A WordPress security audit that shows you what is actually exposed
We run a public, read-only check of your site — WordPress version age, HTTPS/login exposure, exposed endpoints, redirect behavior — and send a prioritized fix list. No access needed. No plugins to install. You keep the report.
Why an audit first
The cheap insurance before a problem costs revenue.
WordPress runs a large share of the web, and most of it is silently behind on security. The sites that get compromised are rarely the ones that were watching — they're the ones where the core went past its patch window, the login stayed on plain HTTP, or an endpoint that should be private stayed public.
You do not need to wait for a Google warning or a host suspension to know where you stand. A 24–48h read-only audit names the specific gaps, rates their severity, and gives you a plain-language fix list — so the decision is about priorities, not panic.
WordPress age
Is your core past the maintained window or fully end-of-life? Known patch history matters.
HTTPS exposure
Does HTTP reach the login page? Mixed content? Certificate problems?
Exposed endpoints
XML-RPC, CLI/health paths, server header leaks, redirect chains.
What we check
Read-only, public, non-destructive — what a normal visitor's browser sees.
Our scanner makes ordinary public requests and reads what the server returns. It never logs in, never posts, never fuzzes, and never touches private hosts. Everything on the list is a verifiable signal:
- WordPress version + age verdict — past maintained window (>2.5y) or end-of-life (>4y) gets flagged with the patch risk explained
- HTTP → HTTPS redirect — a missing redirect means login and forms can still be served over cleartext
- TLS certificate validity — misconfiguration means browser warnings before you even engage
- Mixed content / forms over HTTP — real "your login page is over plain HTTP" findings
- XML-RPC + exposed CLI/health endpoints — common brute-force and persistence vectors
- Server header leaks + redirect chain + page weight — information disclosure and mobile speed signals
Each finding ships with a severity rating and a what to do about it. If you act on the fix list yourself, great. If you want it done, the same page points to scoped cleanup and hardening packages.
How it works
Three steps. No access, no plugins, no scare tactics.
Found something urgent in the report? Emergency WordPress cleanup targets a 48-hour turnaround after deposit and intake — see the CypherSecurity hub for packages.
Know where your site stands.
$49, 24–48h, report is yours to keep. If you'd rather go straight to a full cleanup or hardening, compare packages on the hub.