Security advisorywp2shell: WordPress core vulnerability. Confirm every site is on 6.8.6, 6.9.5, 7.0.2, or newer.

Read the advisory

Free · Detect & harden

WP Security Ninja

See what's risky on your WordPress site in one run

Security Tests check 50+ common hardening gaps, from outdated plugins to exposed config files. You get a weighted score, clear pass and fail counts, and fix guidance on every result.

  • ✓ 50+ hardening checks
  • ✓ Weighted security score
  • ✓ Fix steps on every test
Security test summary showing passed, warning, failed counts and overall score percentage

How it works

A checklist with answers, not just red flags

Run the tests once and you get a prioritized view of what needs attention, plus plain-language guidance for each finding.

  1. Run the tests

    One click from Security Ninja. The Install Wizard can start them in the background on a fresh install.

  2. See your score

    A weighted percentage plus Passed, Warning, and Failed counts. Filter the list to focus on what matters.

  3. Open Details

    Every result explains the risk, why it matters on WordPress, and what to change. Most fixes are manual steps you can follow today.

Things tests catch that are easy to miss

These show up on real sites every week. Tests flag them so you can decide what to fix first.

  • ✓ A user still named admin with full privileges
  • ✓ Anyone can register left enabled on a site that does not need it
  • ✓ Full WordPress version visible in page source
  • ✓ A wp-config.php backup file sitting in the web root
  • ✓ Missing security headers you can add without breaking the site
When issues are found
Security test list showing failed checks for core updates, plugins, and configuration

What gets checked

50+ tests across the things attackers actually probe

Not a generic scan. These checks target real WordPress misconfigurations that show up on hacked and neglected sites.

Software you run

Outdated code is the easiest way in.

Secrets and config

Small wp-config mistakes cause big problems.

wp-config.php permissions and location

Checks file rights and whether the config file sits where it should.

Database prefix and password strength

Warns about default wp_ prefixes and weak database credentials.

What attackers can learn

Information disclosure helps targeted attacks.

Browsable uploads and backup files

Finds wp-config.php.bak, .sql dumps, phpinfo.php, and other files that should not be public.

Server and headers

Hosting settings and HTTP headers matter too.

Security headers

HSTS, CSP, X-Frame-Options, Referrer-Policy, and Permissions-Policy when your host allows them.

Your security score is not a mystery number

The score weighs each test by impact, so a failed core update counts more than a minor header warning. Passed, Warning, and Failed counts give you a quick read before you dig into Details.

  • ✓ Weighted percentage reflects real risk, not just pass/fail tallies
  • ✓ Filter by Failed, Warning, Passed, or Untested
  • ✓ Re-run after fixes to track improvements
Understanding your score
Security test results summary with passed, warning, failed counts and overall score

Every failed test comes with a plan

Click Details on any result and you get context: what the test checked, why it matters, and steps to fix it. Warnings often mean review this, not panic. Some items depend on your host, and the guidance says so.

  • ✓ Plain-language explanations, not error codes
  • ✓ Manual fix steps included free on every test
  • ✓ Docs for common failures when you need more depth
Browse test docs
Expanded security test showing fix guidance and Details panel for a WordPress core update check

Pro when you want fixes faster

The full test suite is free on Free and Pro. Pro adds one-click Auto Fixer on many failing tests, a Fixes settings page for headers and hardening toggles, and scheduled re-runs so you catch regressions.

  • ✓ Auto Fixer applies safe changes without editing files by hand
  • ✓ Fixes page for security headers, XML-RPC, editors, and more
  • ✓ Schedule test runs with Pro Scheduled Scanner
Pro fixes docs
Security test with Apply Fix button for one-click hardening on Pro

Free vs Pro

Same tests on Free and Pro. Pro adds speed.

Every install gets the full audit, scoring, and manual fix guidance. Upgrade when you want one-click fixes and scheduled re-runs.

Forever free

Free

The complete security test suite, included with the WordPress.org plugin.

  • All 50+ security tests
  • Weighted security score
  • Details and manual fix steps on every test
  • AI Security Advisor context on supported WordPress versions
Download Free

Save time fixing

Pro

Everything in Free, plus tools that turn results into actions faster.

  • Everything in Free
  • One-click Auto Fixer on many failing tests
  • Fixes settings page for headers and hardening toggles
  • Scheduled test runs with Scheduled Scanner
See Pro pricing

Customer reviews

4.9 / 5 from 255 reviews

Leave a review

★★★★★

“I've tried most of the security plugins out there. Some are good but Security Ninja beats them all!”

Thomas Rosenstand

★★★★★

A Complete Security Powerhouse with White Label Flexibility and Outstanding Support

“I’ve been using WP Security Ninja with the 3-tier white label option, and I couldn’t be more impressed.”

Shujon

★★★★★

Very helpful

“Security Ninja is part of my arsenal that I offer to my clients. It helps make sure their websites are security and scans them for malware.”

Chaz B.

★★★★★

No WordPress plugin should be your entire security stack, but this one is a solid choice to be a key part of it.

“I've been a web host and sysadmin for 15 years. I'm skeptical when it comes to security tools, and many of them out there are either bogged down bloatware, don't do enough, or try…”

apooley

See all 255 reviews

Frequently asked questions

Are all security tests free?+

Yes. Free and Pro run the same 50+ tests with the same scoring and Details guidance. Pro adds one-click Auto Fixer, the Fixes settings page, and scheduled re-runs.

Do I need 100% to be safe?+

No. A perfect score is rare and not always realistic. Warnings often mean review this, not drop everything. Read Details for each result and fix high-impact failures first. See our guide on security issues were found.

Do tests fix issues automatically?+

Free includes manual fix steps on every test. Pro can apply many fixes with one click through Auto Fixer. Some changes still need a host, developer, or deliberate choice on your part.

What do security tests not cover?+

Tests check configuration and hardening, not live malware or incoming attack traffic. For file-level threats use the Pro malware scanner. For blocking bad visitors use Cloud Firewall and login protection.

How often should I re-run tests?+

After plugin updates, config changes, or when you inherit a site. Pro can schedule recurring test runs with Scheduled Scanner and include results in email reports.

Where do I read about a specific failure?+

Click Details in the plugin, or browse the Security Tests docs hub. We have individual articles for common failures like open registration, default admin users, and version disclosure.

Install free. Run your first audit today.

Download from WordPress.org, run the tests, read Details on anything that fails, and upgrade to Pro when you want one-click fixes.

Try Free