Modules

WordPress security scan

Detect WordPress and review public identity, XML-RPC, login and cron exposure from one verified domain.

AUTHOR ROUTESREST USERSXML-RPCLOGIN + CRON

Check the WordPress surface that stays public

VICE confirms the CMS before testing user enumeration, XML-RPC behavior, the default login path and public cron.

Evidence, not vibes

Every finding keeps its raw evidence next to the remediation, so you can verify the problem is real before you fix it.

$ GET acme.dev/.env200 OK# .env · productionDATABASE_URL=••••••••••••STRIPE_SECRET_KEY=sk_live_51H…SUPABASE_SERVICE_ROLE=••••••RESEND_API_KEY=••••••••

Audits on a schedule

Weekly or monthly runs keep the score fresh and catch regressions while you sleep.

every monday86
01

CMS detection

Confirms WordPress from page and public asset markers.

02

User exposure

Checks author redirects and the public REST users endpoint.

03

XML-RPC exposure

Detects reachable XML-RPC behavior that can amplify password attempts.

04

Login and cron

Reviews the default login path and public HTTP cron exposure.

Resources