Back to selected work

NovaraCode tool / passive WordPress security

WordPress Exposure Scanner

A free passive WordPress security tool that explains publicly observable version, plugin, theme, REST API, XML-RPC, file-exposure, and known-vulnerability signals without attacking the website.Open WordPress Exposure Scanner

Our responsibility

WordPress detection and confidence model, passive exposure rules, local vulnerability catalogue and version matching, manual version workflow, bilingual UX, isolated execution, reporting, and operational safeguards.

Useful WordPress evidence without aggressive testing

The scanner checks externally visible WordPress core, plugin, and theme signals alongside REST user exposure, author enumeration indicators, XML-RPC, readme and license files, debug output, a small approved set of sensitive paths, HTTPS, and relevant security headers. It does not attempt login, brute-force credentials, execute exploits, upload files, fuzz APIs, or change the target.

Evidence and confidence instead of invented precision

WordPress and software versions are inferred from multiple passive signals such as public assets, metadata, discovery links, REST responses, and known endpoints. Conflicting or incomplete evidence is presented as uncertain rather than forced into a definitive answer, and users can supply an installed plugin version manually when the public website does not reveal it.

Local, attributable vulnerability matching

Detected or user-supplied versions are compared with a locally stored vulnerability catalogue using proper version ranges, source provenance, and separate confidence for software detection, version evidence, and the vulnerability match. Wordfence Intelligence synchronization updates the catalogue outside interactive scans, so runtime analysis does not depend on a live third-party API.

Careful language and a deliberately passive boundary

Normal WordPress functionality is not automatically described as vulnerable, and an unknown version is never presented as a confirmed affected installation. Findings explain what was observed, why it may matter, and what to verify next. The same isolated scanner, DNS pinning, redirect validation, response limits, queue controls, and private-network protections used by Website Inspector enforce the security boundary.

From public WordPress signals to a careful assessment

Passive observations are combined with confidence-aware version detection and local vulnerability matching without attempting to exploit the site.

  1. Detect WordPress signals

  2. Inspect public exposure

  3. Match reliable versions locally

  4. Report evidence with context

Technologies and capabilities

WordPressLaravelPHPNext.jsTypeScriptRedis StreamsMySQLDockerWordfence IntelligenceREST APIXML-RPCVersion matching

Related services