We use necessary cookies to run the shop and your account. Other cookies, such as statistics, are only used if you allow them. You can change your choice at any time under “Cookie settings”. Cookie policy
Cookie settings
Choose which cookies we may use. Necessary cookies are always on. You can change or withdraw your choice at any time with the “Cookie settings” link. Cookie policy
Necessary
Always on
Needed for the website to work and to keep it secure, for example the shopping cart, logging in and remembering your cookie choice. They cannot be turned off.
5 services
Cookie choice · GetEasySoft Remembers your cookie choices, their version and your consent ID. Cookies: esk_consent · 6 months
WordPress · GetEasySoft Logging in to your account and security. Cookies: wordpress_logged_in_*, wordpress_sec_*, wordpress_test_cookie · session or up to 14 days
WooCommerce · GetEasySoft Shopping cart and checkout. Cookies: woocommerce_cart_hash, woocommerce_items_in_cart, wp_woocommerce_session_* · up to 2 days
Stripe · Stripe Payments Europe Ltd. Fraud prevention during card payments. Cookies: __stripe_mid, __stripe_sid · up to 1 year
CloudflareProtection against bots Cookies: __cf_bm, cf_clearance · up to 30 minutes / 1 year
Remember your settings and enable extra features such as embedded maps.
Not used on this website at the moment.
Help us understand how visitors use the website, so we can improve it. The data is collected in aggregate.
Not used on this website at the moment.
Used to measure advertising and show relevant ads on other websites, for example Google and Meta, and for embedded videos.
Enter your website address. In about a minute you see known vulnerabilities, HTTPS and security settings, explained in plain language, with the evidence behind every result.
Data from Wordfence Intelligence, WPVulnerability.net, NVD, CISA KEV and EPSS.
Free, no account needed
Only public information: nothing is attacked or changed
Results in plain language, with the evidence
What we check
What does the WordPress security scanner check?
The scanner looks at your website from the outside, the way any visitor or automated tool can. It identifies WordPress, plugins and themes and their versions, compares them with public vulnerability databases, and checks HTTPS, the security certificate, security headers and a few risky WordPress settings.
Area
What we check
Included in
Known vulnerabilities
WordPress core, plugins and themes found on the site, compared with Wordfence Intelligence, WPVulnerability.net and NVD. Flaws that attackers are known to use (CISA KEV) come first.
Free scan
Software versions
Whether the PHP version reported by the server still receives security updates (php.net).
Free scan
HTTPS and certificate
HTTPS available, redirect from HTTP, certificate valid and trusted, expiry date, outdated TLS/SSL protocols.
Free scan
Security headers
Strict-Transport-Security, Content-Security-Policy, X-Content-Type-Options, Referrer-Policy, Permissions-Policy and protection against framing (clickjacking).
Free scan
WordPress settings
XML-RPC switched on, user accounts listed by the REST API, PHP version disclosed.
Free scan
Exposed files
Backups, configuration files and folder listings that anyone can download. We never store their content.
Deep scan (verified websites)
The scan uses public information only. It never logs in, never sends attack code and never changes anything on your website.
How it works
How does the scan work?
You enter an address and pass a short automatic check against bots. Our server then visits the website with a clearly named scanner (EasySoftScanner/1.0), reads public pages and files with at most 40 requests, compares what it finds with vulnerability databases and shows the report right on this page.
Enter the address. Please scan websites you own or manage.
We read what is public. The home page, public files of WordPress, plugins and themes, the HTTP headers and the certificate. Nothing is attacked or changed.
We compare with the sources. Versions are matched with Wordfence Intelligence, WPVulnerability.net, NVD, the CISA KEV catalog and EPSS.
You get the report. A summary in plain words, what to do first, and the technical details with the evidence and the sources.
Reading the results
How do I read the results?
Every result has a severity, from critical to info, and a confidence level that says how sure we are. Start with the items under “What to do first”. Results marked “Actively exploited” are flaws that attackers are known to use, so they come first.
Confirmed We saw direct proof, for example public files that match exactly one release.
