Free agency tools / WordPress Health Scanner

Scan a WordPress site before you touch it

Point it at any WordPress site to surface the exposures attackers look for first — a leaked version, readable files, exposed usernames, missing security headers — scored so you can hand the report to a client.

How it works

  1. 1Enter a WordPress site — we fetch it and confirm it runs WordPress.
  2. 2We probe the classic exposure points: readme, xmlrpc, REST user enumeration, debug.log, security headers and the login page.
  3. 3You get a scored report with a letter grade, category breakdown and Quick Facts (theme, plugins, PHP, caching).

Frequently asked

Should I only scan sites I manage?

Yes — run it on your own or your clients' sites. It only reads public URLs, but scanning is your responsibility.

Why is the WordPress version 'hidden'?

Well-hardened sites strip the version from their markup and assets — that's a good thing, and we report it as hidden rather than guessing.

Is this a full penetration test?

No — it checks the common, high-signal exposures fast. It's a first-pass audit, not a substitute for a full security review.

Related tools