WordPress Security Scanner
Run a bounded public WordPress exposure check for visible core clues, plugins, themes, users, endpoints, and security headers.
WordPress Security Scanner performs a bounded, non-invasive review of public WordPress signals. Enter a public website URL to check visible WordPress indicators, exposed standard endpoints, public author usernames, visible plugin and theme paths, version clues, and common browser security headers.
The scan is designed for website owners, administrators, developers, and security reviewers who need a quick first-pass view of public exposure. It does not brute-force plugins or themes, exploit vulnerabilities, test passwords, or replace authenticated security tools.
WordPress Security Scanner
Enter a public WordPress site URL to review visible WordPress signals, exposed endpoints, themes, plugins, users, and security headers.
Recommended Next Checks
Continue the same task with related tools. When possible, your current input is carried to the next page.
Scam Trust Score Checker
Review visible scam, phishing, trust, domain age, TLS, DNS, page, and reputation signals f...
Basic Auth Generator
Create HTTP Basic Authentication headers by encoding your username and password into a Bas...
Data Breach Check
Review email format, mail-domain security records, and trusted options for live breach exp...
Password Strength Test
Estimate password strength and review practical ways to make passwords longer, stronger, a...
What This WordPress Scan Checks
The scanner fetches the public homepage and selected standard WordPress paths, then reports what can be seen without authentication. It looks for WordPress indicators in HTML and headers, visible core version clues, plugin and theme asset paths, public REST API users, XML-RPC reachability, readme and license files, installer exposure, upload directory listing, and common browser security headers.
How This Differs From the Legacy CI3 Scanner
The legacy CI3 implementation executed an external Python scanner and rendered buckets for general WordPress details, installed plugins, installed themes, and active users. The Laravel implementation keeps those useful sections but avoids brute-force plugin and theme dictionaries on a public tools site. It reports confirmed public evidence only, making the result safer, faster, and easier to explain.
How to Interpret Results
Visible plugins and themes are inferred from public asset paths. A plugin or theme may be active even if it is not visible in the homepage HTML, and a visible asset does not always prove the component is currently vulnerable. Public users may come from the REST API or author archive links. Exposed endpoints such as XML-RPC or REST users are not always vulnerabilities by themselves, but they are useful review signals when hardening a WordPress site.
Recommended WordPress Hardening
Keep WordPress core, plugins, and themes updated. Remove unused plugins and inactive themes. Use unique administrator usernames, strong passwords, and multi-factor authentication. Restrict XML-RPC when it is not needed. Prevent directory listing. Use HTTPS and appropriate security headers. Maintain backups, monitor logs, and use authenticated security tooling for vulnerability matching and malware detection.
WordPress Security Scanner Tips
Use this report as a public-facing exposure review. A clean result does not prove the WordPress site is secure, because many important checks require authenticated access, server logs, plugin inventory, vulnerability database matching, file integrity checks, and hosting-level review. For production sites, combine this public scan with regular updates, backups, MFA, least-privilege accounts, a web application firewall, malware monitoring, and authenticated WordPress security tooling.
Related Tools
Scam Trust Score Checker
Review visible scam, phishing, trust, domain age, TLS, DNS, page, and reputation signals for a public website.
Basic Auth Generator
Create HTTP Basic Authentication headers by encoding your username and password into a Base64-encoded string.
Data Breach Check
Review email format, mail-domain security records, and trusted options for live breach exposure checks.
Password Strength Test
Estimate password strength and review practical ways to make passwords longer, stronger, and unique.
RSA Key Generator
Generate RSA public and private key pairs securely.
OTP Generator
Generate secure One-Time Passwords (OTPs) for two-factor authentication.
Suggest an improvement
Tell us if something is confusing, broken, incorrect, or missing. Feedback helps us improve the tools and workflows people use every day.