Free tool

Free WordPress security scanner

Enter your website address. In about a minute you see known vulnerabilities, HTTPS and security settings, explained in plain language, with the evidence behind every result.

Free basic scan. Only public information is used; nothing is attacked or changed. Please scan only websites you own or manage.

Data from Wordfence Intelligence, WPVulnerability.net, NVD, CISA KEV and EPSS.

  • Free, no account needed
  • Only public information: nothing is attacked or changed
  • Results in plain language, with the evidence

What we check

What does the WordPress security scanner check?

The scanner looks at your website from the outside, the way any visitor or automated tool can. It identifies WordPress, plugins and themes and their versions, compares them with public vulnerability databases, and checks HTTPS, the security certificate, security headers and a few risky WordPress settings.

AreaWhat we checkIncluded in
Known vulnerabilitiesWordPress core, plugins and themes found on the site, compared with Wordfence Intelligence, WPVulnerability.net and NVD. Flaws that attackers are known to use (CISA KEV) come first.Free scan
Software versionsWhether the PHP version reported by the server still receives security updates (php.net).Free scan
HTTPS and certificateHTTPS available, redirect from HTTP, certificate valid and trusted, expiry date, outdated TLS/SSL protocols.Free scan
Security headersStrict-Transport-Security, Content-Security-Policy, X-Content-Type-Options, Referrer-Policy, Permissions-Policy and protection against framing (clickjacking).Free scan
WordPress settingsXML-RPC switched on, user accounts listed by the REST API, PHP version disclosed.Free scan
Exposed filesBackups, configuration files and folder listings that anyone can download. We never store their content.Deep scan (verified websites)

The scan uses public information only. It never logs in, never sends attack code and never changes anything on your website.

How it works

How does the scan work?

You enter an address and pass a short automatic check against bots. Our server then visits the website with a clearly named scanner (EasySoftScanner/1.0), reads public pages and files with at most 40 requests, compares what it finds with vulnerability databases and shows the report right on this page.

  1. Enter the address. Please scan websites you own or manage.
  2. We read what is public. The home page, public files of WordPress, plugins and themes, the HTTP headers and the certificate. Nothing is attacked or changed.
  3. We compare with the sources. Versions are matched with Wordfence Intelligence, WPVulnerability.net, NVD, the CISA KEV catalog and EPSS.
  4. You get the report. A summary in plain words, what to do first, and the technical details with the evidence and the sources.
Rows of rack-mounted servers lit in blue in a data center
Dimly lit desk at night with a laptop, a desk lamp and a clock

Reading the results

How do I read the results?

Every result has a severity, from critical to info, and a confidence level that says how sure we are. Start with the items under “What to do first”. Results marked “Actively exploited” are flaws that attackers are known to use, so they come first.

  • Confirmed We saw direct proof, for example public files that match exactly one release.
  • Probable Strong clues but no direct proof, for example a version number in a public readme file. The reason is always shown.
  • Needs verification It cannot be seen from outside. The report says exactly what to check, for example the plugin version in wp-admin.
  • Actively exploited The flaw is in the Known Exploited Vulnerabilities catalog of the US agency CISA. The badge links to the entry.

The score from 0 to 100 shows the share of the checked points that are in order. It is not a guarantee: no scan can prove that a website is completely secure.

Example report

What does a report look like?

Below is an excerpt of a report for a test website from our lab that runs deliberately outdated software. It shows the summary, the order of the results and how each one is explained, with the technical details one click away. It is not a customer website.

Example report Test site vuln-a.corpus.test from our scanner test lab, with deliberately outdated software. Not a customer website. Excerpt: 5 results.

Security report · Basic scan

vuln-a.corpus.test

Scanned on 29.09.2026 20:26 · http://vuln-a.corpus.test/

Needs attention soon

We found at least one serious problem. Start with the first item in the list below.

