[ GF.dev ] All Tools →

WordPress Vulnerability Scan

WordPress sites are frequent targets. This scanner checks for exposed login pages (wp-login.php), user enumeration endpoints, and exposed readme files.

Ready to scan...

Frequently Asked Questions

Why should I hide wp-login?

Botnets aggressively target the default login page. Hiding or protecting it reduces server load and brute-force risk.

What is User Enumeration?

It is a technique hackers use to discover valid usernames on your site, which is the first step in a brute-force attack.

Learn More

The WordPress Security Hardening Checklist (Guide)
How to Scan Your WordPress Site for Known Vulnerabilities · The WordPress Security Hardening Checklist
WordPress Security Plugins vs Manual Hardening: What Actually Works · The WordPress Security Hardening Checklist
How Attackers Exploit Outdated WordPress Plugins (Real Examples) · The WordPress Security Hardening Checklist