{"id":4329,"date":"2020-12-03T16:22:45","date_gmt":"2020-12-03T16:22:45","guid":{"rendered":"https:\/\/firstsiteguide.com\/?post_type=tools&p=4329"},"modified":"2023-10-04T11:48:35","modified_gmt":"2023-10-04T11:48:35","slug":"wordpress-security-online-scanner","status":"publish","type":"tools","link":"https:\/\/firstsiteguide.com\/wordpress-security-online-scanner\/","title":{"rendered":"WordPress Security Scanner"},"content":{"rendered":"

More than 60 thousand WordPress sites get hacked every day<\/strong>! Don’t believe us? Have a look at this real-time counter<\/a>. It’s extremely frustrating to get hacked. It costs time, money, reputation, and nerves, but what’s even worse – in most cases it’s completely avoidable<\/a> if you follow WordPress security best practices. No site is completely hack-proof. The fact that huge companies get hacked all the time is the best example of that. However, just a tiny effort<\/strong> can dramatically increase the chances of not getting hacked<\/strong>!<\/p>\n\n\n\n

Enter the URL and scan your site<\/h2>\n\n\n
\n \n \n \n
<\/div>\n <\/div>\n\tThe scan is completely safe! It will not simulate a brute-force attack nor perform any kind of action that could jeopardize it.<\/i>
Please enter a valid site URL<\/div>
<\/div>
Check if full WordPress version info is revealed<\/strong>

You should be proud that your site is powered by WordPress and there's no need to hide that information. However disclosing the full WP version info in the default location (page header meta) is not wise. People with bad intentions can easily use Google to find site's that use a specific version of WordPress and target them with 0-day exploits.<\/p><\/div><\/div>

\n\t\t\t
<\/div>\n\t\t\t\t
\n\t\t\t\t
<\/div>\n\t\t\t\t
<\/div>\n\t\t\t\t
<\/div>\n\t\t\t\t<\/div>\n\t\t\t<\/div>
<\/div><\/div>
<\/div>
Check if readme.html<\/i> file is accessible via HTTP<\/strong>

As mentioned in the previous test - you should be proud that your site is powered by WordPress but also hide the exact version you're using. readme.html<\/i> contains WP version info and if left on the default location (WP root) attackers can easily find out your WP version.<\/p><\/div><\/div>

\n\t\t\t
<\/div>\n\t\t\t\t
\n\t\t\t\t
<\/div>\n\t\t\t\t
<\/div>\n\t\t\t\t
<\/div>\n\t\t\t\t<\/div>\n\t\t\t<\/div>
<\/div><\/div>
<\/div>
Check if response headers contain detailed PHP version info<\/strong>

As with the WordPress version it's not wise to disclose the exact PHP version you're using because it makes the job of attacking your site much easier. This issue is not directly WP related but it definitely affects your site.<\/p><\/div><\/div>

\n\t\t\t
<\/div>\n\t\t\t\t
\n\t\t\t\t
<\/div>\n\t\t\t\t
<\/div>\n\t\t\t\t
<\/div>\n\t\t\t\t<\/div>\n\t\t\t<\/div>
<\/div><\/div>
<\/div>
Try getting the list of usernames<\/strong>

Disclosing usernames is not a terrible mistake. Obviously you need the username and the password to login but hiding them will prevent hacker from doing brite-force attacks on your accounts.<\/p><\/div><\/div>

\n\t\t\t
<\/div>\n\t\t\t\t
\n\t\t\t\t
<\/div>\n\t\t\t\t
<\/div>\n\t\t\t\t
<\/div>\n\t\t\t\t<\/div>\n\t\t\t<\/div>
<\/div><\/div>
<\/div>
Check for display of unnecessary information on failed login attempts<\/strong>

By default on failed login attempts WordPress will tell you whether username or password is wrong. An attacker can use that to find out which usernames are active on your system and then use brute-force methods to hack the password.<\/p><\/div><\/div>

\n\t\t\t
<\/div>\n\t\t\t\t
\n\t\t\t\t
<\/div>\n\t\t\t\t
<\/div>\n\t\t\t\t
<\/div>\n\t\t\t\t<\/div>\n\t\t\t<\/div>
<\/div><\/div>
<\/div>
Check if install.php<\/i> file is accessible via HTTP<\/strong>

