My WP host and Malcare flagged this as a vulnerable plugin
I found the plugin didn't do much anyway. Missed attacks with no alerts. I found out site was hacked over and over the hard way (site down, cloaked pages). I'd skip this one. And, it just may be part of the problem.
Lars_Koudal
Aug 25, 2026Hi, sorry this was a frustrating experience.
Host scanners and MalCare often flag Security Ninja because our vulnerability database includes public CVE text, so phrases like wp-config.php show up in those files. That is a false positive, not malware in the plugin. From version 5.294 we store that database compressed so those scanners stop tripping on it. If you are on an older build, please update to the latest.
I am also sorry the site went down and that you did not get the alerts you expected. No plugin can catch every compromise, especially once a site is already being cloaked or taken offline.
Stay safe and take care.