← TOOL INDEX / WT-081
WT-081 WP!
WEBSITE / WEB UTILITY

WordPress Vulnerability Checker

Check a public WordPress site for exposed versions, outdated components, risky public endpoints, accidental file exposure, and known vulnerabilities when version data is available.

WORDPRESS SECURITY
SERVER SERVER ASSISTED
WORDPRESS SECURITY CHECKSAFE PUBLIC SCAN / NO EXPLOIT ATTEMPTS
OWNER / AUTHORIZED USE
FIND SECURITY WARNING SIGNS WITHOUT TRYING TO BREAK THE SITE

The checker identifies publicly visible WordPress versions and components, compares detectable versions with current releases, tests a small set of common exposure paths, and can match detected versions against a known-vulnerability feed when configured.

CHECK WHETHER YOUR WORDPRESS SITE MAY NEED SECURITY ATTENTION

This is a remote defensive assessment. A clean result cannot certify that a site is secure because plugins, versions, malware, server configuration, and authenticated behavior can be hidden from public view.

LOW IMPACT
READYEnter a public WordPress site and confirm you are authorized to test it.

SAFE SCAN NOTE: WhateverTools sends the public URL you enter to its server and makes a limited set of public HTTP/HTTPS requests. Private/internal network ranges and non-standard ports are blocked. The scanner does not attempt exploitation, credential guessing, authentication bypass, SQL injection, file upload, command execution, or destructive actions.

WHAT IT CHECKS

Public WordPress exposure, versions, and known-vulnerability signals.

The scanner looks for WordPress core fingerprints, plugin and theme asset paths, public version clues, outdated versions, XML-RPC availability, anonymous REST user enumeration, exposed debug logs, directory indexing, default readme exposure, and a small fixed set of common wp-config.php backup names. Backup-file checks use HEAD requests and do not download configuration-file contents.

When a Wordfence Intelligence API key is configured on WhateverTools, publicly detected component versions can also be compared with the Wordfence vulnerability database. Known-vulnerability results link back to their source records.

LIMITATIONS

Why a remote scan cannot say “your site is safe.”

CDNs, cache plugins, optimization tools, custom themes, security plugins, and private code can hide WordPress fingerprints and version information. A plugin can also be installed without loading an asset on the page being checked. Use this report as a quick outside-in review, then confirm versions from the WordPress dashboard or hosting filesystem.

IF SOMETHING LOOKS BAD

Patch first, then investigate if exposure may have existed.

Back up the site, update WordPress core/plugins/themes, remove unused extensions, and fix any public debug logs, directory indexes, or backup files. If the scanner finds a known high/critical vulnerability in a version that has been publicly exposed for some time, review administrator accounts, recent file changes, security logs, and web-server logs rather than assuming an update alone proves the site was never compromised.

For SSL, redirects, headers, robots.txt, sitemap, and general website configuration, also run the Website Health Checker.