Probable Strong clues but no direct proof, for example a version number in a public readme file. The reason is always shown.
Needs verification It cannot be seen from outside. The report says exactly what to check, for example the plugin version in wp-admin.
Actively exploited The flaw is in the Known Exploited Vulnerabilities catalog of the US agency CISA. The badge links to the entry.
The score from 0 to 100 shows the share of the checked points that are in order. It is not a guarantee: no scan can prove that a website is completely secure.
Example report
What does a report look like?
Below is an excerpt of a report for a test website from our lab that runs deliberately outdated software. It shows the summary, the order of the results and how each one is explained, with the technical details one click away. It is not a customer website.
Example report Test site vuln-a.corpus.test from our scanner test lab, with deliberately outdated software. Not a customer website. Excerpt: 5 results.
Security report · Basic scan
vuln-a.corpus.test
Scanned on 29.09.2026 20:26 · http://vuln-a.corpus.test/
Needs attention soon
We found at least one serious problem. Start with the first item in the list below.
This record contains material that is subject to copyright. Copyright 2012-2026 Defiant Inc. Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy. License: https://www.wordfence.com/wordfence-intelligence-terms-and-conditions/
WordPress: WordPress Core < 5.8.3 - SQL Injection via WP_Query
HighConfirmed
What it means
WordPress 5.8.1, the version your site runs, has a publicly known security flaw.
Why it matters
Known flaws are published, and automated tools look for websites that have not been updated yet. How serious it is depends on the flaw: the level and the technical details are shown below.
What to do
Make a backup, then update WordPress to version 5.8.3 or later (Dashboard → Updates).
Technical details
Confirmed: The version was identified by comparing the hashes of public files with the official releases.
WordPress 5.8.1 is affected by a known vulnerability (< 5.8.3).
This record contains material that is subject to copyright. Copyright 2012-2026 Defiant Inc. Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy. License: https://www.wordfence.com/wordfence-intelligence-terms-and-conditions/
Contact Form 7: Contact Form 7 <= 5.3.1 - Arbitrary File Upload via Bypass
HighProbable
What it means
The plugin Contact Form 7 (version 5.3.1) on your site has a publicly known security flaw.
Why it matters
Known flaws are published, and automated tools look for websites that have not been updated yet. How serious it is depends on the flaw: the level and the technical details are shown below.
What to do
Make a backup, then update Contact Form 7 to version 5.3.2 or later (wp-admin → Plugins).
Technical details
Probable: The version comes from the public readme.txt file, which is not always updated together with the code.
Contact Form 7 5.3.1 is affected by a known vulnerability (< 5.3.2).
This record contains material that is subject to copyright. Copyright 2012-2026 Defiant Inc. Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy. License: https://www.wordfence.com/wordfence-intelligence-terms-and-conditions/
Low (2)
Security header missing: Content-Security-Policy
LowConfirmed
What it means
Your site does not tell browsers which sources of scripts are allowed.
Why it matters
It is an extra safety net: if harmful code were ever injected into a page, this rule could stop it from running.
What to do
This rule has to be tested before it is switched on, because a strict rule can block features of your site. Ask your web developer to set it up.
Technical details
Confirmed: Observed directly in the HTTP headers of the home page.
The homepage response does not include the Content-Security-Policy header. A Content-Security-Policy limits where scripts can be loaded from and reduces the impact of XSS.
How to fix it
Define a Content-Security-Policy (start with Content-Security-Policy-Report-Only to test).
We only report what can be traced back to a source. Vulnerability records come from public databases that we synchronise every day, and each report shows when every source was last updated. When two sources disagree, the report shows both values instead of choosing one.
EPSS (FIRST): the probability that a vulnerability will be exploited in the next 30 days.
php.net: which PHP versions still receive security updates.
wordpress.org: official releases, used to recognise versions.
Vulnerability data provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. Used under the Wordfence Intelligence Terms and Conditions; every result links to its record.