What to do first

  1. Social Warfare: Social Warfare <= 3.5.2 - Unauthenticated Arbitrary Settings Update High Actively exploited Make a backup, then update Social Warfare to version 3.5.3 or later (wp-admin → Plugins).
  2. WordPress: WordPress Core < 5.8.3 - SQL Injection via WP_Query High Make a backup, then update WordPress to version 5.8.3 or later (Dashboard → Updates).
  3. Contact Form 7: Contact Form 7 <= 5.3.1 - Arbitrary File Upload via Bypass High Make a backup, then update Contact Form 7 to version 5.3.2 or later (wp-admin → Plugins).
How sure are we? The labels explained
Confirmed
We saw direct proof.
Probable
Strong clues, but no direct proof. The reason is shown.
Needs verification
Cannot be seen from outside. Please check it as described.
Actively exploited
The flaw is on the CISA list of vulnerabilities that attackers are known to use. Deal with these first.
  • 0 Critical
  • 3 High
  • 0 Medium
  • 2 Low
  • 0 Info

High (3)

Social Warfare: Social Warfare <= 3.5.2 - Unauthenticated Arbitrary Settings Update

High Probable Actively exploited (CISA Known Exploited Vulnerabilities catalog, opens in a new tab)

What it means

The plugin Social Warfare (version 3.5.2) on your site has a publicly known security flaw.

Why it matters

Attacks that use this flaw have been observed: it is on the CISA list of actively exploited vulnerabilities. Deal with it first.

What to do

Make a backup, then update Social Warfare to version 3.5.3 or later (wp-admin → Plugins).

Technical details

Probable: The version comes from the public readme.txt file, which is not always updated together with the code.

Social Warfare 3.5.2 is affected by a known vulnerability (< 3.5.3).

  • CVE-2019-9978
  • CVSS 3.1 7.2
  • EPSS: 72.9% probability of exploitation in 30 days (percentile 99)
  • Affected versions: < 3.5.3
  • Fixed in: 3.5.3

How to fix it

Update Social Warfare to version 3.5.3 or later.

Evidence

Checked URL
GET http://vuln-a.corpus.test/wp-content/plugins/social-warfare/readme.txt
What was found
Stable tag: 3.5.2
Rule
sec.vuln.plugin
Observed
29.09.2026 20:26

Sources

This record contains material that is subject to copyright. Copyright 2012-2026 Defiant Inc. Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy. License: https://www.wordfence.com/wordfence-intelligence-terms-and-conditions/

WordPress: WordPress Core < 5.8.3 - SQL Injection via WP_Query

High Confirmed

What it means

WordPress 5.8.1, the version your site runs, has a publicly known security flaw.

Why it matters

Known flaws are published, and automated tools look for websites that have not been updated yet. How serious it is depends on the flaw: the level and the technical details are shown below.

What to do

Make a backup, then update WordPress to version 5.8.3 or later (Dashboard → Updates).

Technical details

Confirmed: The version was identified by comparing the hashes of public files with the official releases.

WordPress 5.8.1 is affected by a known vulnerability (< 5.8.3).

  • CVE-2022-21661
  • CVSS 3.1 8.0
  • EPSS: 97.8% probability of exploitation in 30 days (percentile 100)
  • Affected versions: < 5.8.3
  • Fixed in: 5.8.3

How to fix it

Update WordPress to version 5.8.3 or later.

Evidence

Checked URL
GET http://vuln-a.corpus.test/wp-includes/css/dist/block-library/style.min.css
What was found
file hashes match WordPress 5.8.1
Rule
sec.vuln.core
Observed
29.09.2026 20:26

Sources

This record contains material that is subject to copyright. Copyright 2012-2026 Defiant Inc. Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy. License: https://www.wordfence.com/wordfence-intelligence-terms-and-conditions/

Contact Form 7: Contact Form 7 <= 5.3.1 - Arbitrary File Upload via Bypass

High Probable

What it means

The plugin Contact Form 7 (version 5.3.1) on your site has a publicly known security flaw.

Why it matters

Known flaws are published, and automated tools look for websites that have not been updated yet. How serious it is depends on the flaw: the level and the technical details are shown below.

What to do

Make a backup, then update Contact Form 7 to version 5.3.2 or later (wp-admin → Plugins).

Technical details

Probable: The version comes from the public readme.txt file, which is not always updated together with the code.

Contact Form 7 5.3.1 is affected by a known vulnerability (< 5.3.2).

