Skip to content

Software

Site software page shows an overview of all the software components your site has been built with.

To see an overview of all your site’s software, navigate to Sites > yourdomain.com > Software in Patchstack App.

The following actions are available only for WordPress CMS:

  • Have an overview of software your site is using and see all your software versions
  • See if any of the software is found vulnerable or outdated, how many vulnerabilities each one has, and whether Patchstack is already mitigating them
  • Click the Vulnerabilities cell to read the advisory behind it. Where a package has several, the arrows at the top of the panel move between them
  • Update, activate, deactivate, or delete the existing plugins/themes
  • Update all your software with one click
  • Force resynchronization between Patchstack App and your site if something looks out of sync

To perform any actions with specific plugins or themes on your site, follow the steps below:

Section titled “To perform any actions with specific plugins or themes on your site, follow the steps below:”
  1. Check the checkboxes of your plugins or themes (at the left side of the table row)
  2. Click on the Actions button next to the search bar
  3. You can then pick one of the following actions:
    • Update
    • Activate
    • Deactivate
    • Delete

Software that is grayed out, is currently either deactivated on the website. If the checkbox is missing for that row, it means this software cannot be updated via third party apps like Patchstack. This goes for some of the premium licensed software, which use non-standard updating mechanisms.

You can update components altogether by clicking the Update All button.
Just keep in mind to back up your files and database before doing that.

A list of vulnerabilities reads as a list of things to do, which is wrong when Patchstack is already blocking attacks on them. A summary above the table says which of three states the site is in:

StateWhat it means
No known vulnerabilitiesNothing installed matches a vulnerability Patchstack knows about.
MitigatedEvery vulnerable component is covered by a vPatch, and protection is on for this site. Attacks are blocked; there is nothing you need to do right now.
Not mitigatedAt least one vulnerable component has no virtual patch behind it, or protection is switched off for the site.

Individual rows say the same thing: a component covered by a virtual patch shows Mitigated in place of its patch priority, and its version is no longer shown in red. The priority moves into the tooltip, along with a reminder of what mitigation does and does not do.

Mitigated is not fixed. A virtual patch blocks attempts to exploit the vulnerability. The vulnerable version is still installed, and updating it is still the permanent fix.