White Rabbit Group CMS Watch

Loading the latest scan…

We monitor security advisories and platform deadlines so you know what changed, what matters, and when to act. For WordPress, Drupal, Shopify, Webflow, HubSpot, Craft CMS, and Strapi.

Platform pulse

Where the risk is right now.

Select a platform to filter the feed. A quiet platform means our sources found nothing to report. It doesn’t mean the platform is safe.

Live feed · last 14 days

What vendors announced.

    Upcoming deadlines · next 90 days

    Know what changes and when.

    Dates come from vendors’ own notices and support schedules. Some are collected automatically and appear only when the vendor’s own wording confirms the date. Our team confirms the rest before they appear here. Countdown timers update automatically every day.

      Why this matters

      An advisory is where the clock starts ticking.

      Exposure

      Once a fix is public, attackers can study it too.

      Automated scanning for unpatched sites can begin within hours. A site that waits until next month’s maintenance window remains exposed in the meantime.

      Breakage

      Sunsets break things quietly.

      Deprecated APIs, retired PHP versions, and end-of-life major versions rarely fail on day one. Forms, integrations, and tracking can stop working later, often without anyone noticing until leads go missing.

      Delivery

      Updates need a safe path to production.

      Applying a patch is the easy part. The real work is testing it against your plugins, modules, and custom code, then shipping it without downtime. That’s what keeps a site secure and stable.

      Care plans

      This page tells you what vendors announced.

      Our care plans take it further and match those advisories to the exact versions running on your sites.

      Watch

      Security monitoring

      • Advisories matched to the exact versions in your stack.
      • Same-day alert when something affects you.
      • Monthly risk summary for stakeholders.
      Talk to us

      Maintain

      Most requested

      Proactive maintenance

      • Everything in Watch.
      • Critical patches applied within an agreed-upon SLA.
      • Core, plugin, and module updates tested in staging first.
      • Uptime, backup, and restore checks.
      Talk to us

      Advanced

      Upgrades and roadmap

      • Everything in Maintain.
      • Major version upgrades and deprecation cleanup.
      • Structured Dev → QA → UAT → Production release process.
      • Dedicated engineering hours.
      Talk to us

      Free health check

      We’ll check whether any of the latest security advisories affect your site.

      Tell us what you run. One of our team members will compare your site’s versions against current advisories and send you a short, plain-language report with recommended next steps.

      1. 01It covers all seven platforms on this page.
      2. 02We don’t need any logins for the first review.
      3. 03We reply within one business day.
      Platforms you run

      How we track

      Straight from the people who ship the software.

      We check every source daily at 11:30 p.m. UTC and retry any that fail. If we still can’t reach a source, we mark it as unavailable instead of quietly dropping it.

      About these updates

      Please read before acting on anything above.

      We quote headlines and summaries directly from each vendor. Each item links to the original notice. Severity labels appear only where the vendor gives one.

      We report what vendors published. We do not verify it independently. Dates and links come from the vendor. We do not test the vulnerabilities ourselves.

      This is not a complete list. Vendor indexes go out of date, and feeds sometimes drop older items. If something isn’t listed here, that doesn’t mean nothing was announced.

      Nothing here tells you whether a particular site is affected. To know that, someone has to check the versions installed on that site.