Free · no account

WordPress check

Paste an address and we detect WordPress from the outside, read its version and theme, and check a handful of common exposures.

We only fetch public URLs, like any visitor. Nothing is stored, no account required.

What the check shows

Everything is fetched from the outside – no plugin, no login to the site.

Version & theme

Whether it is WordPress, which version is running and the active theme.

Common exposures

readme, XML-RPC, user enumeration via REST and a public debug log.

Without touching the site

We only read public URLs – the same ones any visitor can reach.

See inside your WordPress, not just the outside

Ravnsight Detective catches errors and changes from within the site – and flags risky exposures.