WordPress security, made simple

Is your WordPress site exposed right now?

Run a passive scan against your own site and see what an attacker sees — outdated core, leaked headers, public user list. No account, no plugin, no payload sent.

scanng --passive
https://

Passive scan only. We request the same pages any visitor would.

Latest WordPress core vulnerabilities in our database

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint…2026-07-17WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly…2026-07-17WordPress Core, in versions up to 6.0.2, is vulnerable to Authenticated Stored Cross-Site…2024-10-16WordPress Core is vulnerable to Stored Cross-Site Scripting via user display names in the…2024-05-03WordPress is an open publishing platform for the Web2024-04-04WordPress is an open publishing platform for the Web2024-04-04WordPress does not properly restrict which user fields are searchable via the REST API,…2023-10-16Exposure of Sensitive Information to an Unauthorized Actor in WordPress from 6.3 through…2023-10-13Auth2023-10-13WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via…2023-05-17WordPress through 6.1.1 depends on unpredictable client visits to cause wp-cron.php execution…2023-01-05WordPress is affected by an unauthenticated blind SSRF in the pingback feature2022-12-14Cross-site scripting vulnerability in WordPress versions prior to 6.0.3 allows a remote…2022-12-05Improper authentication vulnerability in WordPress versions prior to 6.0.3 allows a remote…2022-12-05Cross-site scripting vulnerability in WordPress versions prior to 6.0.3 allows a remote…2022-12-05A flaw exists in Wordpress related to the 'wp-admin/press-this.php 'script improperly checking…2022-04-18WordPress is a free and open-source content management system written in PHP and paired with a…2022-01-06WordPress is a free and open-source content management system written in PHP and paired with a…2022-01-06WordPress is a free and open-source content management system written in PHP and paired with a…2022-01-06WordPress is a free and open-source content management system written in PHP and paired with a…2022-01-06WordPress before 5.8 lacks support for the Update URI plugin header2021-11-25WordPress is a free and open-source content management system written in PHP and paired with a…2021-09-09WordPress is a free and open-source content management system written in PHP and paired with a…2021-09-09WordPress is a free and open-source content management system written in PHP and paired with a…2021-09-09WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint…2026-07-17WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly…2026-07-17WordPress Core, in versions up to 6.0.2, is vulnerable to Authenticated Stored Cross-Site…2024-10-16WordPress Core is vulnerable to Stored Cross-Site Scripting via user display names in the…2024-05-03WordPress is an open publishing platform for the Web2024-04-04WordPress is an open publishing platform for the Web2024-04-04WordPress does not properly restrict which user fields are searchable via the REST API,…2023-10-16Exposure of Sensitive Information to an Unauthorized Actor in WordPress from 6.3 through…2023-10-13Auth2023-10-13WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via…2023-05-17WordPress through 6.1.1 depends on unpredictable client visits to cause wp-cron.php execution…2023-01-05WordPress is affected by an unauthenticated blind SSRF in the pingback feature2022-12-14Cross-site scripting vulnerability in WordPress versions prior to 6.0.3 allows a remote…2022-12-05Improper authentication vulnerability in WordPress versions prior to 6.0.3 allows a remote…2022-12-05Cross-site scripting vulnerability in WordPress versions prior to 6.0.3 allows a remote…2022-12-05A flaw exists in Wordpress related to the 'wp-admin/press-this.php 'script improperly checking…2022-04-18WordPress is a free and open-source content management system written in PHP and paired with a…2022-01-06WordPress is a free and open-source content management system written in PHP and paired with a…2022-01-06WordPress is a free and open-source content management system written in PHP and paired with a…2022-01-06WordPress is a free and open-source content management system written in PHP and paired with a…2022-01-06WordPress before 5.8 lacks support for the Update URI plugin header2021-11-25WordPress is a free and open-source content management system written in PHP and paired with a…2021-09-09WordPress is a free and open-source content management system written in PHP and paired with a…2021-09-09WordPress is a free and open-source content management system written in PHP and paired with a…2021-09-09

Four things an attacker checks first

The live scan runs exactly these, and nothing else. No payload, no brute force — only what any visitor can already see.

Header

Transport security

Missing HSTS leaves visitors open to downgrade attacks and session hijacking.

Header

Server disclosure

A talkative Server header hands an attacker your software and its version.

REST API

Public user list

The REST API happily lists your admin accounts unless it is locked down.

Database

Core version

The published version is matched against every known vulnerability affecting it.

A vulnerability database, not a checklist

Every scan is matched against the NIST National Vulnerability Database, expanded version by version and refreshed every night.

0

documented core vulnerabilities

0

WordPress versions mapped

2026-07-17

most recent entry, refreshed daily

Advanced web security insights

Unlock detailed reports and intuitive analysis for enhanced web security, regularly updated to stay current.

Dynamic analysis

Revolutionize web security testing with our dynamic page analysis approach, uncovering vulnerabilities in real-time unlike traditional version-based methods.

Security proven tools

Empower your web security with tools trusted by cybersecurity experts, ensuring comprehensive pentesting without the complexity.

Clear insight reports

Unlock easy-to-understand reports for non-technical audiences, simplifying complex security findings.

Continuous security updates

Stay ahead with regularly updated tools, ensuring cutting-edge security measures.

Three steps, no plugin to install

1

You give us a URL

Nothing to install, nothing to configure. Just the address of your site.

2

We look from the outside

Exactly what an attacker does first: headers, exposed endpoints, published version.

3

You get a readable report

Each finding comes with its impact and the fix, written for people who do not read CVE feeds.

Simple pricing, for everyone

Discover flexible pricing options for ScanNG's advanced web security solutions.

Basic

Perfect for blogs or personal websites.

$15/month

  • 1 scan every month
  • 1 website available
  • Email report
Book a demo
Most popular

Pro

Perfect for small and medium-sized enterprises.

$40/month

  • 1 scan every 2 weeks
  • 3 website available
  • Email report
Book a demo

Mission critical

Perfect for large companies or critical projects.

$100/month

  • 1 scan every week
  • 5 website available
  • Email report
Book a demo

Frequently asked questions

Find answers to commonly asked questions about our services, ensuring clarity and confidence in your web security journey.

ScanNG is your top choice for WordPress site security. We employ proven cybersecurity tools used by penetration testers to ensure your website stays protected from online threats. With ScanNG, security is simple and effective.

ScanNG conducts thorough security scans by simulating real-world attack scenarios on your WordPress site. We employ a combination of automated tools and manual testing techniques to ensure comprehensive coverage, including vulnerability detection in themes, plugins, and core WordPress files.

ScanNG is essential for safeguarding your WordPress site against cyber threats and potential data breaches. With the increasing complexity of cyber attacks, relying solely on manual security measures is insufficient. ScanNG automates the process, ensuring proactive identification and mitigation of security risks.

Unlike traditional security services, ScanNG offers a comprehensive solution tailored specifically for WordPress sites. Our platform is continuously updated with the latest threat intelligence, providing real-time protection against emerging vulnerabilities. Additionally, ScanNG provides intuitive dashboards and actionable recommendations for effortless security management.

Yes, ScanNG provides ongoing support to ensure the security of your WordPress site post-scanning. Our dedicated team of security experts offers assistance with vulnerability remediation, security best practices, and continuous monitoring to safeguard your website against evolving threats.

See a full report on your own site

Book a 20-minute demo: we run a complete scan on a site you own and walk you through every finding, live.

Book a demo