There have already been a couple of security issues regarding the install.php<\/i> file. Once you install WP this file becomes useless and there's no reason to keep it in the default location and accessible via HTTP.<\/p>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div><\/div>

\n\t\t\t
<\/div>\n\t\t\t\t
\n\t\t\t\t
<\/div>\n\t\t\t\t
<\/div>\n\t\t\t\t
<\/div>\n\t\t\t\t<\/div>\n\t\t\t<\/div>
<\/div><\/div>
<\/div>
Check if upgrade.php<\/i> file is accessible via HTTP<\/strong>

There have already been a couple of security issues regarding this file. Besides the security issue it's never a good idea to let people run any database upgrade scripts without your knowledge. This is a useful file but it should not be accessible on the default location.<\/p>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div><\/div>

\n\t\t\t
<\/div>\n\t\t\t\t
\n\t\t\t\t
<\/div>\n\t\t\t\t
<\/div>\n\t\t\t\t
<\/div>\n\t\t\t\t<\/div>\n\t\t\t<\/div>
<\/div><\/div>
<\/div>
Check if uploads<\/i> folder is browsable<\/strong>

Allowing anyone to view all files in the uploads folder just by point the brower to it will allow them to easily download all your uploaded files.\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\tIt's a security and a copyright issue.<\/p>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div><\/div>

\n\t\t\t
<\/div>\n\t\t\t\t
\n\t\t\t\t
<\/div>\n\t\t\t\t
<\/div>\n\t\t\t\t
<\/div>\n\t\t\t\t<\/div>\n\t\t\t<\/div>
<\/div><\/div>
<\/div>
Check if Windows Live Writer link is present in pages' header<\/strong>

If you're not using Windows Live Writer there's really no valid reason to have it's link in the page header thus telling the whole world you're using WordPress.<\/p>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div><\/div>

\n\t\t\t
<\/div>\n\t\t\t\t
\n\t\t\t\t
<\/div>\n\t\t\t\t
<\/div>\n\t\t\t\t
<\/div>\n\t\t\t\t<\/div>\n\t\t\t<\/div>
<\/div><\/div>
<\/div>
Check if EditURI link is present in pages' header<\/strong>

If you're not using any Really Simple Discovery services such as pingbacks there's no need to advertise that endpoint (link) in the header. Please note that for most sites this is not a security issue because they \"want to be discovered\" but if you want to hide the fact that you're using WP this is the way to go.<\/p>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div><\/div>

\n\t\t\t
<\/div>\n\t\t\t\t
\n\t\t\t\t
<\/div>\n\t\t\t\t
<\/div>\n\t\t\t\t
<\/div>\n\t\t\t\t<\/div>\n\t\t\t<\/div>
<\/div><\/div>
<\/div>
Check if admin interface is delivered via HTTPS<\/strong>
Enabling Wordpress administration over SSL should make it much harder for a malicious person to steal your cookies and\/or authentication headers and use them to impersonate you and gain access to wp-admin. It also obfuscates the ability to sniff your content, which could be important for legal blogs which may have drafts of documents that need strict protection.<\/div><\/div>
\n\t\t\t
<\/div>\n\t\t\t\t
\n\t\t\t\t
<\/div>\n\t\t\t\t
<\/div>\n\t\t\t\t
<\/div>\n\t\t\t\t<\/div>\n\t\t\t<\/div>
<\/div><\/div><\/div>\n\n\n\n

Hackers love low hanging fruit<\/h2>\n\n\n\n

If you’re hacking more\/less any site you can and don’t have a specific target it’s obvious you’ll initially target the weakest sites<\/strong>. Ones that take almost no effort to hack. All we’re saying is – don’t be in that category! Believe us, it doesn’t take much because a lot of people have 12345<\/em> sets as their password and don’t update WordPress plugins, core, or themes for years.<\/p>\n\n\n\n

