Free tool · Security
WordPress Vulnerability Scanner
The WordPress vulnerability scanner looks for public software information and checks identifiable versions against available vulnerability records. Enter your site address to find a practical starting point for a security review.
Free WordPress vulnerability scan
Free to use without an account. View the result here and choose whether to receive it by email.
What the tool covers
Investigate exposed software versions
Public WordPress, plugin and theme clues, with possible known vulnerability matches and linked record identifiers where the available sources provide them.
Public WordPress signals
The submitted page is checked for visible WordPress information, including a core version when the page discloses one.
Plugin and theme clues
Asset addresses can reveal software identifiers and version hints. Only components visible in the public page can contribute to this check.
Known vulnerability matches
Available versions are compared with vulnerability sources. The report highlights at most one finding per plugin, prioritising the highest reported severity, with an advisory link when available.
Gaps in the evidence
Missing versions and incomplete provider coverage stay visible as limitations. An unavailable check is not converted into a clean security result.
Understand the limits
Hidden software and missing versions remain unverified. A clear result does not establish that a site is secure or free of malware.
Understanding your result
Turn a vulnerability finding into a useful next step
Public evidence helps you decide where to investigate. Confirm the software and release inside WordPress before treating an external match as an issue on your installation.
A possible match needs confirmation
Compare the reported identifier and version with your installed software, then read the linked advisory's affected releases. A cached asset or version-like query string can give an outdated clue.
No matches covers the checked evidence
A zero count applies to the versions and vulnerability records available to this scan. Continue checking your complete plugin inventory and maintaining backups, updates and account access.
Limited visibility calls for an internal review
Use the Plugins screen and your host's information to fill gaps that the public page cannot resolve. For a known plugin release, the separate vulnerability lookup avoids relying on asset detection.
Start with the software visitors can see
A public page can reveal WordPress or plugin information through its source and loaded files. The scanner reads these clues without logging in, installing anything or trying to exploit the website. Version clues need confirmation against your WordPress dashboard before you act on a match.
Use a match to plan the next step
Each plugin has at most one highlighted finding, selected by the highest severity supplied by the sources. The total still includes other matching advisories, so a plugin can have more issues than its single finding shows. Follow the credited advisory, confirm the installed version in WordPress and review the developer's fix guidance. Take a current backup and test the available update on staging before changing the live site.
Read incomplete coverage carefully
A site can hide a plugin version, serve cached files or block requests from automated checks. Those gaps stay unknown. The report cannot examine private files, stolen accounts or changes inside the database, so unexplained redirects and unfamiliar administrators still need investigation.
Questions about this tool
What does this WordPress vulnerability scanner check?
It reads public WordPress software clues and matches identifiable versions with available known vulnerability records. The result separates detected issues from information the scanner could not verify.
Can it find every vulnerable plugin?
No. Plugins without public clues and components with hidden versions cannot be fully assessed. Confirm your installed inventory inside WordPress and use the plugin vulnerability lookup for a component you already know.
Does a clear scan mean my site has no malware?
No. Known software vulnerabilities and malware are different problems. This external check cannot inspect all private files, accounts or database content.
Will the scan change my WordPress site?
No. It reads public information without logging in, installing software or exploiting a suspected issue.
Can I receive the vulnerability result by email?
Yes. Start the scan and use the optional email form to receive its result. You can also read the result on this page without creating an account.
Free website widget
Add this tool to your website
Let visitors use the WordPress Vulnerability Scanner on your own page, including the option to email their results. Copy the code into an Elementor HTML widget or a WordPress Custom HTML block, then preview the published page.
Get the embed code
The widget fits the width of its container. Increase the height value if you want more of the report visible at once; longer results can be scrolled inside the widget.
BugShield hosts and runs the tool. Results and email addresses stay inside the widget and are not shared with the page embedding it. If your editor removes the code or your site blocks external widgets, ask your website administrator to allow frames from bugshield.co.uk.
Need help with the next step?
A BugShield developer can review the findings and help you decide what your WordPress site needs.
Explore WordPress support