Passive WordPress security check
WordPress Exposure Scanner
Check what a public visitor can learn about a WordPress installation, including version signals, observable plugins and themes, REST users, XML-RPC, debug files and known vulnerabilities when a reliable version is available.
What this tool checks
Observable plugins and themes
Known vulnerable versions
REST API and user exposure
XML-RPC and public files
HTTPS and security headers
Understand what your WordPress site exposes
Normal WordPress functionality is not automatically a vulnerability. This report explains the context of each exposed endpoint or version signal and distinguishes confirmed version matches from uncertain observations.
Passive by design
The scanner does not attempt login, execute exploits, enumerate large path lists or modify the site. Hidden plugins and server-side weaknesses may require an authorized audit with administrative and hosting access.
FAQ
WordPress scanner questions
Does an available XML-RPC endpoint mean the site is vulnerable?
Not by itself. It can increase attack surface when unused, so the report presents it with context rather than treating it as a critical flaw.
Why was a plugin not detected?
Passive detection only sees plugins that leave public asset or endpoint signals. A hidden or inactive plugin may not be observable.
How are known vulnerabilities matched?
Detected or manually supplied versions are compared with a locally stored vulnerability catalogue using version ranges and source provenance.
Is this a complete WordPress security audit?
No. A complete audit also needs authorized access to code, configuration, users, hosting and operational logs.
New practical tools, occasionally
Hear about new free NovaraCode tools and substantial updates. No frequent marketing emails.
Need help fixing these issues?
NovaraCode builds, secures and maintains production web applications with direct senior developer communication.
NovaraCode performs non-invasive checks using information publicly available from the submitted website and its DNS configuration. A good score does not guarantee that a website is secure.
