The most-attacked platform there is
WordPress runs a huge share of the web, so attackers scan for it constantly. Most break-ins come through out-of-date plugins and exposed sign-in pages.
Review publicly visible WordPress information, software-version clues and potential exposures.
Why it matters
WordPress runs a huge share of the web, so attackers scan for it constantly. Most break-ins come through out-of-date plugins and exposed sign-in pages.
Author names, the sign-in page, the version number and the plugin list are often visible to anyone who looks. Each one makes an attacker’s job easier.
Keeping WordPress, its plugins and its theme up to date, and tightening what is public, removes almost all of the risk. This report shows where to start.
Common questions
The quick check reads your homepage for the signs of WordPress, the version it advertises, and the plugins and themes visible in the page code, plus the same connection and browser settings as our website security scan. The deeper checks, once you have confirmed you manage the domain, also look at the sign-in page, author details, the remote-publishing connection, the readme file and whether uploads can be browsed as a list.
The deeper checks look at parts of a site that should only be tested with the owner’s say-so. You can confirm with an email address on the domain, which takes a minute, or by adding one short record to your domain settings.
Yes. We only look at pages your site already serves to any visitor. We do not sign in, try passwords or change anything. Please only check websites you own or look after.
Use the other route on the report: whoever manages your domain adds one short record to its settings, then you press the button.
Because there is so much of it, and because plugins and themes are written by thousands of different people. An out-of-date plugin on one site is usually out of date on many, so attackers scan for it everywhere at once.