We’ve created this free scanner to show you a few things you should check on your site. None of the listed things by themselves pose any danger but they do increase your chances of being hacked because you’re the low-hanging fruit. Just enter your site’s URL and click Scan Site. It only takes a few seconds to do the scan. No, your site won’t slow down nor will anything bad happen to it. If you want to find out more about the tests, get help on how to fix them, and perform over 40 tests to secure your site we recommend installing Security Ninja<\/a> – it’s free on the official WordPress repository, and it will help you make your WordPress website more secure.<\/p>\n\n\n

\n \n\n

Perform 40+ security tests<\/strong> on your site with 1 click<\/strong> for free & and get all WordPress security issues fixed. Install Security Ninja<\/a> plugin and keep your site safe!<\/p>\n\n<\/div>","protected":false},"author":1,"featured_media":7959,"comment_status":"open","ping_status":"closed","template":"","acf":[],"yoast_head":"\nFree Online WordPress Security Scanner Tool<\/title>\n<meta name=\"description\" content=\"More than 60 thousand WordPress sites get hacked every day! In most cases it's completely avoidable if you follow WordPress security best practices.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/firstsiteguide.com\/wordpress-security-online-scanner\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Free Online WordPress Security Scanner Tool\" \/>\n<meta property=\"og:description\" content=\"More than 60 thousand WordPress sites get hacked every day! In most cases it's completely avoidable if you follow WordPress security best practices.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/firstsiteguide.com\/wordpress-security-online-scanner\/\" \/>\n<meta property=\"og:site_name\" content=\"FirstSiteGuide\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/firstsiteguide\" \/>\n<meta property=\"article:modified_time\" content=\"2023-10-04T11:48:35+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/firstsiteguide.com\/wp-content\/uploads\/2020\/12\/wordPress-security-scanner.png\" \/>\n\t<meta property=\"og:image:width\" content=\"844\" \/>\n\t<meta property=\"og:image:height\" content=\"430\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/firstsiteguide.com\/wp-content\/uploads\/2020\/12\/wordPress-security-scanner.png\" \/>\n<meta name=\"twitter:site\" content=\"@firstsiteguide\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/firstsiteguide.com\/wordpress-security-online-scanner\/\",\"url\":\"https:\/\/firstsiteguide.com\/wordpress-security-online-scanner\/\",\"name\":\"Free Online WordPress Security Scanner Tool\",\"isPartOf\":{\"@id\":\"https:\/\/firstsiteguide.com\/#website\"},\"datePublished\":\"2020-12-03T16:22:45+00:00\",\"dateModified\":\"2023-10-04T11:48:35+00:00\",\"description\":\"More than 60 thousand WordPress sites get hacked every day! In most cases it's completely avoidable if you follow WordPress security best practices.\",\"breadcrumb\":{\"@id\":\"https:\/\/firstsiteguide.com\/wordpress-security-online-scanner\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/firstsiteguide.com\/wordpress-security-online-scanner\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/firstsiteguide.com\/wordpress-security-online-scanner\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/firstsiteguide.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"WordPress Security Scanner\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/firstsiteguide.com\/#website\",\"url\":\"https:\/\/firstsiteguide.com\/\",\"name\":\"FirstSiteGuide\",\"description\":\"Online Business Advice\",\"publisher\":{\"@id\":\"https:\/\/firstsiteguide.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/firstsiteguide.com\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/firstsiteguide.com\/#organization\",\"name\":\"FirstSiteGuide\",\"url\":\"https:\/\/firstsiteguide.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/firstsiteguide.