WordPress 7.1.2: critical core security fix. Update now, then check inactive themes and comments.

Details

Security tests

Fixed test results still fail

Why some Security Ninja tests still fail after a fix on local, maintenance, or password-protected sites.

Sometimes you apply a fix, re-run the scan, and the test still fails or reports that it could not determine the status.

This often happens on:

  • Local development sites on your computer
  • Sites with a maintenance or “coming soon” plugin
  • Password-protected staging sites

Some tests pretend to be a normal browser visitor. If anything blocks or redirects that request, the test cannot see the real public response and may fail.

Local setups also differ from production servers (self-signed SSL certificates, different file permissions, hosts-file URLs). Treat those failures as environment noise unless the same test fails on a publicly reachable production site.

SSL on local development

Self-signed certificates are common locally and are not trusted like a public Certificate Authority certificate. Tests that inspect HTTPS behavior can fail even when your local site “works” in the browser after you accept the warning.

Tests that often fail in those environments

  • Check if the expose_php PHP directive is turned off
  • Check if the uploads folder is browsable
  • Check if the admin interface is delivered via SSL
  • Check if readme.html is accessible
  • Check if license.txt is accessible
  • Check if install.php is accessible
  • Check if upgrade.php is accessible

Related: Maintenance and password-protected sites.

Still stuck? Get help or contact us.

Larger screenshot

Enlarged image