  • CVE-2020-35489
  • CVSS 3.1 8.1
  • EPSS: 89.3% probability of exploitation in 30 days (percentile 100)
  • Affected versions: < 5.3.2
  • Fixed in: 5.3.2

How to fix it

Update Contact Form 7 to version 5.3.2 or later.

Evidence

Checked URL
GET http://vuln-a.corpus.test/wp-content/plugins/contact-form-7/readme.txt
What was found
Stable tag: 5.3.1
Rule
sec.vuln.plugin
Observed
29.09.2026 20:26

Sources

This record contains material that is subject to copyright. Copyright 2012-2026 Defiant Inc. Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy. License: https://www.wordfence.com/wordfence-intelligence-terms-and-conditions/

Low (2)

Security header missing: Content-Security-Policy

Low Confirmed

What it means

Your site does not tell browsers which sources of scripts are allowed.

Why it matters

It is an extra safety net: if harmful code were ever injected into a page, this rule could stop it from running.

What to do

This rule has to be tested before it is switched on, because a strict rule can block features of your site. Ask your web developer to set it up.

Technical details

Confirmed: Observed directly in the HTTP headers of the home page.

The homepage response does not include the Content-Security-Policy header. A Content-Security-Policy limits where scripts can be loaded from and reduces the impact of XSS.

How to fix it

Define a Content-Security-Policy (start with Content-Security-Policy-Report-Only to test).

Evidence

Checked URL
GET http://vuln-a.corpus.test/
What was found
response headers without Content-Security-Policy
Rule
sec.headers.content-security-policy
Observed
29.09.2026 20:26

XML-RPC endpoint is active

Low Confirmed

What it means

An older interface for remote publishing (XML-RPC) is switched on.

Why it matters

It is often used by automated tools that try to guess passwords. Many sites do not need it.

What to do

If you do not use the WordPress mobile app, Jetpack or remote publishing, switch it off with a security plugin or ask your web developer.

Technical details

Confirmed: Observed directly in the server response.

http://vuln-a.corpus.test/xmlrpc.php answers as an XML-RPC server. It is a frequent target for password guessing and pingback abuse.

How to fix it

If no app or service needs XML-RPC (Jetpack and the mobile apps may), block xmlrpc.php at the web server or with a security plugin.

Evidence

Checked URL
GET http://vuln-a.corpus.test/xmlrpc.php
What was found
XML-RPC server accepts POST requests only.
Rule
sec.xmlrpc.enabled
Observed
29.09.2026 20:26

Data sources — last synchronisation

  • Wordfence Intelligence: 29.09.2026 20:26
  • CISA KEV: 29.09.2026 20:26
  • EPSS (FIRST): 29.09.2026 20:26

Vulnerability data from Wordfence Intelligence. Copyright 2012-2026 Defiant Inc.

Results marked “Probable” or “Needs verification” are indicative. The scanner only uses public information (and, for verified sites, checks whether sensitive files are reachable) and never attempts to exploit a vulnerability. No scan can guarantee that a website is completely secure.

Data sources

Where does the vulnerability data come from?

We only report what can be traced back to a source. Vulnerability records come from public databases that we synchronise every day, and each report shows when every source was last updated. When two sources disagree, the report shows both values instead of choosing one.

Vulnerability data provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. Used under the Wordfence Intelligence Terms and Conditions; every result links to its record.

Close-up of program code on a dark computer monitor

Prices

What does it cost? Free scan, deep scan with credits or monitoring

The basic scan is free and needs no account. A deep scan adds checks for exposed files and backups, only for websites whose ownership you have verified: the first one of each domain and account is free, after that it costs one credit. Monitoring repeats the deep scan every week and emails you when a newly published vulnerability affects your website.

Free

Basic scan

€0

  • All public checks: vulnerabilities, HTTPS, security headers, WordPress settings
  • No account needed
  • Up to 3 scans per hour and 10 per day per website

Free deep scan One per module for each verified domain and each account (confirmed email address).

