Aardwolf Security Scanner Wordpress Plugin - Rating, Reviews, Demo & Download
Plugin Description
Aardwolf Security Scanner runs a battery of passive, read-only checks against
your own WordPress site — the same low-hanging fruit a penetration tester looks
for first — and gives you a prioritised, plain-English list of what to fix and
how.
It does not attack your server, exploit anything, or send any data off-site.
Every check runs locally on your own install.
What it checks
- Software updates — outdated WordPress core, plugins and themes, plus dormant/inactive extensions that widen your attack surface.
- Accounts & authentication — the default
adminusername, username enumeration via author archives and the REST API, insecure registration defaults, and missing login brute-force protection. - Configuration hardening — the dashboard file editor, exposed debug output, missing/placeholder security keys and salts, the default
wp_table prefix, and forcing HTTPS on the admin area. - Information exposure — a reachable XML-RPC endpoint, the version-leaking
readme.html, the generator meta tag, directory browsing, and sensitive files (debug logs,.git,.env, config backups) left in the web root. - HTTP security headers — missing
X-Frame-Options,X-Content-Type-Options,Referrer-Policy,Content-Security-Policyand HSTS. - Transport & environment — sites still on plain HTTP and end-of-life PHP versions.
- File permissions — world-readable/writable
wp-config.phpand root directory. - Known vulnerabilities — installed plugins that have been removed from the WordPress.org directory (often a sign a plugin was pulled for an unresolved security issue).
Each finding comes with a severity rating and a specific, actionable remediation.
Scheduled scans & email alerts
Run scans automatically in the background (daily or weekly via WP-Cron) and get
an email when your security posture regresses — the score drops, problems
increase, or a high-risk issue appears. You can also choose to be emailed after
every scheduled scan.
Export reports
Export the latest scan as a CSV file, or open a clean, print-styled PDF
report that you can save or share (uses your browser’s “Save as PDF”).
About Aardwolf Security
This plugin is provided by Aardwolf Security.
Automated checks are a great first line of defence, but they are not a
substitute for a manual penetration test by a qualified assessor.
External services
This plugin connects to one external service, the official WordPress.org Plugin API (https://api.wordpress.org/plugins/info/1.0/).
- What it is used for: the “Known Vulnerabilities” check queries this API to find out whether any of your installed plugins have been removed/closed on the WordPress.org directory (which often indicates a plugin was pulled for an unresolved security issue).
- What data is sent, and when: the directory slug of each installed plugin (e.g.
akismet) is sent when a scan runs. No personal data, site content, or credentials are transmitted. Responses are cached for 24 hours to minimise requests. - Terms & privacy: this is a WordPress.org service, governed by the WordPress.org Terms and Privacy Policy.
The plugin also makes loopback HTTP requests to your own site (its own URL) to inspect response headers and check for publicly exposed files. These stay on your own server and are not sent to any third party.
Screenshots
No screenshots provided
