Get a broad overview
- What it checks
- Publicly visible software, known vulnerabilities, mobile performance, SEO, SSL and domain health.
- Keep in mind
- Software coverage may be partial when your hosting or security tools hide version details.
New 24/7 monitoring and daily cloud backups now included in every Shield Pro plan.
WordPress checks
Check public security, software, performance, SEO and AI readiness without installing a plugin. Choose a focused tool and get a useful next step.
All tools
Run a focused check for site health, AI readiness or a specific security issue without making changes to your website.
Performance & security
Run a free external scan for WordPress software vulnerabilities, performance, SEO, SSL, and domain health.
Scan your siteAI & discoverability
Automatically test whether AI agents can discover, read and interact with your WordPress website.
Check AI readinessSecurity
Check whether your site is vulnerable to XSS2Shell (CVE-2026-64638). Free, non-destructive, no install required.
Open checkerUse the right check
Start with what you want to find out. Compare what each check covers and how to read its results.
A starting point for better site care. These checks run without changing your website. Use them alongside regular updates, backups, access controls and monitoring, rather than as a complete security audit.
Tool FAQs
Understand what each check covers, what its result means and when a closer technical review is worthwhile.
Free WordPress tools are focused checks that help you investigate a website without paying for a report or starting a support plan. BugShield tools examine specific public security, software, performance, SEO, AI readiness, SSL and domain signals.
BugShield provides a WordPress site health scan, an automatic WordPress AI readiness checker and an XSS2Shell checker. New tools will be added to this library as useful checks become available.
No. The live scanners read public website signals from BugShield's server. A BugShield maintenance plan uses the WordPress plugin for deeper internal inventory and continuous monitoring.
Yes. The site health and AI readiness scans read public signals, while the XSS2Shell checker tests login-page behaviour. The tools do not upload plugins, edit the website or attempt to gain access.
The scan reviews publicly visible WordPress software for known vulnerabilities and checks mobile performance, SEO essentials, SSL and domain health. Some websites hide version details, so software coverage can be partial.
The site health scan can identify potential vulnerabilities when the website exposes enough plugin, theme, WordPress or PHP version information. Hidden versions and private server details cannot be confirmed through an external scan.
The XSS2Shell checker tests whether a WordPress login page shows the behaviour associated with CVE-2026-64638. It returns a vulnerable, not vulnerable or unknown result without carrying out the later attack steps.
The automatic checker reviews public discovery files, Markdown negotiation, AI crawler policies, standard agent protocol endpoints and optional commerce signals. It runs every supported test without changing the website.
A clear result only applies to the signals covered by that tool. An external check cannot inspect every private file, database record, account or server setting, so continue using updates, backups, access controls and ongoing security monitoring.
Keep the result, confirm that a current backup is available and review the recommended next step before changing the site. You can request a one-off fix when you need a developer to investigate and resolve a specific problem.
Yes. You can open a tool, enter the requested website address and review the core result online without creating a BugShield account. The site health scan also offers an optional email field while a result is being prepared.
Get a confirmed price and a BugShield developer for malware cleanup, urgent fixes, and ongoing WordPress care.
Request a fix