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/firstsiteguide.com\/wp-content\/uploads\/2020\/11\/fsg-logo-green.svg\",\"contentUrl\":\"https:\/\/firstsiteguide.com\/wp-content\/uploads\/2020\/11\/fsg-logo-green.svg\",\"width\":73,\"height\":70,\"caption\":\"FirstSiteGuide\"},\"image\":{\"@id\":\"https:\/\/firstsiteguide.com\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/firstsiteguide\",\"https:\/\/twitter.com\/firstsiteguide\",\"https:\/\/www.instagram.com\/firstsiteguide\/\",\"https:\/\/www.linkedin.com\/company\/firstsiteguide\/\",\"https:\/\/www.pinterest.com\/firstsiteguide\/\",\"https:\/\/www.youtube.com\/firstsiteguide\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Free Online WordPress Security Scanner Tool","description":"More than 60 thousand WordPress sites get hacked every day! In most cases it's completely avoidable if you follow WordPress security best practices.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/firstsiteguide.com\/wordpress-security-online-scanner\/","og_locale":"en_US","og_type":"article","og_title":"Free Online WordPress Security Scanner Tool","og_description":"More than 60 thousand WordPress sites get hacked every day! In most cases it's completely avoidable if you follow WordPress security best practices.","og_url":"https:\/\/firstsiteguide.com\/wordpress-security-online-scanner\/","og_site_name":"FirstSiteGuide","article_publisher":"https:\/\/www.facebook.com\/firstsiteguide","article_modified_time":"2023-10-04T11:48:35+00:00","og_image":[{"width":844,"height":430,"url":"https:\/\/firstsiteguide.com\/wp-content\/uploads\/2020\/12\/wordPress-security-scanner.png","type":"image\/png"}],"twitter_card":"summary_large_image","twitter_image":"https:\/\/firstsiteguide.com\/wp-content\/uploads\/2020\/12\/wordPress-security-scanner.png","twitter_site":"@firstsiteguide","twitter_misc":{"Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/firstsiteguide.com\/wordpress-security-online-scanner\/","url":"https:\/\/firstsiteguide.com\/wordpress-security-online-scanner\/","name":"Free Online WordPress Security Scanner Tool","isPartOf":{"@id":"https:\/\/firstsiteguide.com\/#website"},"datePublished":"2020-12-03T16:22:45+00:00","dateModified":"2023-10-04T11:48:35+00:00","description":"More than 60 thousand WordPress sites get hacked every day! In most cases it's completely avoidable if you follow WordPress security best practices.","breadcrumb":{"@id":"https:\/\/firstsiteguide.com\/wordpress-security-online-scanner\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/firstsiteguide.com\/wordpress-security-online-scanner\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/firstsiteguide.com\/wordpress-security-online-scanner\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/firstsiteguide.com\/"},{"@type":"ListItem","position":2,"name":"WordPress Security Scanner"}]},{"@type":"WebSite","@id":"https:\/\/firstsiteguide.com\/#website","url":"https:\/\/firstsiteguide.com\/","name":"FirstSiteGuide","description":"Online Business Advice","publisher":{"@id":"https:\/\/firstsiteguide.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/firstsiteguide.com\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/firstsiteguide.com\/#organization","name":"FirstSiteGuide","url":"https:\/\/firstsiteguide.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/firstsiteguide.com\/#\/schema\/logo\/image\/","url":"https:\/\/firstsiteguide.com\/wp-content\/uploads\/2020\/11\/fsg-logo-green.svg","contentUrl":"https:\/\/firstsiteguide.com\/wp-content\/uploads\/2020\/11\/fsg-logo-green.svg","width":73,"height":70,"caption":"FirstSiteGuide"},"image":{"@id":"https:\/\/firstsiteguide.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/firstsiteguide","https:\/\/twitter.com\/firstsiteguide","https:\/\/www.instagram.com\/firstsiteguide\/","https:\/\/www.linkedin.com\/company\/firstsiteguide\/","https:\/\/www.pinterest.com\/firstsiteguide\/","https:\/\/www.youtube.com\/firstsiteguide"]}]}},"_links":{"self":[{"href":"https:\/\/firstsiteguide.com\/wp-json\/wp\/v2\/tools\/4329"}],"collection":[{"href":"https:\/\/firstsiteguide.com\/wp-json\/wp\/v2\/tools"}],"about":[{"href":"https:\/\/firstsiteguide.com\/wp-json\/wp\/v2\/types\/tools"}],"author":[{"embeddable":true,"href":"https:\/\/firstsiteguide.com\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/firstsiteguide.com\/wp-json\/wp\/v2\/comments?post=4329"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/firstsiteguide.com\/wp-json\/wp\/v2\/media\/7959"}],"wp:attachment":[{"href":"https:\/\/firstsiteguide.com\/wp-json\/wp\/v2\/media?parent=4329"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}