Security check
Find outdated JavaScript libraries with known vulnerabilities
Themes, plugins and old templates often ship their own copy of a JavaScript library, and that copy never gets updated. SecurityScan finds the library versions your pages actually load and flags the ones with published vulnerabilities.
How versions are detected
From script URLs
Version numbers in file names and paths, such as jquery-1.12.4.min.js.
From the running page
The loaded page reports its own versions, for example jQuery.fn.jquery. This catches bundled or renamed files that the URL doesn’t reveal.
Against known vulnerabilities
Each version is compared with the first safe release of that library. Older versions are reported with their CVE identifiers.
What a finding means
There is one finding per library, such as “Outdated library: jquery 1.12.4”, with its CVEs. It means code with known vulnerabilities is served to your visitors. Whether it can be exploited depends on how the site uses it, but updating is usually simpler than proving it can’t.
Where old copies come from
Usually from a theme or plugin that bundles its own copy. The file path in the page source tells you which one. Update it, or replace it if it is no longer maintained, then re-scan to confirm.
Questions
- Does it scan server-side code or npm dependencies?
- No. It checks only the libraries your pages load in the browser, the ones visitors and attackers can see.
- Will updating jQuery break my site?
- Major version jumps can. Test on a copy first. The jQuery Migrate plugin helps with old code during the transition.
- Which libraries are covered?
- Common libraries such as jQuery, Bootstrap, AngularJS, Lodash and Moment.js, and others in our list of versions with known vulnerabilities.
Technical checks, not legal advice. SecurityScan does not replace a consultation with a lawyer.