New 24/7 monitoring and daily cloud backups now included in every Shield Pro plan.

Free tool · Security

WordPress Vulnerability Scanner

The WordPress vulnerability scanner looks for public software information and checks identifiable versions against available vulnerability records. Enter your site address to find a practical starting point for a security review.

Free WordPress vulnerability scan

Enter your website URL and we will check visible WordPress software for possible matches with known vulnerabilities.

Free to use without an account. View the result here and choose whether to receive it by email.

What the tool covers

Investigate exposed software versions

Public WordPress, plugin and theme clues, with possible known vulnerability matches and linked record identifiers where the available sources provide them.

Public WordPress signals

The submitted page is checked for visible WordPress information, including a core version when the page discloses one.

Plugin and theme clues

Asset addresses can reveal software identifiers and version hints. Only components visible in the public page can contribute to this check.

Known vulnerability matches

Available versions are compared with vulnerability sources. The report highlights at most one finding per plugin, prioritising the highest reported severity, with an advisory link when available.

Gaps in the evidence

Missing versions and incomplete provider coverage stay visible as limitations. An unavailable check is not converted into a clean security result.

Understand the limits

Hidden software and missing versions remain unverified. A clear result does not establish that a site is secure or free of malware.

Understanding your result

Turn a vulnerability finding into a useful next step

Public evidence helps you decide where to investigate. Confirm the software and release inside WordPress before treating an external match as an issue on your installation.

A possible match needs confirmation

Compare the reported identifier and version with your installed software, then read the linked advisory's affected releases. A cached asset or version-like query string can give an outdated clue.

No matches covers the checked evidence

A zero count applies to the versions and vulnerability records available to this scan. Continue checking your complete plugin inventory and maintaining backups, updates and account access.

Limited visibility calls for an internal review

Use the Plugins screen and your host's information to fill gaps that the public page cannot resolve. For a known plugin release, the separate vulnerability lookup avoids relying on asset detection.

Start with the software visitors can see

A public page can reveal WordPress or plugin information through its source and loaded files. The scanner reads these clues without logging in, installing anything or trying to exploit the website. Version clues need confirmation against your WordPress dashboard before you act on a match.

Use a match to plan the next step

Each plugin has at most one highlighted finding, selected by the highest severity supplied by the sources. The total still includes other matching advisories, so a plugin can have more issues than its single finding shows. Follow the credited advisory, confirm the installed version in WordPress and review the developer's fix guidance. Take a current backup and test the available update on staging before changing the live site.

Read incomplete coverage carefully

A site can hide a plugin version, serve cached files or block requests from automated checks. Those gaps stay unknown. The report cannot examine private files, stolen accounts or changes inside the database, so unexplained redirects and unfamiliar administrators still need investigation.

Questions about this tool

What does this WordPress vulnerability scanner check?

It reads public WordPress software clues and matches identifiable versions with available known vulnerability records. The result separates detected issues from information the scanner could not verify.

Can it find every vulnerable plugin?

No. Plugins without public clues and components with hidden versions cannot be fully assessed. Confirm your installed inventory inside WordPress and use the plugin vulnerability lookup for a component you already know.

Does a clear scan mean my site has no malware?

No. Known software vulnerabilities and malware are different problems. This external check cannot inspect all private files, accounts or database content.

Will the scan change my WordPress site?

No. It reads public information without logging in, installing software or exploiting a suspected issue.

Can I receive the vulnerability result by email?

Yes. Start the scan and use the optional email form to receive its result. You can also read the result on this page without creating an account.

Free website widget

Add this tool to your website

Let visitors use the WordPress Vulnerability Scanner on your own page, including the option to email their results. Copy the code into an Elementor HTML widget or a WordPress Custom HTML block, then preview the published page.

Get the embed code
Preview the widget

The widget fits the width of its container. Increase the height value if you want more of the report visible at once; longer results can be scrolled inside the widget.

BugShield hosts and runs the tool. Results and email addresses stay inside the widget and are not shared with the page embedding it. If your editor removes the code or your site blocks external widgets, ask your website administrator to allow frames from bugshield.co.uk.

Need help with the next step?

A BugShield developer can review the findings and help you decide what your WordPress site needs.

Explore WordPress support