NovaraCode tool / passive WordPress security
WordPress Exposure Scanner
A free passive WordPress security tool that explains publicly observable version, plugin, theme, REST API, XML-RPC, file-exposure, and known-vulnerability signals without attacking the website.Open WordPress Exposure ScannerOur responsibility
WordPress detection and confidence model, passive exposure rules, local vulnerability catalogue and version matching, manual version workflow, bilingual UX, isolated execution, reporting, and operational safeguards.
Useful WordPress evidence without aggressive testing
The scanner checks externally visible WordPress core, plugin, and theme signals alongside REST user exposure, author enumeration indicators, XML-RPC, readme and license files, debug output, a small approved set of sensitive paths, HTTPS, and relevant security headers. It does not attempt login, brute-force credentials, execute exploits, upload files, fuzz APIs, or change the target.
Evidence and confidence instead of invented precision
WordPress and software versions are inferred from multiple passive signals such as public assets, metadata, discovery links, REST responses, and known endpoints. Conflicting or incomplete evidence is presented as uncertain rather than forced into a definitive answer, and users can supply an installed plugin version manually when the public website does not reveal it.
Local, attributable vulnerability matching
Detected or user-supplied versions are compared with a locally stored vulnerability catalogue using proper version ranges, source provenance, and separate confidence for software detection, version evidence, and the vulnerability match. Wordfence Intelligence synchronization updates the catalogue outside interactive scans, so runtime analysis does not depend on a live third-party API.
Careful language and a deliberately passive boundary
Normal WordPress functionality is not automatically described as vulnerable, and an unknown version is never presented as a confirmed affected installation. Findings explain what was observed, why it may matter, and what to verify next. The same isolated scanner, DNS pinning, redirect validation, response limits, queue controls, and private-network protections used by Website Inspector enforce the security boundary.
From public WordPress signals to a careful assessment
Passive observations are combined with confidence-aware version detection and local vulnerability matching without attempting to exploit the site.
Detect WordPress signals
Inspect public exposure
Match reliable versions locally
Report evidence with context
