Is your WordPress site exposed?
Enter your URL for a passive WordPress security check: outdated core and plugins, exposed endpoints and files, user enumeration, XML-RPC and missing security headers. Read-only, no login, results in seconds.
What we check
Core & version
Confirms WordPress and reads the core version if it is publicly exposed, then matches it against known advisories.
Plugins & themes
Fingerprints plugins and themes from their public asset paths and flags versions with known vulnerabilities.
Exposed endpoints
The REST users route (user enumeration) and XML-RPC, both common brute-force and abuse routes, checked for reachability only.
Exposed files
readme.html, debug.log, wp-config backups and other conventional leak paths, checked for existence, never read.
Security headers
CSP, HSTS, clickjacking and MIME-sniffing protection, plus HTTPS and mixed content.
Outdated libraries
Front-end libraries (jQuery and friends) with public CVEs, matched against a local dataset.
Want it hardened, not just scored?
A score tells you where you stand. Our team fixes it: updates, hardening and a rebuild on a modern stack when that is the right call.
Hire a WordPress developerTalk to us