Is your WordPress site exposed? Find out in seconds.
Paste a URL. We render your site in a real browser and probe it from the outside — skimmers, exposed config files, forgotten installs, outdated plugins, user enumeration, TLS. No install. 100% read-only.
Report for
This is the 20% visible from the outside.
The backdoor in your theme files, the injected wp-config, the cron firing 10,000×, and the forgotten copies we can't guess by name — those are only visible from the inside. The read-only connector sees it all: 2 minutes, never writes a line.
Create an account & install the connector →A real outside-in audit — not just a ping
Everything below runs from a public URL, the way an attacker and a visitor see your site. No plugin, no login.
Skimmers & Magecart
Runtime-injected scripts that hook checkout fields and exfiltrate card data to an external endpoint — invisible to inside-only scanners.
Redirects & hidden iframes
Off-domain redirects, cloaking (different content to Google vs users), hidden cross-origin iframes and SEO/pharma spam injection.
Exposed config & secrets
Publicly readable wp-config.php.bak, .env, .git, SQL dumps and backup archives that leak your database credentials.
Forgotten installs
Old /old, /dev, /backup copies running an unpatched WordPress — the classic pivot — plus leftover Duplicator installers.
User enumeration
/?author=1 and the REST API leaking real admin usernames — the first half of a targeted brute-force.
Outdated plugins & jQuery
We fingerprint your WordPress version, active plugins and their versions from the public page, and flag jQuery with known XSS CVEs.
TLS & security headers
Expired or soon-to-expire certificates, mixed content, and missing CSP / HSTS / X-Frame-Options headers.
Broken forms
We discover every form and flag the ones that no longer render — the contact form your leads silently fall through.
Blacklist & performance
Safe Browsing / Spamhaus reputation, plus Core Web Vitals (LCP, CLS, INP) that quietly cost you rankings and conversions.
The free scan is the first 20%
An honest line: some things simply can't be seen from the outside. The read-only connector unlocks the rest — and it never writes a thing.
Free scan — from the outside
- Skimmers & injected scripts in the live DOM
- Exposed files we can guess by name (wp-config.bak, .git, .env, dumps)
- Forgotten installs on common paths (/old, /dev, /backup)
- User enumeration & xmlrpc
- Plugin/jQuery versions & known CVEs from the public page
- TLS, headers, forms, Core Web Vitals
Read-only connector — from the inside
- File-integrity: the backdoor injected into your theme files
- The injected wp-config and the real options table
- Every plugin — including the inactive ones
- The cron firing 10,000× and the real error logs
- Forgotten copies on paths we can't guess
- Admin users, and a memory of what changed and when
WordPress security scan — FAQ
Is the WordPress security scan really free?
Do I need to install a plugin to scan my site?
Is the scan safe? Does it change anything on my site?
What can it find without installing anything?
How is this different from Wordfence or Sucuri?
Can it detect WordPress malware?
Scan your site now — it's free
See what an attacker sees, in seconds. Then decide whether you want the full picture.
Run a free scan →