{"id":343921,"date":"2026-07-22T19:37:17","date_gmt":"2026-07-22T19:37:17","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/aardwolf-security-scanner\/"},"modified":"2026-07-25T12:37:41","modified_gmt":"2026-07-25T12:37:41","slug":"aardwolf-security-scanner","status":"publish","type":"plugin","link":"https:\/\/zh-sg.wordpress.org\/plugins\/aardwolf-security-scanner\/","author":23536486,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.2.6","stable_tag":"1.2.6","tested":"7.0.2","requires":"5.6","requires_php":"7.2","requires_plugins":null,"header_name":"Aardwolf Security Scanner","header_author":"Aardwolf Security","header_description":"Scans your WordPress site for common attack vectors covered in a penetration test and suggests configuration remediations to keep the bad guys out.","assets_banners_color":"001a68","last_updated":"2026-07-25 12:37:41","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"https:\/\/aardwolfsecurity.com\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":46,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.2.5":{"tag":"1.2.5","author":"aardwolfsec","date":"2026-07-22 19:37:05"},"1.2.6":{"tag":"1.2.6","author":"aardwolfsec","date":"2026-07-25 12:37:41"}},"upgrade_notice":{"1.2.6":"<p>Plain-language readme and updated directory tags. No functional changes.<\/p>","1.0.0":"<p>Initial release.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3619131,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3619131,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3619131,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3619131,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.2.5","1.2.6"],"block_files":[],"assets_screenshots":[],"screenshots":[]},"plugin_section":[],"plugin_tags":[31093,600,8642,138582,6460],"plugin_category":[54],"plugin_contributors":[272861],"plugin_business_model":[],"class_list":["post-343921","plugin","type-plugin","status-publish","hentry","plugin_tags-hardening","plugin_tags-security","plugin_tags-security-audit","plugin_tags-security-scanner","plugin_tags-vulnerability","plugin_category-security-and-spam-protection","plugin_contributors-aardwolfsec","plugin_committers-aardwolfsec"],"banners":{"banner":"https:\/\/ps.w.org\/aardwolf-security-scanner\/assets\/banner-772x250.png?rev=3619131","banner_2x":"https:\/\/ps.w.org\/aardwolf-security-scanner\/assets\/banner-1544x500.png?rev=3619131","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/aardwolf-security-scanner\/assets\/icon-128x128.png?rev=3619131","icon_2x":"https:\/\/ps.w.org\/aardwolf-security-scanner\/assets\/icon-256x256.png?rev=3619131","generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>Aardwolf Security Scanner checks your WordPress site for the security problems attackers look for first. It runs a set of read-only checks, gives each finding a severity rating, and tells you how to fix it in clear language.<\/p>\n\n<p>You can run a scan on demand or on a schedule. The plugin does not attack your server or change any files, and it does not send your data anywhere. Every check runs on your own install.<\/p>\n\n<h4>What it checks<\/h4>\n\n<ul>\n<li>Software updates. Outdated WordPress core, plugins and themes, plus inactive plugins and themes that still sit on disk.<\/li>\n<li>Accounts and authentication. The default \"admin\" username, username enumeration through author archives and the REST API, risky registration defaults, and missing brute-force protection on the login form.<\/li>\n<li>Configuration. The dashboard file editor, exposed debug output, missing or placeholder security keys and salts, the default \"wp_\" table prefix, and whether the admin area is forced over HTTPS.<\/li>\n<li>Information exposure. A reachable XML-RPC endpoint, the version-leaking readme.html, the generator meta tag, directory browsing, and sensitive files such as debug logs, .git, .env and config backups left in the web root.<\/li>\n<li>HTTP security headers. Missing X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Content-Security-Policy and HSTS.<\/li>\n<li>Transport and environment. Sites still on plain HTTP, and end-of-life PHP versions.<\/li>\n<li>File permissions. World-readable or world-writable wp-config.php and site root.<\/li>\n<li>Known vulnerabilities. Installed plugins that have been removed from the WordPress.org directory, which often means a plugin was pulled for an unresolved security issue.<\/li>\n<\/ul>\n\n<p>Each finding comes with a severity rating and clear steps to fix it. Every scan produces a security score out of 100 so you can track progress over time.<\/p>\n\n<h4>Scheduled scans and email alerts<\/h4>\n\n<p>Run a scan automatically once a day or once a week. The plugin can email you when the score drops, when the number of problems goes up, or when a high-risk issue appears. You can also choose to get an email after every scan.<\/p>\n\n<h4>Export reports<\/h4>\n\n<p>Save the latest scan as a CSV file, or open a clean printable report and save it as a PDF from your browser.<\/p>\n\n<h4>About Aardwolf Security<\/h4>\n\n<p>This plugin is made by <a href=\"https:\/\/aardwolfsecurity.com\/\">Aardwolf Security<\/a>. Automated checks are a good first line of defence, but they are not a replacement for a manual penetration test by a qualified tester.<\/p>\n\n<h3>External services<\/h3>\n\n<p>This plugin connects to one external service, the official WordPress.org Plugin API (https:\/\/api.wordpress.org\/plugins\/info\/1.0\/).<\/p>\n\n<ul>\n<li>What it is used for: the Known Vulnerabilities check asks this API whether any of your installed plugins have been removed from the WordPress.org directory.<\/li>\n<li>What data is sent, and when: the directory slug of each installed plugin (for example \"akismet\") is sent when a scan runs. No personal data, site content or credentials are sent. Responses are cached for 24 hours.