IP Location.net Tools site
wpscan

WordPress Security Scanner

Run a bounded public WordPress exposure check for visible core clues, plugins, themes, users, endpoints, and security headers.

WordPress Security Scanner performs a bounded, non-invasive review of public WordPress signals. Enter a public website URL to check visible WordPress indicators, exposed standard endpoints, public author usernames, visible plugin and theme paths, version clues, and common browser security headers.

The scan is designed for website owners, administrators, developers, and security reviewers who need a quick first-pass view of public exposure. It does not brute-force plugins or themes, exploit vulnerabilities, test passwords, or replace authenticated security tools.

WordPress Security Scanner

Enter a public WordPress site URL to review visible WordPress signals, exposed endpoints, themes, plugins, users, and security headers.

Run a bounded public WordPress exposure scan without brute force or exploitation.

Recommended Next Checks

Continue the same task with related tools. When possible, your current input is carried to the next page.

What This WordPress Scan Checks

The scanner fetches the public homepage and selected standard WordPress paths, then reports what can be seen without authentication. It looks for WordPress indicators in HTML and headers, visible core version clues, plugin and theme asset paths, public REST API users, XML-RPC reachability, readme and license files, installer exposure, upload directory listing, and common browser security headers.

How This Differs From the Legacy CI3 Scanner

The legacy CI3 implementation executed an external Python scanner and rendered buckets for general WordPress details, installed plugins, installed themes, and active users. The Laravel implementation keeps those useful sections but avoids brute-force plugin and theme dictionaries on a public tools site. It reports confirmed public evidence only, making the result safer, faster, and easier to explain.

How to Interpret Results

Visible plugins and themes are inferred from public asset paths. A plugin or theme may be active even if it is not visible in the homepage HTML, and a visible asset does not always prove the component is currently vulnerable. Public users may come from the REST API or author archive links. Exposed endpoints such as XML-RPC or REST users are not always vulnerabilities by themselves, but they are useful review signals when hardening a WordPress site.

Recommended WordPress Hardening

Keep WordPress core, plugins, and themes updated. Remove unused plugins and inactive themes. Use unique administrator usernames, strong passwords, and multi-factor authentication. Restrict XML-RPC when it is not needed. Prevent directory listing. Use HTTPS and appropriate security headers. Maintain backups, monitor logs, and use authenticated security tooling for vulnerability matching and malware detection.

WordPress Security Scanner Tips

Use this report as a public-facing exposure review. A clean result does not prove the WordPress site is secure, because many important checks require authenticated access, server logs, plugin inventory, vulnerability database matching, file integrity checks, and hosting-level review. For production sites, combine this public scan with regular updates, backups, MFA, least-privilege accounts, a web application firewall, malware monitoring, and authenticated WordPress security tooling.

Suggest an improvement

Tell us if something is confusing, broken, incorrect, or missing. Feedback helps us improve the tools and workflows people use every day.