Skip to main content
UNPWNED
WordPress Security Guide
Q&AWordPress

How to check if my WordPress site is vulnerable?

Check that WordPress core, all plugins, and themes are running the latest versions. Look for exposed sensitive files like wp-config.php, debug.log, and database backups. Verify that directory listing is disabled on /wp-content/uploads/ and /wp-content/plugins/. Test whether XML-RPC is accessible and user enumeration is possible through the REST API. Check for security headers in your HTTP responses. Verify that your login page has brute-force protection. UNPWNED automates bounded outside-in component-CVE, sensitive-path, XML-RPC, user-enumeration, header, exposure, dependency, endpoint, rate-limit, and configuration checks. It does not prove complete WordPress, plugin, login, or application security.

Check your WordPress app now

Run free security scan

Last reviewed: 2026-04-07. Based on publicly available security research and UNPWNED scan telemetry.