Skip to content

Dashboard

To access the main dashboard in Patchstack App, click on Dashboard from the left-side navigation menu.

Dashboard shows you a general overview of all your WordPress sites:

Vulnerabilities section shows you a general overview about all the vulnerabilities currently present on each of your WordPress sites. Each vulnerability is counted once, however many of your sites it affects, so the numbers here match the Detected Vulnerabilities list further down the page, which shows one row per vulnerability with the number of affected sites on it. The vulnerabilities are divided into three different groups, which indicate the patching priority:

  1. High patch priority software versions are expected to be mass-exploited or have already known to be exploited vulnerabilities. It’s important to patch those by updating the software to patched versions and/or enabling Patchstack firewall, which applies vPatches automatically.

  2. Medium patch priority software versions are not expected to be mass-exploited, but could potentially be exploited in more targeted attacks. It’s important to patch those by updating the software to patched versions and/or enabling Patchstack firewall, which applies vPatches automatically.

  3. Low patch priority software versions are not expected to be exploited, therefore low patch priority vulnerabilities won’t receive a vPatch from Patchstack.

You can use the search bar on the dashboard page, to find current vulnerabilities across any of your specific sites, or you can search your vulnerabilities by description.

There are four main filters for vulnerability searching on the dashboard:

  1. Priority filter - find vulnerabilities by patch priority. You can filter by high, medium and low patch priority vulnerabilities.

  2. Severity filter - find vulnerabilities by CVSS severity score. You can filter by critical, high, medium, low severity.

  3. Exploited - filter out the vulnerabilities that are known to be exploited.

  4. Outdated - show vulnerabilities where a patched release exists, so the installed version is behind the fix. (This filter was previously labelled “Fix available”.)

List of vulnerability icons with descriptions

Section titled “List of vulnerability icons with descriptions”

There are several icons shown on each vulnerability row. Below is a list of what each icon means.

No update available
This software is found vulnerable, but it has no updates yet. It is recommended to turn on Patchstack firewall, or to disable and remove this plugin until update is available.


Outdated (update available)
This software has a patched release available — the installed version is behind the fix. It is recommended to update immediately. In vulnerability lists and filters this state is labelled Outdated.


High patch priority
Red exclamation mark indicates that this software version is expected to be mass-exploited or has already known to be exploited vulnerability. It is recommended to turn on Patchstack firewall as high patch priority vulnerabilities receive a vPatch from Patchstack. Update this software as soon as possible.


Medium patch priority
Yellow exclamation mark indicates that this software version is not expected to become mass-exploited, but could potentially be exploited in more targeted attacks. It is recommended to turn on Patchstack firewall as medium patch priority vulnerabilities receive a vPatch from Patchstack. Update this software as soon as possible.


Low patch priority
Gray exclamation mark indicates that this software version is not expected to become exploited. It is important to update this software when possible, although the security risk is very low. Low patch priority vulnerabilities won’t receive a vPatch from Patchstack.


CVSS score
These numbers represent the CVSS score given to the vulnerability. The higher the CVSS score, the more severe is the vulnerability.
Low (0.0 - 3.9); Medium (4.0 - 6.9); High (7.0 - 8.9); Critical (9.0+)

In the Threats Blocked section you can see a graph, which shows you how many attacks have been blocked by Patchstack across all your sites in total.
On the top right corner, you can choose the time period (7 days, 1 month, 6 months or 1 year).
On the left side, you see the number of attacks.

By moving the cursor on the graph, you can see the number of attacks by day.

The Websites card counts every site on your account once and puts each one in a single status, so the bar and the rows under it always add up to your total number of sites.

  • Protected — protection is on for the site, and every exploitable vulnerability on it has either been updated away or is covered by a vPatch.
  • Vulnerable — the site has an exploitable vulnerability (medium or high patch priority) that no vPatch is holding off yet. Update the affected software to close the gap. Protection can still be active on such a site: the card is telling you there is something protection cannot cover on its own.
  • Unresponsive — Patchstack has not heard from the site recently, so its vulnerability data cannot be trusted. Check that the Patchstack plugin is installed and connected.
  • At risk — nothing exploitable is standing against the site, but protection is not on for it either.

Low patch priority findings do not make a site Vulnerable. They are not expected to be exploited and never receive a vPatch, so they only appear in the Vulnerabilities section.

Because each site lands in exactly one status, these numbers are not the same as the tabs on the Sites page. Those tabs can list one site under several of them at once, so a site that is both unresponsive and vulnerable is counted once here and twice there.

The Vulnerabilities card splits every advisory standing against your sites by patch priority — how likely it is to be exploited. The three add up to the total above them.

  • Highly exploitable — act on these first.
  • Exploitable — worth scheduling.
  • No to low impact — not expected to be exploited, and never given a vPatch.

Under them, No official fix counts the advisories whose author has released no patched version. There is nothing to update to, so an update cannot close them — protection can hold them off in the meantime. They are counted in the three rows above as well, which is why they have no colour of their own on the bar.

The Packages card counts the packages installed across your sites.

  • With vulnerabilities — at least one advisory applies to the installed version.
  • Advised to replace — the package was closed in its repository. It is likely abandoned, or no longer supported.
  • No known issues — nothing is disclosed against the version you have.
  • Outdated — a newer version is available. A package can be outdated and also appear in the rows above, so this number overlaps them.

Only With vulnerabilities and No known issues are drawn on the bar: every package falls on exactly one side of those two, and the other rows cut across them.

In the Reports section, you can see how many reports have been scheduled and how many are available to download.