WordPress Security Scanner

WordPress Security Scanner is a tool operated by muurahainen.com. It checks publicly accessible parts of WordPress websites for exposed information and common security configuration issues.

If you found this page through a User-Agent string in your server logs, a website assessment may have been initiated using our scanner.

Current status: private testing

The service is currently in private testing and is not open for public use. Scans are initiated by the operator and are intended only for websites we own or have explicit permission to assess.

We are actively improving the scanner’s accuracy, reporting and compatibility with website security systems. Please contact us if you notice unexpected behaviour.

What the scanner does

The scanner makes a limited set of read-only HTTP requests. These may include requests to the homepage, standard WordPress endpoints and paths where configuration or backup files could accidentally be publicly accessible.

It checks for issues such as:

  • Publicly exposed version information and metadata.
  • Directory listings and potentially exposed configuration or backup files.
  • HTTP security headers and HTTPS redirects.
  • Information available through public WordPress endpoints.

The scanner does not attempt to log in, guess passwords, exploit vulnerabilities, upload files or modify the target website. It does not recursively crawl the website.

Request limits and protective measures

Within each scan, requests are processed sequentially, with at least two seconds between request starts. Each scan is limited to 60 outbound requests and a maximum duration of three minutes.

The scanner applies response-size limits and request timeouts. It stops further requests when it receives an HTTP 429 response, detects a blocking challenge page or encounters a request timeout. It does not attempt to solve or bypass browser security challenges.

A 401 or 403 response to an individual path is recorded as an access restriction; it does not necessarily stop the entire scan.

Identifying the scanner

Our scanner identifies itself using the WP-Surface-Checker product name in its User-Agent header. Versions that link to this page use the following format:

WP-Surface-Checker/<version> (+https://muurahainen.com/wordpress-security-scanner-agent)

Earlier test versions may use:

WP-Surface-Checker/0.2 (authorized closed test)

A User-Agent string can be copied by other software and is not proof that a request originated from us. If you need to verify traffic, please contact us.

Contact and unexpected traffic

Operator: muurahainen.com
Contact: hei@muurahainen.com

If you believe a scan was unexpected, unauthorized or disruptive, please email us so we can investigate and stop further testing where appropriate.

Useful details include the affected hostname, request timestamps and timezone, source IP address, requested paths and User-Agent string. Please do not send passwords, session cookies or sensitive file contents.

You are welcome to block the scanner according to your website’s security policy. We do not ask you to disable your security protections.