Free WordPress security scan

Is your WordPress site exposed? Find out in seconds.

Paste a URL. We render your site in a real browser and probe it from the outside — skimmers, exposed config files, forgotten installs, outdated plugins, user enumeration, TLS. No install. 100% read-only.

https://
Outside-in diagnosis · nothing installed · results in seconds
100% read-only No plugin required We never touch your site
scanscanning…
0checks
0warnings
0critical
What the scan checks

A real outside-in audit — not just a ping

Everything below runs from a public URL, the way an attacker and a visitor see your site. No plugin, no login.

Malware

Skimmers & Magecart

Runtime-injected scripts that hook checkout fields and exfiltrate card data to an external endpoint — invisible to inside-only scanners.

Malware

Redirects & hidden iframes

Off-domain redirects, cloaking (different content to Google vs users), hidden cross-origin iframes and SEO/pharma spam injection.

Exposure

Exposed config & secrets

Publicly readable wp-config.php.bak, .env, .git, SQL dumps and backup archives that leak your database credentials.

Exposure

Forgotten installs

Old /old, /dev, /backup copies running an unpatched WordPress — the classic pivot — plus leftover Duplicator installers.

Recon

User enumeration

/?author=1 and the REST API leaking real admin usernames — the first half of a targeted brute-force.

Vulnerabilities

Outdated plugins & jQuery

We fingerprint your WordPress version, active plugins and their versions from the public page, and flag jQuery with known XSS CVEs.

Transport

TLS & security headers

Expired or soon-to-expire certificates, mixed content, and missing CSP / HSTS / X-Frame-Options headers.

Reliability

Broken forms

We discover every form and flag the ones that no longer render — the contact form your leads silently fall through.

Reputation

Blacklist & performance

Safe Browsing / Spamhaus reputation, plus Core Web Vitals (LCP, CLS, INP) that quietly cost you rankings and conversions.

Outside-in vs the connector

The free scan is the first 20%

An honest line: some things simply can't be seen from the outside. The read-only connector unlocks the rest — and it never writes a thing.

Free scan — from the outside

  • Skimmers & injected scripts in the live DOM
  • Exposed files we can guess by name (wp-config.bak, .git, .env, dumps)
  • Forgotten installs on common paths (/old, /dev, /backup)
  • User enumeration & xmlrpc
  • Plugin/jQuery versions & known CVEs from the public page
  • TLS, headers, forms, Core Web Vitals

Read-only connector — from the inside

  • File-integrity: the backdoor injected into your theme files
  • The injected wp-config and the real options table
  • Every plugin — including the inactive ones
  • The cron firing 10,000× and the real error logs
  • Forgotten copies on paths we can't guess
  • Admin users, and a memory of what changed and when
Questions

WordPress security scan — FAQ

Is the WordPress security scan really free?
Yes. Paste a URL and get a full outside-in report at no cost. You leave a name and email to unlock the detailed findings — no card, no install.
Do I need to install a plugin to scan my site?
No. The scan runs entirely from the outside on any public URL. Nothing is installed. The optional read-only connector unlocks the ~80% that can only be seen from inside.
Is the scan safe? Does it change anything on my site?
It is 100% read-only. It requests public pages and paths the way any visitor or search engine would, and never writes, modifies or deletes anything.
What can it find without installing anything?
Injected skimmers, off-domain redirects and cloaking, hidden iframes, SEO spam, exposed wp-config backups, .git and .env, SQL dumps, forgotten dev/old/backup installs, leftover Duplicator installers, user enumeration, outdated plugins and jQuery with known CVEs, an expired or weak TLS certificate, missing security headers, broken forms and Core Web Vitals.
How is this different from Wordfence or Sucuri?
Those run inside WordPress. Site Doctor's free scan is outside-in — it sees exactly what an attacker and a visitor see, with no plugin required, so it catches runtime skimmers and public exposures an inside-only scanner can miss.
Can it detect WordPress malware?
It detects the malware that is visible from the outside — injected skimmers, malicious redirects, hidden iframes, crypto-miners and SEO/pharma spam — and flags the exposed files and forgotten installs that are the usual entry points. Deep file-integrity checks need the read-only connector.

Scan your site now — it's free

See what an attacker sees, in seconds. Then decide whether you want the full picture.

Run a free scan →