WordPress / CMS
WordPress exposure and configuration checks.
The WordPress / CMS tools collection brings together free checks for the things every WordPress owner has to stay on top of: security hardening, public exposure, and WooCommerce store configuration. Because WordPress powers such a large share of the web, it is a constant target for automated attacks, which makes it worth regularly reviewing items like wp-admin login protection, plugin and theme updates, file permissions, exposed xmlrpc and wp-json endpoints, and your WooCommerce payment and shipping flow. Whether you run a personal blog, a one-person online store, or a small business site, these tools let you catch the most important risks yourself without deep security expertise.
The usual workflow is straightforward. Start with the hardening checklist to confirm the basics such as logins, updates, and permissions, then use the exposure checks to see whether things like the wp-admin path, the REST API, or directory listings are needlessly visible to the outside world, and finally, if you sell online, run the WooCommerce checkout checklist to spot gaps in your payment, shipping, and cart setup. Rather than trying to fix everything at once, tackle the highest-risk findings first (admin passwords, missing security updates, publicly readable backups), then re-run the checks after each change to confirm things actually improved.