Free site check · no email
See what your site is telling strangers.
Every site publishes more than its owner realises — the WordPress version, browsable folders, missing security headers. This checks what anyone on the internet can already see, in about ten seconds.
It only reads
We request your public pages, the same as any visitor. Nothing is modified, nothing is stored, and you need no account.
We say what we cannot see
A scan from outside cannot read your plugin list, so it cannot tell you whether anything is vulnerable. We will not pretend otherwise.
Every finding is actionable
Each one comes with instructions for fixing it yourself. Most take a few minutes and need no developer.
Why an outside scan can only tell you so much.
Plenty of tools will scan a URL and hand you a security grade. Be sceptical of that grade: the single most important question — whether any plugin you run has a published vulnerability — cannot be answered from outside, because your plugin list is not public.
That is why our free plugin exists. It runs the same checks from inside, where the answers actually are, and it is the same code we run on client sites.
From outside
- HTTPS and certificate
- Security headers
- Exposed version info
- Browsable folders
- XML-RPC exposure
- Compression and caching
Only from inside
- Known vulnerabilities
- Outdated plugins
- Abandoned plugins
- Backups running
- PHP support status
- Admin accounts