WordPress security scanner
Check TLS, headers, DNS, email auth, and exposure signals on your live domain.
WordPress sites face constant scrutiny from the outside. RedScore runs a passive scan on your domain in about 60 seconds and ranks what matters first. No plugin install, no wp-admin access, and no invasive testing.
Scan your domainFree scan · No signup · Results in ~60 seconds · Opens /lookup
example-corp.com
✓ scan complete · grade D · 4 issues
AI summary
DMARC enforcement is missing, which leaves spoofing open. SPF is too permissive. Several key web security headers are absent.
Why WordPress sites need an outside-in scan
Weak TLS, missing headers, poor email auth, and exposed services are visible to anyone checking your domain. RedScore collects those signals into one score so you know what to fix first.
Built for WordPress sites
RedScore scans your live domain from the outside. It does not access wp-admin or scan installed plugins.
Use /lookup to check your domain. Nothing to install on your WordPress host.
Certificate health and security headers visible on your live site.
SPF, DMARC, and DNS records that affect trust and deliverability.
Plain-English guidance on which public gaps to close first.
What you get
Your scan returns a 0-100 RedScore, grades across ten security areas, and a short summary of public findings on your live site.
63 / 100
Grade C
example-corp.com
AI summary
Cookie settings are weak and server headers reveal stack details. Email spoofing is plausible with incomplete SPF and DMARC.
What RedScore checks today
This is not a WordPress plugin vulnerability scan, wp-admin review, or authenticated penetration test. It checks the public security signals visible on your domain from the internet.
After the free scan
Free scans show your score and category breakdown. Claim your site to unlock complete findings, scheduled rescans, and alerts when public posture changes.
FAQ
Free scan · No signup · ~60 seconds
Scan your domain