<\/li>\n<li>Terms and privacy: this is a WordPress.org service, covered by the <a href=\"https:\/\/wordpress.org\/about\/\">WordPress.org Terms<\/a> and <a href=\"https:\/\/wordpress.org\/about\/privacy\/\">Privacy Policy<\/a>.<\/li>\n<\/ul>\n\n<p>The plugin also sends requests to your own site (its own URL) to inspect response headers and look for exposed files. These stay on your own server.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the aardwolf-security-scanner folder to \/wp-content\/plugins\/, or install the ZIP from Plugins, Add New, Upload Plugin.<\/li>\n<li>Activate the plugin from the Plugins screen.<\/li>\n<li>Open Security Scanner in the admin menu and click Run Security Scan.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"is%20it%20safe%20to%20run%20on%20a%20production%20site%3F\"><h3>Is it safe to run on a production site?<\/h3><\/dt>\n<dd><p>Yes. All checks are read-only. The plugin sends a few requests to your own site to inspect headers and look for exposed files, which is harmless. Keep a current backup before you change any settings, as good practice.<\/p><\/dd>\n<dt id=\"does%20it%20fix%20things%20automatically%3F\"><h3>Does it fix things automatically?<\/h3><\/dt>\n<dd><p>No. The scanner reports each problem and tells you how to fix it. You make the changes yourself, such as editing wp-config.php, adjusting file permissions, or updating settings.<\/p><\/dd>\n<dt id=\"why%20does%20a%20check%20say%20it%20could%20not%20complete%3F\"><h3>Why does a check say it could not complete?<\/h3><\/dt>\n<dd><p>Some checks send a request to your own site. If your host blocks these requests, those checks are skipped instead of failed, and the result explains what to check by hand.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.2.6<\/h4>\n\n<ul>\n<li>Rewrote the readme in plainer language and updated the tags for the plugin directory. No functional changes.<\/li>\n<\/ul>\n\n<h4>1.2.5<\/h4>\n\n<ul>\n<li>Printable report stylesheet is now registered and enqueued via wp_enqueue_style()\/wp_print_styles() instead of a hard-coded link tag.<\/li>\n<\/ul>\n\n<h4>1.2.4<\/h4>\n\n<ul>\n<li>Moved the printable report's CSS to a bundled stylesheet (no inline style tag) and removed the inline print-button script.<\/li>\n<li>Removed an unnecessary wp-admin\/includes\/plugin.php include in the login-protection check.<\/li>\n<li>Corrected the Contributors username.<\/li>\n<\/ul>\n\n<h4>1.2.3<\/h4>\n\n<ul>\n<li>Removed the duplicate Plugin URI header (it matched the Author URI); kept the Author URI.<\/li>\n<\/ul>\n\n<h4>1.2.2<\/h4>\n\n<ul>\n<li>Output all logos via escaped image tags for cleaner markup.<\/li>\n<li>Documented the WordPress.org Plugin API usage under a new \"External services\" readme section.<\/li>\n<\/ul>\n\n<h4>1.2.1<\/h4>\n\n<ul>\n<li>Resolved WordPress.org Plugin Check findings: removed the unused Domain Path header and the discouraged load_plugin_textdomain() call, rewrote the CSV export without direct filesystem functions, scoped template variables, tidied the uninstall routine, and updated \"Tested up to\".<\/li>\n<\/ul>\n\n<h4>1.2.0<\/h4>\n\n<ul>\n<li>Removed the optional WPScan API integration and the one-click hardening feature. These are planned for a future Pro add-on. The free directory-removal check, which needs no API key, remains.<\/li>\n<\/ul>\n\n<h4>1.1.1<\/h4>\n\n<ul>\n<li>Scheduled scans now let you choose the time of day, and the day of the week for weekly scans, in your site timezone.<\/li>\n<li>Fixed the oversized admin menu icon.<\/li>\n<li>Failed checks now show a problem-worded title (for example \"Usernames are publicly enumerable\") instead of the healthy-state wording.<\/li>\n<li>The user-enumeration check now tests the live vectors (REST users endpoint and the ?author= redirect) rather than stored user data.<\/li>\n<\/ul>\n\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>Added scheduled scans (daily or weekly) with email alerts on regression.<\/li>\n<li>Added CSV and printable PDF report export.<\/li>\n<li>Added a Known Vulnerabilities check.<\/li>\n<li>Bumped \"Tested up to\" and refreshed the settings screen.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release: security checks across six categories, a security score, and optional one-click hardening.<\/li>\n<\/ul>","raw_excerpt":"Free WordPress security scanner. Audit your site for vulnerabilities, weak settings and exposed files, with a clear fix for every issue found.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/zh-sg.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/343921","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zh-sg.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/zh-sg.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/zh-sg.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=343921"}],"author":[{"embeddable":true,"href":"https:\/\/zh-sg.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/aardwolfsec"}],"wp:attachment":[{"href":"https:\/\/zh-sg.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=343921"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/zh-sg.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=343921"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/zh-sg.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=343921"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/zh-sg.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=343921"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/zh-sg.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=343921"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/zh-sg.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=343921"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}