WordPress Security Scan

Dedicated scan for WordPress sites. Identifies vulnerable plugins and themes, misconfigurations, exposed files and vulnerabilities specific to the WordPress ecosystem.

What it analyzes

WordPress version detection and known vulnerabilities
Installed plugin analysis and associated vulnerabilities
Theme verification and known vulnerabilities
User enumeration and password policy verification
Exposed configuration file detection (wp-config.php)
File and directory permission verification

How it works

1

Verify target ownership

2

Start automated scan

3

Process results

4

RFC 3161 signed PDF report

What the report includes

Vulnerabilities with severity (Critical/High/Medium/Low)
Technical description and recommended remediation
CVSS score where applicable
RFC 3161 digital signature
Post-fix Targeted Rescan available

Target ownership verification

Method 1 β€” DNS TXT record: add a TXT record to your domain with the provided verification token.

Method 2 β€” HTTP file: upload a verification file to the /.well-known/ directory of your server.

Frequently asked questions

Start the scan

Get Started