Free agency tools / WordPress Health Scanner
Scan a WordPress site before you touch it
Point it at any WordPress site to surface the exposures attackers look for first — a leaked version, readable files, exposed usernames, missing security headers — scored so you can hand the report to a client.
Results for
How it works
- 1Enter a WordPress site — we fetch it and confirm it runs WordPress.
- 2We probe the classic exposure points: readme, xmlrpc, REST user enumeration, debug.log, security headers and the login page.
- 3You get a scored report with a letter grade, category breakdown and Quick Facts (theme, plugins, PHP, caching).
Frequently asked
Should I only scan sites I manage?
Yes — run it on your own or your clients' sites. It only reads public URLs, but scanning is your responsibility.
Why is the WordPress version 'hidden'?
Well-hardened sites strip the version from their markup and assets — that's a good thing, and we report it as hidden rather than guessing.
Is this a full penetration test?
No — it checks the common, high-signal exposures fast. It's a first-pass audit, not a substitute for a full security review.