Pay per scan

Deep scan with credits

from €1.96 per scan

PackPrice
1 credit€4.90
3 credits€9.90
10 credits€24.90
25 credits€49.00
  • 1 credit = 1 deep scan of a verified website, on either module (security or AI readiness)
  • Deep security scan: also exposed files, backups and folder listings
  • Credits are valid for 12 months from purchase
  • If a scan fails because of a problem on our side, the credit is returned

Subscription

Monitoring

from €7.90 per month

PlanWebsitesManual rescans / monthPrice
Monitoring Starter1—€7.90 / month
or €79.00 / year
Monitoring Agency10100€24.90 / month
or €249.00 / year
Monitoring Agency 2525250€49.00 / month
or €490.00 / year
  • Weekly security scan and an email when a newly published vulnerability affects a component we detected
  • Monthly AI readiness check
  • History and comparison of scans
  • Included rescans reset every month and are not carried over; cancel anytime, the plan runs until the end of the paid period

Credits and plans are bought in your GetEasySoft account. Customer accounts for the scanner open soon; the free scan is available now.

Prices in EUR.

Blue network cables plugged into a switch in a server room

Privacy

What happens to my data?

We store the address you scanned, the results and the date, so that the report can be shown and shared. Your IP address is used only as a hashed value to limit abuse. We do not store the content of files we find, the names of user accounts, or an email address you type to receive the report.

  • Operator: Einzelunternehmen Alin Ghiorghiu, Kloten, Switzerland.
  • Hosting of the scanner: HOSTON SRL, Romania (EU).
  • Reports: kept for up to 12 months, then deleted automatically. Private links expire after 30 days.
  • Bot protection: Cloudflare Turnstile, loaded only when you use the form.
  • Details: privacy policy.

Care & security

Found a problem and no time to fix it?

We look after WordPress websites: updates with a backup first, security settings and hardening, and help when something went wrong. Send us the address of your website, and you get a clear answer and a fixed price before we change anything.

Let us fix it Our services

Hands typing on a laptop keyboard in a dark room

Frequently asked questions

Is the scan really free?

Yes. The basic scan is free and needs no account. To keep it available for everyone, there is a limit of 3 scans per hour per visitor and 10 scans per day per website.

Is it safe to scan my website? Can it break something?

The scanner only reads public pages and files, like a visitor does. It never logs in, never sends attack code and makes at most 40 requests per scan. It does not change anything on your website.

Can I scan a website that is not mine?

Please scan only websites you own or manage. The scan uses public information only, but the results are meant for the people who are responsible for the website.

Why does a result say “Probable” or “Needs verification”?

From the outside we cannot always see the exact version of a plugin. “Probable” means strong clues, and the reason is shown. “Needs verification” means that you need to check it in wp-admin, as the report explains.

What does “Actively exploited” mean?

The vulnerability is listed in the Known Exploited Vulnerabilities catalog of the US agency CISA: attacks that use it have been observed. Update or remove the affected component first.

My score is low. Has my website been hacked?

Not necessarily. The score shows how many of the checked points are in order; it does not look for malware or signs of a break-in. A low score means there are known weaknesses that are worth fixing soon.

My website got a good score. Is it 100% secure?

No scan can guarantee that. A good score means that the public checks found no evidence of a problem. Keep WordPress, plugins and themes updated, and use strong passwords with two-factor login.

How long does a scan take?

Usually less than a minute. When a website responds slowly it can take longer. You can keep the page open: the report appears as soon as it is ready.

Can I get the report by email or share it?

Yes. After the scan you can send the report to your email address once, or create a private link. The link works for 30 days and is not listed in search engines.

How much does a deep scan cost?

The first deep scan of each verified domain and account is free (confirmed email address). After that one deep scan costs one credit: from 4.90 EUR for one credit to 49 EUR for 25. Credits are valid for 12 months and work for both the security scan and the AI readiness check.

Does it work for websites that do not use WordPress?

Partly. HTTPS, the certificate and the security headers are checked for every website. The WordPress checks run only when WordPress is detected.

Check your website now

The free scan takes about a minute. If something needs fixing and you do not have the time, we can do it for you.

Last updated: · Published by GetEasySoft

Photos: panumas nikhomkhai on Pexels, Julien Bachelet on Pexels, Nemuel Sereti on Pexels, Brett Sayles on Pexels, cottonbro studio on Pexels