Scan like an attacker, safely
Exposed .env and .git files, secrets in JavaScript bundles, Supabase and Firebase rules, TLS, headers, email spoofing and more.
Vigavo for WordPress
Outdated core, exposed backups and config files, user enumeration and missing headers, checked from the outside.
Free. No signup. Read-only checks from the outside.
We compare your WordPress version with the current release and look for the files attackers try first.
Core version, readme and debug files, xmlrpc and user listing.
wp-config backups, database dumps and archives in the web root.
Connect the MySQL database with a read-only user for daily backups.
Findings ranked by what an attacker would try first, with the fix right next to each one.
Exposed .env and .git files, secrets in JavaScript bundles, Supabase and Firebase rules, TLS, headers, email spoofing and more.
Scheduled scans compare against the last result, so you hear about a new leak once, not every day.
Encrypted database snapshots, verified by an actual restore and row counts.
Each critical finding comes with a prompt you can paste into Cursor, Claude Code, Lovable or Bolt.
Deduplicated alerts, daily or weekly digests, and a clear grade from A to F.
No. A plugin for deeper checks is planned; the scan works without it.
No. A few dozen light requests per scan.
We report what is visible from outside. Full plugin audits come with the plugin.
Yes. We only make the same read-only requests any visitor's browser could make. Nothing is changed and nothing is exploited.
The scan result. Free scans are deleted after 30 days.