Безкоштовний інструмент, обліковий запис не потрібен

Free WordPress Security Configuration Checker

Check eight externally observable WordPress configuration areas: XML-RPC, wp-login.php, debug leakage, directory listing, version disclosure, security headers, REST user enumeration, and sensitive public paths.

Також відомий як: WordPress hardening checker, XML-RPC and REST API test
Докази, показані з джереломОбліковий запис не потрібенНемає вигаданих метрик

Запустіть реальну перевірку вище

Надішліть публічну URL-адресу, домен або ключове слово. Novaverb покаже лише ті докази, які цей інструмент може насправді отримати або виміряти.

Модель доказів

Знайте, що доводить результат

This check captures public HTTP evidence for eight WordPress configuration areas: XML-RPC, the standard login path, debug leakage, directory listing, version disclosure, six response headers, REST API user enumeration and selected sensitive paths. It keeps each observation separate and publishes no general security score.

1. Джерело

Bounded live HTTP observations from the submitted public WordPress origin. Результат вказує, звідки походять його докази.

2. Межа

This is a non-intrusive configuration review of selected public HTTP responses. It does not test passwords, exploit vulnerabilities, enumerate plugins, or prove that a WordPress site is secure.

3. Наступна дія

Використовуйте знахідку для перевірки проблеми, а потім підключіть робочий простір, коли вам потрібна історія, моніторинг або аналіз всього сайту.

How to read this WordPress configuration result

Observation, not exploitation

The checker recognizes selected public response signatures. It sends no attack payload, login attempt, password test or component enumeration request.

No composite security score

Each of the eight areas stands on its own evidence. A clean header result cannot cancel an exposed debug log, and an unavailable response never becomes a pass.

Fix, deploy, re-check

Prioritize exposed logs and sensitive files, then public user enumeration and unnecessary endpoints. Re-run the exact check after deploying each configuration change.

Отримайте правильну відповідь

Що подати - і чого уникати

Submit a public WordPress domain or any URL on that site. The checker normalises the address to the final public origin before requesting WordPress paths. Private and reserved targets are refused, and the result may say WordPress was not confirmed when the site hides or changes all recognizable public signals.

Використовуйте це так
your-wordpress-site.comA public WordPress domain works, and the checker normalizes the address before the bounded requests.
https://www.your-wordpress-site.com/blogA full page URL works too; WordPress configuration paths are checked at the final public origin.
Уникати це
localhost / 10.0.0.8Private and internal targets are refused by the public-IP safety boundary.
Expecting a vulnerability scanThis tool checks selected public configuration evidence only; it does not exploit, authenticate, or enumerate installed components.
Публічна методологія

Саме так цей результат виробляється

Every request passes through the public-IP safety boundary and every redirect target is checked again. The checker recognizes specific response signatures rather than treating every HTTP 200 as exposure, runs a bounded set of paths, and discards raw response bodies before the result is stored or displayed.

  1. Ми отримуємо подану публічну адресу через перевірку безпеки з прив'язкою IP та повторно перевіряємо кожне місце перенаправлення.
  2. We request a bounded WordPress path set and recognize exact login, XML-RPC, REST, directory-index, debug and sensitive-file signatures.
  3. We read the homepage for WordPress version signals and six selected browser security headers.
  4. We discard raw response bodies and report eight named configuration observations without creating a composite security score.
Побудовано на публічних стандартах

Міжнародні стандарти, до яких застосовується ця перевірка

WordPress documentation defines XML-RPC and REST API behavior, while RFC 9110 defines the HTTP responses observed. The response-header section applies the selected OWASP Secure Headers set. These references describe configuration surfaces; none turns a public response into proof of a vulnerability.

OWASPSecure Headers
OWASP Secure Headers Project

Reports presence of the six selected response-header controls without claiming their policy values are complete.

Читати специфікацію
Ми перераховуємо стандарт лише там, де цей інструмент дійсно читає або вимірює його. Якщо сигнал знаходиться поза межами живої перевірки, результат говорить про це, а не натякає на охоплення.
Загальні запитання

WordPress Security Configuration Checker Часті запитання

What does the WordPress Security Configuration Checker inspect?

It observes eight public configuration areas: XML-RPC, wp-login.php, debug output, directory listing, WordPress version disclosure, six security headers, the REST API user endpoint, and selected sensitive WordPress paths.

Is this a WordPress vulnerability scanner?

No. The checker sends bounded public HTTP requests only. It does not exploit vulnerabilities, test passwords, enumerate plugins or themes, inspect source code, or look up known software vulnerabilities.

