WordPress security audit.

Review publicly visible WordPress information, software-version clues and potential exposures.

Enter your WordPress website address to see what it reveals publicly and where it could be tightened.

Why it matters

The most-attacked platform there is

WordPress runs a huge share of the web, so attackers scan for it constantly. Most break-ins come through out-of-date plugins and exposed sign-in pages.

What an outsider can see

Author names, the sign-in page, the version number and the plugin list are often visible to anyone who looks. Each one makes an attacker’s job easier.

Maintenance is the protection

Keeping WordPress, its plugins and its theme up to date, and tightening what is public, removes almost all of the risk. This report shows where to start.

Common questions

Before you run it, or after you have.

What does the audit check?

The quick check reads your homepage for the signs of WordPress, the version it advertises, and the plugins and themes visible in the page code, plus the same connection and browser settings as our website security scan. The deeper checks, once you have confirmed you manage the domain, also look at the sign-in page, author details, the remote-publishing connection, the readme file and whether uploads can be browsed as a list.

Why do I have to confirm I manage the domain?

The deeper checks look at parts of a site that should only be tested with the owner’s say-so. You can confirm with an email address on the domain, which takes a minute, or by adding one short record to your domain settings.

Is this safe, and is it legal?

Yes. We only look at pages your site already serves to any visitor. We do not sign in, try passwords or change anything. Please only check websites you own or look after.

My email is not on the same domain as my website. What then?

Use the other route on the report: whoever manages your domain adds one short record to its settings, then you press the button.

Why is WordPress attacked so much?

Because there is so much of it, and because plugins and themes are written by thousands of different people. An out-of-date plugin on one site is usually out of date on many, so attackers scan for it everywhere at once.