Free tool

Check your WordPress attack surface

See which WordPress surfaces your website exposes publicly — in seconds and without installing anything.

We only inspect publicly accessible website information. No login attempts, exploitation or intrusive security testing.

What this checks

Publicly reachable endpoints

wp-login.php, the REST API, XML-RPC — whether each one is publicly reachable, redirected, or hidden.

Fingerprinting

Generator tags, wp-content/wp-includes paths, and other metadata that identifies WordPress to automated scanners.

Headers & caching

Revealing server/version headers, security headers, and whether your frontend already looks statically served.

A before/after estimate

What your exposure could look like with WP Static Shield's Zero-WordPress isolation applied.

This remote check analyses only publicly accessible website information. It is not a vulnerability scan, penetration test or guarantee of security. Results are estimates and may be affected by caching, firewalls, proxies and site configuration.