How to audit a WordPress site in 2026.
Is wp-login listing users?
Deeper than a manual audit or a scanner. At the scale AI agents attack.
The audit starts after signup. $49 for one month. Your report stays in your account.
- Core, plugins, themes
- Known CVEs
- Configuration & backups
- XML-RPC & login
01 / 08·running
Enumerating the attack surface
Checking exposed WordPress endpoints, versions, plugins, themes, and externally reachable services.
Signals
- WordPress versionDetecting exposed version information and outdated components.
- Known vulnerabilitiesMatching discovered plugins and themes against known CVEs.
- Authentication surfaceTesting login, enumeration, and externally exposed authentication behavior.
- XML-RPCChecking whether XML-RPC is enabled and what attack surface it creates.
An audit that thinks like an attacker.
Find what shouldn't be exposed.
We start outside your WordPress installation, looking across the site, related hosts, ports, and externally reachable services.
Hosts & subdomains
Find related infrastructure worth checking.
Ports & services
Identify what the internet can actually reach.
Go deeper than version checks.
Core, plugins, themes, authentication, XML-RPC, configuration, and known vulnerabilities are examined as an attacker would encounter them.
WordPress-specific checks
Focus on the attack surface unique to WordPress.
Known CVEs
Identify vulnerable versions and map findings to vulnerability IDs.
A finding is only useful if you can act on it.
The report gives you evidence, reproduction details, and CVE identifiers where applicable, so your team knows what was found and why it matters.
Evidence
See what the audit actually observed.
CVE IDs
Connect vulnerable components to known vulnerabilities.
Your report
The completed report remains available inside your paid account.
Before you start.
A few things worth knowing before you put your site through the audit.
Contact usAudit WordPress from the outside.
Go deeper than a manual audit or a scanner. At the scale AI agents attack.