RedScore.ai
All posts
Checklists

WordPress security scan checklist

Run this WordPress security scan checklist on your live domain first: TLS, headers, DNS, email auth, exposure, reputation. No plugin install.

1 min read · 2026-06-08 · RedScore Research Team

Quick answer

A WordPress security scan checklist starts with public posture on your live domain: TLS, headers, DNS, email authentication, exposure, and reputation. RedScore checks those signals from the outside in about 60 seconds. It does not scan wp-admin or plugin CVEs.

Why start with public posture on WordPress?

WordPress sites get hit constantly. Plugin drama matters, but strangers check the public stuff first: certificates, headers, DNS, email auth, exposed services.

Most site owners jump straight to plugin lists. That is backwards. Fix what the internet can already see in about 60 seconds, then worry about wp-admin hardening.

What is on the WordPress security scan checklist?

  1. TLS and certificate health on your primary domain.
  2. Security headers like HSTS, CSP, and clickjacking protections where visible.
  3. DNS hygiene, including dangling records and sloppy delegation.
  4. Email authentication with SPF, DKIM, and DMARC posture.
  5. Public exposure signals that should not be internet-facing.
  6. Reputation checks for blocklist or unsafe listings.

RedScore rolls these into one score and tells you what to fix first.

What does this checklist skip?

wp-admin reviews, plugin vulnerability databases, and authenticated penetration testing. Those are separate jobs.

This checklist is the free outside-in pass. Do it before you pay for heavier tooling.

How do I run it?

Go to /lookup, enter your live domain, and work the report top to bottom. The WordPress security scanner page explains what the outside-in pass covers.

Frequently asked questions

Does this checklist cover WordPress plugin CVEs?

No. Plugin CVE hunting needs different tooling. This checklist is the public footprint anyone can check without logging into your site.

Do I need a WordPress security plugin to run this scan?

No. Enter your domain. RedScore reads public signals only. Nothing to install on the host.

How often should I run this checklist?

Before launches, after DNS or hosting changes, and whenever you renew a security questionnaire. Claim the domain if you want scheduled rescans.

Will this work on managed WordPress hosts?

Yes. WP Engine, Kinsta, SiteGround, or any host with a public domain works the same way.

Run a free outside-in scan on your domain in about 60 seconds.

Scan domain