WooCommerce Security Scan

Dedicated scan for WooCommerce stores. Checks the WooCommerce and e-commerce plugin versions, exposed REST endpoints, the checkout flow and the configurations that put orders and customer data at risk.

What it analyzes

WooCommerce version detection and known vulnerabilities
Analysis of e-commerce plugins and payment gateways
Check for exposed REST API endpoints (wc/v1, wc/v2, wc/v3)
Review of checkout and order-management configuration
Detection of exposed customer data and files
File permission and store hardening checks

How it works

1

Verify target ownership

2

Start automated scan

3

Process results

4

RFC 3161 signed PDF report

What the report includes

Vulnerabilities with severity (Critical/High/Medium/Low)
Technical description and recommended remediation
CVSS score where applicable
RFC 3161 digital signature
Post-fix Targeted Rescan available

Target ownership verification

Method 1 β€” DNS TXT record: add a TXT record to your domain with the provided verification token.

Method 2 β€” HTTP file: upload a verification file to the /.well-known/ directory of your server.

Frequently asked questions

Start the scan

Get Started