Free · Detect & harden

WP Security Ninja

See what's risky on your WordPress site in one run

Security Tests check 50+ common hardening gaps, from outdated plugins to readme.html version disclosure and exposed config files. You get a weighted score, clear pass and fail counts, and fix guidance on every result.

  • ✓ 50+ hardening checks
  • ✓ Weighted security score
  • ✓ Fix steps on every test
Security test summary showing passed, warning, failed counts and overall score percentage

How it works

A checklist with answers, not just red flags

Run the tests once and you get a prioritized view of what needs attention, plus plain-language guidance for each finding.

  1. Run the tests

    One click from Security Ninja. The Install Wizard can start them in the background on a fresh install.

  2. See your score

    A weighted percentage plus Passed, Warning, and Failed counts. Filter the list to focus on what matters.

  3. Open Details

    Every result explains the risk, why it matters on WordPress, and what to change. Most fixes are manual steps you can follow today.

Things tests catch that are easy to miss

These show up on real sites every week. Tests flag them so you can decide what to fix first.

  • ✓ A user still named admin with full privileges
  • ✓ Anyone can register left enabled on a site that does not need it
  • ✓ Public readme.html version disclosure in the WordPress root
  • ✓ Full WordPress version visible in page source
  • ✓ A wp-config.php backup file sitting in the web root
  • ✓ Missing security headers you can add without breaking the site
When issues are found
Security test list showing failed checks for core updates, plugins, and configuration

What gets checked

50+ tests across the things attackers actually probe

Not a generic scan. These checks target real WordPress misconfigurations that show up on hacked and neglected sites.

Software you run

Outdated code is the easiest way in.

Secrets and config

Small wp-config mistakes cause big problems.

wp-config.php permissions and location

Checks file rights and whether the config file sits where it should.

Database prefix and password strength

Warns about default wp_ prefixes and weak database credentials.

What attackers can learn

Information disclosure helps targeted attacks.

Browsable uploads and backup files

Finds wp-config.php.bak, .sql dumps, phpinfo.php, and other files that should not be public.

Server and headers

Hosting settings and HTTP headers matter too.

Security headers

HSTS, CSP, X-Frame-Options, Referrer-Policy, and Permissions-Policy when your host allows them.

Your security score is not a mystery number

The score weighs each test by impact, so a failed core update counts more than a minor header warning. Passed, Warning, and Failed counts give you a quick read before you dig into Details.

  • ✓ Weighted percentage reflects real risk, not just pass/fail tallies
  • ✓ Filter by Failed, Warning, Passed, or Untested
  • ✓ Re-run after fixes to track improvements
Understanding your score
Security test results summary with passed, warning, failed counts and overall score

Every failed test comes with a plan

Click Details on any result and you get context: what the test checked, why it matters, and steps to fix it. Warnings often mean review this, not panic. Some items depend on your host, and the guidance says so.

  • ✓ Plain-language explanations, not error codes
  • ✓ Manual fix steps included free on every test
  • ✓ Docs for common failures when you need more depth
Browse test docs
Expanded security test showing fix guidance and Details panel for a WordPress core update check

Pro when you want fixes faster

The full test suite is free on Free and Pro. Pro adds one-click Auto Fixer on many failing tests, a Fixes settings page for headers and hardening toggles, and scheduled re-runs so you catch regressions.

  • ✓ Auto Fixer applies safe changes without editing files by hand
  • ✓ Fixes page for security headers, XML-RPC, editors, and more
  • ✓ Schedule test runs with Pro Scheduled Scanner
Pro fixes docs
Security test with Apply Fix button for one-click hardening on Pro

Free vs Pro

Same tests on Free and Pro. Pro adds speed.

Every install gets the full audit, scoring, and manual fix guidance. Upgrade when you want one-click fixes and scheduled re-runs.

Forever free

Free

The complete security test suite, included with the WordPress.org plugin.

  • All 50+ security tests
  • Weighted security score
  • Details and manual fix steps on every test
  • AI Security Advisor context on supported WordPress versions
Download Free

Save time fixing

Pro

Everything in Free, plus tools that turn results into actions faster.

  • Everything in Free
  • One-click Auto Fixer on many failing tests
  • Fixes settings page for headers and hardening toggles
  • Scheduled test runs with Scheduled Scanner
See Pro pricing

Customer reviews

4.9 / 5 from 261 reviews

Leave a review

Very helpful

“Security Ninja is part of my arsenal that I offer to my clients. It helps make sure their websites are security and scans them for malware.”

Chaz B.Chaz B.

No WordPress plugin should be your entire security stack, but this one is a solid choice to be a key part of it.

“I've been a web host and sysadmin for 15 years. I'm skeptical when it comes to security tools, and many of them out there are either bogged down bloatware, don't do enough, or try…”

apooleyapooley

Fast security audit with one-click fixes, but use judgment

“I installed WP Security Ninja on my own WordPress website, ran a scan, and fixed several real issues in under an hour.”

davenelsondavenelson

Great offering

“My Wordpress site had recently been compromised even when I had a scanning plugin that was supposed to detect malware.”

coachcharlescaincoachcharlescain

See all 261 reviews

Frequently asked questions

What is WordPress readme.html version disclosure? +

WordPress ships a readme.html file in the site root. When it stays public, anyone can open it and often learn which WordPress version you run. That is version disclosure. Attackers use it to pick known exploits for that release. Security Tests checks whether readme.html is reachable over HTTP.

Is exposing readme.html dangerous? +

It is not a remote code execution bug by itself. It still helps targeted attacks by confirming you run WordPress and which core version is present. Removing or blocking readme.html is a standard hardening step alongside hiding version tags in page source.

How do I remove or block WordPress readme.html? +

Delete readme.html from the WordPress root (same folder as wp-config.php) via FTP or your host file manager, or block HTTP access with server rules. On Pro, the Remove Unwanted Files fix can clear readme.html and similar leftover files in one step. Full steps: secure or remove readme.html in the Security Tests docs.

Are all security tests free? +

Yes. Free and Pro run the same 50+ tests with the same scoring and Details guidance. Pro adds one-click Auto Fixer, the Fixes settings page, and scheduled re-runs.

Do I need 100% to be safe? +

No. A perfect score is rare and not always realistic. Warnings often mean review this, not drop everything. Read Details for each result and fix high-impact failures first. See our guide on security issues were found.

Do tests fix issues automatically? +

Free includes manual fix steps on every test. Pro can apply many fixes with one click through Auto Fixer. Some changes still need a host, developer, or deliberate choice on your part.

What do security tests not cover? +

Tests check configuration and hardening, not live malware or incoming attack traffic. For file-level threats use the Pro malware scanner. For blocking bad visitors use Cloud Firewall and login protection.

How often should I re-run tests? +

After plugin updates, config changes, or when you inherit a site. Pro can schedule recurring test runs with Scheduled Scanner and include results in email reports.

Where do I read about a specific failure? +

Click Details in the plugin, or browse the Security Tests docs hub. We have individual articles for common failures like readme.html version disclosure, open registration, and default admin users.

Install free. Run your first audit today.

Download from WordPress.org, run the tests, read Details on anything that fails, and upgrade to Pro when you want one-click fixes.

Try Free

Larger screenshot

Enlarged image