Modules
WordPress security scan
Detect WordPress and review public identity, XML-RPC, login and cron exposure from one verified domain.
Check the WordPress surface that stays public
VICE confirms the CMS before testing user enumeration, XML-RPC behavior, the default login path and public cron.
Evidence, not vibes
Every finding keeps its raw evidence next to the remediation, so you can verify the problem is real before you fix it.
Audits on a schedule
Weekly or monthly runs keep the score fresh and catch regressions while you sleep.
01
CMS detection
Confirms WordPress from page and public asset markers.
02
User exposure
Checks author redirects and the public REST users endpoint.
03
XML-RPC exposure
Detects reachable XML-RPC behavior that can amplify password attempts.
04
Login and cron
Reviews the default login path and public HTTP cron exposure.