RedScore.ai

WordPress security scanner

Scan your WordPress site's public security posture

Check TLS, headers, DNS, email auth, and exposure signals on your live domain.

WordPress sites face constant scrutiny from the outside. RedScore runs a passive scan on your domain in about 60 seconds and ranks what matters first. No plugin install, no wp-admin access, and no invasive testing.

Scan your domain

Free scan · No signup · Results in ~60 seconds · Opens /lookup

example-corp.com

✓ scan complete · grade D · 4 issues

42/ 100
Grade D

AI summary

DMARC enforcement is missing, which leaves spoofing open. SPF is too permissive. Several key web security headers are absent.

FAILDMARC enforcement
FAILSPF policy strength
WARNWeb headers & TLS hardening
WARNCookie secure flag
PASSGoogle Safe Browsing

Why WordPress sites need an outside-in scan

Public misconfigurations show up before plugin issues do

Weak TLS, missing headers, poor email auth, and exposed services are visible to anyone checking your domain. RedScore collects those signals into one score so you know what to fix first.

Built for WordPress sites

Public posture check without installing anything

RedScore scans your live domain from the outside. It does not access wp-admin or scan installed plugins.

No plugin required

Use /lookup to check your domain. Nothing to install on your WordPress host.

TLS and headers

Certificate health and security headers visible on your live site.

DNS and email auth

SPF, DMARC, and DNS records that affect trust and deliverability.

Prioritized fixes

Plain-English guidance on which public gaps to close first.

What you get

One outside-in report for your WordPress domain

Your scan returns a 0-100 RedScore, grades across ten security areas, and a short summary of public findings on your live site.

C62DNS & Domain Security
D48Email Security
B75Infrastructure Hygiene
C68Web Application Security
F32Cookie & Privacy Hygiene
D45Technology Fingerprinting
B78Public Exposure
A91Certificate & PKI Health
B82Brand & Domain Reputation
C55Third-Party Risk Surface
63/ 100
Grade C

63 / 100

Grade C

example-corp.com

AI summary

Cookie settings are weak and server headers reveal stack details. Email spoofing is plausible with incomplete SPF and DMARC.

Email auth gaps
Header hardening
Certificate hygiene

What RedScore checks today

Public signals on your WordPress site

  • TLS and certificate health on your domain
  • Security headers visible on the live site
  • DNS and email authentication posture
  • Cookie and web application security signals
  • Public exposure and reputation indicators

What this does not replace

This is not a WordPress plugin vulnerability scan, wp-admin review, or authenticated penetration test. It checks the public security signals visible on your domain from the internet.

After the free scan

Claim your domain for full findings and monitoring

Free scans show your score and category breakdown. Claim your site to unlock complete findings, scheduled rescans, and alerts when public posture changes.

  • Full finding detail for your WordPress domain
  • Scheduled scans and change alerts
  • Remediation guides and trust reporting

FAQ

Common questions

Scan your WordPress site before someone else does

Free scan · No signup · ~60 seconds

Scan your domain