Skip to main content
Metrics type: Key MetricsCategory: Ecommerce Platform
Current WP version vs latest. WordPress core upgrades patch security CVEs almost monthly, running 2+ versions behind = active exposure. Top-3 store-breaker (WC02).

At a glance

Current WordPress core version compared against the latest release. WP core ships security CVEs almost monthly; running 2+ versions behind is active exposure.

Calculation

Calculated automatically from your WooCommerce data. See the At a glance summary above for what the metric tracks and the worked example below for a typical reading.

Worked example

A self-hosted UK fashion brand. Polled 12 Apr 26. Three observations:
  1. Self-hosted variance is the recurring theme. This brand applies WP core updates monthly during a maintenance window. Two minor versions behind is typical for self-hosted Woo. Managed-Woo (Pressable, WP Engine) auto-applies minor releases within 24-72 hours.
  2. WordPress core CVEs are common. The 6.4.x branch has shipped 4 security releases since 6.5.0 dropped. The merchant is exposed to all 4 unless they have a WAF (Wordfence, Sucuri) blocking the relevant attack patterns. Patching to 6.6.x closes them.
  3. Plugin-induced data shape variance: WP version reporting is reliable. Unlike commercial plugins, WP core version reports identically via REST API and via filesystem inspection. False positives on this card are rare.

Sibling cards merchants should reference together

Reconciling against the vendor’s own dashboard

Where to look in WordPress Admin: WP Admin → Dashboard → Updates. The “WordPress” section at the top shows the installed version and any available core update. Why our number may differ from WP Admin: Cross-connector reconciliation:

Known limitations / merchant FAQs

Self-hosted vs managed-Woo, why does it matter? Self-hosted owns updates. Managed-Woo applies minor releases automatically. WordPress.com is fully managed. Status-filter selection, why >2 minor releases threshold? A 1-minor lag is normal (some merchants wait 2-4 weeks for stability). 2+ minors lagging means CVE exposure is accumulating; that is the right action threshold. Refund-object accounting? Not applicable. Plugin-induced data shape variance? Some “version masking” security plugins hide WP version from public-facing pages. They do NOT mask the REST API metadata, so this card detects accurately. Multi-currency, does it affect this card? No. Why does Woo and Stripe disagree? Stripe does not track WP version. Today is jumpy, why? Stable; flips on / off with version changes. Sync-lag from self-hosted server slowness? Hourly poll. Brief outages delay detection by 1-2 hours. My WP Admin shows the latest version, why is the alert firing?
  1. Force a “Check again” in Dashboard → Updates.
  2. Verify the version reported in wp-load.php constant $wp_version.
  3. If genuinely up-to-date, contact support; the WordPress.org API may have stale data.

Tracked live in Vortex IQ Nerve Centre

WordPress Core Version is one of hundreds of KPI pulses Vortex IQ tracks across WooCommerce and 70+ other ecommerce connectors. Nerve Centre runs the detection layer; Vortex Mind investigates the cause when something moves; Ask Viq lets you interrogate any number in plain English. Start for free or book a demo to see this metric running on your own data.