—
—
Check a public WordPress site for exposed versions, outdated components, risky public endpoints, accidental file exposure, and known vulnerabilities when version data is available.
Connecting to the public site and identifying WordPress components without attempting exploitation.
This is a remote defensive assessment. A clean result cannot certify that a site is secure because plugins, versions, malware, server configuration, and authenticated behavior can be hidden from public view.
—
Matches only appear when the scanner can identify a component version and the vulnerability data source is available. A missing match does not prove a component is safe.
Only components referenced by public page assets can be detected. Installed but unused/hidden plugins may not appear here.
SAFE SCAN NOTE: WhateverTools sends the public URL you enter to its server and makes a limited set of public HTTP/HTTPS requests. Private/internal network ranges and non-standard ports are blocked. The scanner does not attempt exploitation, credential guessing, authentication bypass, SQL injection, file upload, command execution, or destructive actions.
The scanner looks for WordPress core fingerprints, plugin and theme asset paths, public version clues, outdated versions, XML-RPC availability, anonymous REST user enumeration, exposed debug logs, directory indexing, default readme exposure, and a small fixed set of common wp-config.php backup names. Backup-file checks use HEAD requests and do not download configuration-file contents.
When a Wordfence Intelligence API key is configured on WhateverTools, publicly detected component versions can also be compared with the Wordfence vulnerability database. Known-vulnerability results link back to their source records.
CDNs, cache plugins, optimization tools, custom themes, security plugins, and private code can hide WordPress fingerprints and version information. A plugin can also be installed without loading an asset on the page being checked. Use this report as a quick outside-in review, then confirm versions from the WordPress dashboard or hosting filesystem.
Back up the site, update WordPress core/plugins/themes, remove unused extensions, and fix any public debug logs, directory indexes, or backup files. If the scanner finds a known high/critical vulnerability in a version that has been publicly exposed for some time, review administrator accounts, recent file changes, security logs, and web-server logs rather than assuming an update alone proves the site was never compromised.
For SSL, redirects, headers, robots.txt, sitemap, and general website configuration, also run the Website Health Checker.