Vigavo for WordPress

WordPress, watched.We stay awake.

Outdated core, exposed backups and config files, user enumeration and missing headers, checked from the outside.

Free. No signup. Read-only checks from the outside.

What we check on WordPress

We compare your WordPress version with the current release and look for the files attackers try first.

  1. Version and exposure

    Core version, readme and debug files, xmlrpc and user listing.

  2. Leftover files

    wp-config backups, database dumps and archives in the web root.

  3. Database backups

    Connect the MySQL database with a read-only user for daily backups.

Everything a small team forgets to check

Findings ranked by what an attacker would try first, with the fix right next to each one.

Scan like an attacker, safely

Exposed .env and .git files, secrets in JavaScript bundles, Supabase and Firebase rules, TLS, headers, email spoofing and more.

Watch for changes

Scheduled scans compare against the last result, so you hear about a new leak once, not every day.

Backups that restore

Encrypted database snapshots, verified by an actual restore and row counts.

Fix prompts

Each critical finding comes with a prompt you can paste into Cursor, Claude Code, Lovable or Bolt.

Alerts without noise

Deduplicated alerts, daily or weekly digests, and a clear grade from A to F.

Questions

Do I need a plugin?

No. A plugin for deeper checks is planned; the scan works without it.

Will it slow my site?

No. A few dozen light requests per scan.

Do you check plugins?

We report what is visible from outside. Full plugin audits come with the plugin.

Is the scan safe for my site?

Yes. We only make the same read-only requests any visitor's browser could make. Nothing is changed and nothing is exploited.

What do you store?

The scan result. Free scans are deleted after 30 days.

Feedback
Type