Prices
What does it cost? Free scan, deep scan with credits or monitoring
The basic scan is free and needs no account. A deep scan adds checks for exposed files and backups, only for websites whose ownership you have verified: the first one of each domain and account is free, after that it costs one credit. Monitoring repeats the deep scan every week and emails you when a newly published vulnerability affects your website.
Free
Basic scan
€0
All public checks: vulnerabilities, HTTPS, security headers, WordPress settings
No account needed
Up to 3 scans per hour and 10 per day per website
Free deep scan One per module for each verified domain and each account (confirmed email address).
Pay per scan
Deep scan with credits
from €1.96 per scan
Pack
Price
1 credit
€4.90
3 credits
€9.90
10 credits
€24.90
25 credits
€49.00
1 credit = 1 deep scan of a verified website, on either module (security or AI readiness)
Deep security scan: also exposed files, backups and folder listings
Credits are valid for 12 months from purchase
If a scan fails because of a problem on our side, the credit is returned
Subscription
Monitoring
from €7.90 per month
Plan
Websites
Manual rescans / month
Price
Monitoring Starter
1
—
€7.90 / month or €79.00 / year
Monitoring Agency
10
100
€24.90 / month or €249.00 / year
Monitoring Agency 25
25
250
€49.00 / month or €490.00 / year
Weekly security scan and an email when a newly published vulnerability affects a component we detected
Monthly AI readiness check
History and comparison of scans
Included rescans reset every month and are not carried over; cancel anytime, the plan runs until the end of the paid period
Credits and plans are bought in your GetEasySoft account. Customer accounts for the scanner open soon; the free scan is available now.
Prices in EUR.
Privacy
What happens to my data?
We store the address you scanned, the results and the date, so that the report can be shown and shared. Your IP address is used only as a hashed value to limit abuse. We do not store the content of files we find, the names of user accounts, or an email address you type to receive the report.
We look after WordPress websites: updates with a backup first, security settings and hardening, and help when something went wrong. Send us the address of your website, and you get a clear answer and a fixed price before we change anything.
Yes. The basic scan is free and needs no account. To keep it available for everyone, there is a limit of 3 scans per hour per visitor and 10 scans per day per website.
Is it safe to scan my website? Can it break something?
The scanner only reads public pages and files, like a visitor does. It never logs in, never sends attack code and makes at most 40 requests per scan. It does not change anything on your website.
Can I scan a website that is not mine?
Please scan only websites you own or manage. The scan uses public information only, but the results are meant for the people who are responsible for the website.
Why does a result say “Probable” or “Needs verification”?
From the outside we cannot always see the exact version of a plugin. “Probable” means strong clues, and the reason is shown. “Needs verification” means that you need to check it in wp-admin, as the report explains.
What does “Actively exploited” mean?
The vulnerability is listed in the Known Exploited Vulnerabilities catalog of the US agency CISA: attacks that use it have been observed. Update or remove the affected component first.
My score is low. Has my website been hacked?
Not necessarily. The score shows how many of the checked points are in order; it does not look for malware or signs of a break-in. A low score means there are known weaknesses that are worth fixing soon.
My website got a good score. Is it 100% secure?
No scan can guarantee that. A good score means that the public checks found no evidence of a problem. Keep WordPress, plugins and themes updated, and use strong passwords with two-factor login.
How long does a scan take?
Usually less than a minute. When a website responds slowly it can take longer. You can keep the page open: the report appears as soon as it is ready.
Can I get the report by email or share it?
Yes. After the scan you can send the report to your email address once, or create a private link. The link works for 30 days and is not listed in search engines.
How much does a deep scan cost?
The first deep scan of each verified domain and account is free (confirmed email address). After that one deep scan costs one credit: from 4.90 EUR for one credit to 49 EUR for 25. Credits are valid for 12 months and work for both the security scan and the AI readiness check.
Does it work for websites that do not use WordPress?
Partly. HTTPS, the certificate and the security headers are checked for every website. The WordPress checks run only when WordPress is detected.
Check your website now
The free scan takes about a minute. If something needs fixing and you do not have the time, we can do it for you.