",
     "status": "active",
     "active": true,
     "installed": "6.5.1.6",
     "available": "6.5.1.7",
     "priority": "P0",
     "vulns": [
      {
       "name": "wpDataTables &#8211; WordPress Data Table, Dynamic Tables &amp; Table Charts Plugin [wpdatatables] < 7.4",
       "cvss": "9.3",
       "severity": "CRITICAL",
       "cve": "CVE-2026-49080"
      },
      {
       "name": "wpDataTables &#8211; WordPress Data Table, Dynamic Tables &amp; Table Charts Plugin [wpdatatables] < 7.4.1",
       "cvss": "9.3",
       "severity": "CRITICAL",
       "cve": "CVE-2026-54825"
      },
      {
       "name": "wpDataTables &#8211; WordPress Data Table, Dynamic Tables &amp; Table Charts Plugin [wpdatatables] < 7.5.2",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-65509"
      }
     ],
     "vuln_count": 3,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 6.5.1.6 -> 6.5.1.7"
     ],
     "fix_available": true,
     "recommendation": "UPDATE NOW \u2014 actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us."
    },
    {
     "plugin": "revslider",
     "status": "active",
     "active": true,
     "installed": "6.7.58",
     "available": null,
     "priority": "P1",
     "vulns": [
      {
       "name": "Slider Revolution [revslider] < 7.0.11",
       "cvss": "8.8",
       "severity": "HIGH",
       "cve": "CVE-2026-6692"
      },
      {
       "name": "Slider Revolution [revslider] < 7.1.0",
       "cvss": "7.1",
       "severity": "HIGH",
       "cve": "CVE-2026-57678"
      },
      {
       "name": "Slider Revolution [revslider] < 7.0.11",
       "cvss": "6.5",
       "severity": "MEDIUM",
       "cve": "CVE-2026-7542"
      },
      {
       "name": "Slider Revolution [revslider] < 7.0.10",
       "cvss": "5.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-6728"
      }
     ],
     "vuln_count": 5,
     "breaking_risk": "N/A",
     "breaking_notes": [
      "no update available \u2014 nothing to upgrade to",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": false,
     "recommendation": "NO FIX AVAILABLE \u2014 vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently."
    },
    {
     "plugin": "really-simple-ssl",
     "status": "active",
     "active": true,
     "installed": "9.8.1",
     "available": "9.8.3",
     "priority": "P2",
     "vulns": [
      {
       "name": "Really Simple Security &#8211; Simple and Performant Security (formerly Really Simple SSL) [really-simple-ssl] < 9.8.2",
       "cvss": "4.3",
       "severity": "MEDIUM",
       "cve": "CVE-2026-82519"
      }
     ],
     "vuln_count": 1,
     "breaking_risk": "HIGH",
     "breaking_notes": [
      "patch bump 9.8.1 -> 9.8.3",
      "HIGH BLAST RADIUS plugin \u2014 touches page rendering / forms / cache sitewide"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 real but lower-severity CVE. Low urgency, still worth clearing."
    },
    {
     "plugin": "all-in-one-wp-migration",
     "status": "active",
     "active": true,
     "installed": "7.110",
     "available": "7.111",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "MEDIUM",
     "breaking_notes": [
      "minor version bump 7.110 -> 7.111"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 routine maintenance bump, low risk."
    },
    {
     "plugin": "admin-site-enhancements",
     "status": "inactive",
     "active": false,
     "installed": "9.1.1",
     "available": "9.1.2",
     "priority": "P4",
     "vulns": [],
     "vuln_count": 0,
     "breaking_risk": "LOW",
     "breaking_notes": [
      "patch bump 9.1.1 -> 9.1.2"
     ],
     "fix_available": true,
     "recommendation": "UPDATE \u2014 plugin is INACTIVE, near-zero front-end risk. Safe to batch."
    }
   ],
   "p0": 1,
   "p1": 1,
   "total_updates": 4
  }
 }
}