Aardwolf Security Scanner runs a battery of passive, read-only checks against
your own WordPress site — the same low-hanging fruit a penetration tester looks
for first — and gives you a prioritised, plain-English list of what to fix and
how.
It does not attack your server, exploit anything, or send any data off-site.
Every check runs locally on your own install.
admin username, username enumeration via author archives and the REST API, insecure registration defaults, and missing login brute-force protection.wp_ table prefix, and forcing HTTPS on the admin area.readme.html, the generator meta tag, directory browsing, and sensitive files (debug logs, .git, .env, config backups) left in the web root.X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Content-Security-Policy and HSTS.wp-config.php and root directory.Each finding comes with a severity rating and a specific, actionable remediation.
Run scans automatically in the background (daily or weekly via WP-Cron) and get
an email when your security posture regresses — the score drops, problems
increase, or a high-risk issue appears. You can also choose to be emailed after
every scheduled scan.
Export the latest scan as a CSV file, or open a clean, print-styled PDF
report that you can save or share (uses your browser’s “Save as PDF”).
This plugin is provided by Aardwolf Security.
Automated checks are a great first line of defence, but they are not a
substitute for a manual penetration test by a qualified assessor.
This plugin connects to one external service, the official WordPress.org Plugin API (https://api.wordpress.org/plugins/info/1.0/).
akismet) is sent when a scan runs. No personal data, site content, or credentials are transmitted. Responses are cached for 24 hours to minimise requests.The plugin also makes loopback HTTP requests to your own site (its own URL) to inspect response headers and check for publicly exposed files. These stay on your own server and are not sent to any third party.