Should XML-RPC always be disabled?

Not always. XML-RPC can support publishing clients, integrations and pingbacks. If nothing you use needs it, restrict or disable it; if it must stay public, protect it with rate limiting and monitoring.

Is a public wp-login.php page automatically insecure?

No. The standard login page is normally public, so reachability is a review item rather than proof of a defect. Use strong passwords, multi-factor authentication, rate limiting and monitoring instead of relying on a hidden URL.

How does the checker detect exposed WP_DEBUG output?

It looks for recognizable PHP and WordPress error signatures in the captured homepage and public debug.log response. It never displays or stores the raw log or configuration-file contents.

What counts as WordPress directory listing?

The checker requests selected wp-content directories and looks for an actual generated index page, such as an Index of page with a parent-directory listing. A normal application response is not labeled as directory listing.

How can WordPress disclose its version?

A page can disclose a WordPress version through its generator metadata. Removing that metadata reduces easy fingerprinting, but installing security updates remains the important control.

Is the WordPress REST API unsafe?

No. The REST API is a normal WordPress feature. The relevant observation is whether the public users endpoint returns account identifiers; the checker reports REST availability and user enumeration separately.

Which sensitive WordPress paths are checked?

The bounded path set covers the public readme and license files, the install and setup screens, debug.log, and one common wp-config.php backup name. Only recognized content is labeled exposed, and raw sensitive content is discarded.

Does a clean configuration result prove the site is secure?

No. It only means the selected public observations did not show those configuration exposures at that moment. Plugin vulnerabilities, authorization flaws, malware, weak accounts and server-side issues require separate authorized testing.

Більше безкоштовних перевірок

Досліджуйте всі безкоштовні інструменти Novaverb

SEO перевірник сайтуПокриття обходу, індексовані сторінки та внутрішні посилання
Інструмент дослідження ключових слівПеревірте доступний обсяг пошуку точного запиту, складність ключового слова та …
Перевірка SERPПеревірка повернених органічних результатів для ключового слова та країни, включаючи …
Перевірник безпеки сайтуАудит безпеки вебсайту, сертифікатів TLS/SSL, заголовків безпеки HTTP та відкритих …
Перевірка часу відповіді сервераВимірюйте час сервера до першого байта (TTFB), DNS-запит, TCP-з'єднання та …
Перевірка зворотних посиланьДосліджуйте зворотні посилання, посилаючі домени, dofollow посилання та авторитет домену …
Перевірка robots.txtТестуйте та перевіряйте правила robots.txt, директиви User-Agent, заблоковані шляхи та …
Перевірка карти сайтуВідкрийте декларації карти сайту, перевірте кореневий документ і отримайте обмежену …
Перевірка мета-тегівПеревірте довжину заголовка сторінки, метаопису, структуру заголовка H1, соціальні теги …
Перевірка статусу HTTP та перенаправленьВідстежуйте коди статусу HTTP (200, 301, 302, 404, 500) та …
Монітор сайтуЗапустіть одну перевірку доступності в реальному часі та збережіть зразок …
Тест HTTP/2Перевірте, чи точний поданий ім'я хоста веде переговори про HTTP/2 …
Тест HTTP/3Перевірте, чи ваш веб-сервер підтримує HTTP/3 через QUIC з живим …
Тест продуктивності веб-сайтуПорівняйте час відповіді HTTP з доступних місць перевірки та перевірте …
GEO CheckerПеревірка спостережуваних сигналів сторінки, які підтримують отримання, витяг відповідей, атрибуцію …
Перевірник основних веб-показниківПеревірте 75-й процентиль реальних користувачів LCP, INP та CLS з …
Перевірка PageSpeedЗапустіть один аудит лабораторії Lighthouse для перевірки продуктивності, доступності, найкращих …
Перевірка безпеки сайтуПеревірте, чи домен або URL позначено за шкідливе ПЗ, фішинг …
Перевірка Knowledge GraphШукайте відповідні сутності для бренду, особи, продукту або організації та …
Перевірка прогалин у ключових словахЗнайдіть ключові слова для ранжування, які спостерігалися для конкурента, але …
Топ-сторінки конкурентаЗнайдіть сторінки з найвищим оціненим органічним трафіком в доступному індексі …
Переглянути повний центр безкоштовних інструментів
Перевірте → зрозумійте → виправте

Перетворіть цю перевірку на перевірене виправлення

Кожен безкоштовний інструмент Novaverb - це одна воронка: проведіть перевірку, зрозумійте докази, потім виправте це і доведіть, що проблема вирішена, з новою перевіркою - без вигаданих станів проходження.