For WordPress sites

Close the gaps WordPress sites get hit for

Bots scan millions of WordPress sites every day for the same handful of mistakes. Webforta finds them first from the outside, with an optional connector plugin for checks from inside the site.

  • wp-config backupsDetects readable wp-config.php.bak and similar copies that expose database passwords.
  • Version exposureFlags generator tags that reveal your exact WordPress version.
  • XML-RPCTells you when xmlrpc.php is reachable, a favourite for brute-force attacks.
  • Headers & cookiesChecks login cookies and security headers that themes and hosts often miss.
No plugin required to start

Outside-in, so it can't be disabled by an attacker

Scanning and monitoring run from outside your server, so a compromised site can't switch them off. For a look inside, add the optional Webforta Connector plugin: it reports modified core files, PHP files in uploads and suspicious code. Neither replaces keeping WordPress and plugins updated.

See what your website shows attackers

Start a 14-day trial, verify a domain and run your first scan in about ten minutes. No card required.