See which WordPress surfaces your website exposes publicly — in seconds and without installing anything.
We only inspect publicly accessible website information. No login attempts, exploitation or intrusive security testing.
wp-login.php, the REST API, XML-RPC — whether each one is publicly reachable, redirected, or hidden.
Generator tags, wp-content/wp-includes paths, and other metadata that identifies WordPress to automated scanners.
Revealing server/version headers, security headers, and whether your frontend already looks statically served.
What your exposure could look like with WP Static Shield's Zero-WordPress isolation applied.
This remote check analyses only publicly accessible website information. It is not a vulnerability scan, penetration test or guarantee of security. Results are estimates and may be affected by caching, firewalls, proxies and site configuration.