BLACK FRIDAY
Save 59% on PageForge Annual $191/year $485/year
Claim 59% Off →
Aardwolf Security Scanner icon
Actively maintained Tested up to 7.0.7 #44 in hardening

Aardwolf Security Scanner

Free WordPress security scanner. Audit your site for vulnerabilities, weak settings and exposed files, with a clear fix for every issue found.

Active installs<10New
Downloads · 30d69▲ +25.5% vs prev. 30d
Rating—0 reviews
Health score55/100Fair
All-time downloads273Since Jul 2026
Support resolved—No recent threads
RequiresWP 5.6PHP 7.2+
Downloads · 7d8▼ -63.6% week over week
Our verdict

Use with caution

Aardwolf Security Scanner works, but test it on a staging site before relying on it in 2026. Was last updated 3 months ago, and scores 55/100 on our health check.

  • Small user base (<10 active installs)
  • Very few reviews so far

How does it stack up?

Side-by-side on installs, updates, ratings & support

Daily downloads

91827Jul 22Aug 30Oct 8
Yesterday1
Daily average (1y)4
Peak day37Jul 25, 2026
Last 12 months280

Download spikes usually follow a new release — each site that auto-updates counts as a download.

Rankings

Where Aardwolf Security Scanner stands today

WordPress.org search rankings

Live position in the plugin search, top 100
KeywordPositionCompeting pluginsCategory
hardening >100 2,197 Best hardening plugins →
security >100 10,000 Best security plugins →
security audit >100 1,667 Best security audit plugins →
security scanner >100 880 Best security scanner plugins →
vulnerability >100 3,759 Best vulnerability plugins →

About Aardwolf Security Scanner

From the official readme · v1.2.6

Description

Aardwolf Security Scanner checks your WordPress site for the security problems attackers look for first. It runs a set of read-only checks, gives each finding a severity rating, and tells you how to fix it in clear language.

You can run a scan on demand or on a schedule. The plugin does not attack your server or change any files, and it does not send your data anywhere. Every check runs on your own install.

What it checks

  • Software updates. Outdated WordPress core, plugins and themes, plus inactive plugins and themes that still sit on disk.
  • Accounts and authentication. The default “admin” username, username enumeration through author archives and the REST API, risky registration defaults, and missing brute-force protection on the login form.
  • Configuration. The dashboard file editor, exposed debug output, missing or placeholder security keys and salts, the default “wp_” table prefix, and whether the admin area is forced over HTTPS.
  • Information exposure. A reachable XML-RPC endpoint, the version-leaking readme.html, the generator meta tag, directory browsing, and sensitive files such as debug logs, .git, .env and config backups left in the web root.
  • HTTP security headers. Missing X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Content-Security-Policy and HSTS.
  • Transport and environment. Sites still on plain HTTP, and end-of-life PHP versions.
  • File permissions. World-readable or world-writable wp-config.php and site root.
  • Known vulnerabilities. Installed plugins that have been removed from the WordPress.org directory, which often means a plugin was pulled for an unresolved security issue.

Each finding comes with a severity rating and clear steps to fix it. Every scan produces a security score out of 100 so you can track progress over time.

Scheduled scans and email alerts

Run a scan automatically once a day or once a week. The plugin can email you when the score drops, when the number of problems goes up, or when a high-risk issue appears. You can also choose to get an email after every scan.

Export reports

Save the latest scan as a CSV file, or open a clean printable report and save it as a PDF from your browser.

About Aardwolf Security

This plugin is made by Aardwolf Security. Automated checks are a good first line of defence, but they are not a replacement for a manual penetration test by a qualified tester.

External services

This plugin connects to one external service, the official WordPress.org Plugin API (https://api.wordpress.org/plugins/info/1.0/).

  • What it is used for: the Known Vulnerabilities check asks this API whether any of your installed plugins have been removed from the WordPress.org directory.
  • What data is sent, and when: the directory slug of each installed plugin (for example “akismet”) is sent when a scan runs. No personal data, site content or credentials are sent. Responses are cached for 24 hours.
  • Terms and privacy: this is a WordPress.org service, covered by the WordPress.org Terms and Privacy Policy.

The plugin also sends requests to your own site (its own URL) to inspect response headers and look for exposed files. These stay on your own server.

Installation

  1. Upload the aardwolf-security-scanner folder to /wp-content/plugins/, or install the ZIP from Plugins, Add New, Upload Plugin.
  2. Activate the plugin from the Plugins screen.
  3. Open Security Scanner in the admin menu and click Run Security Scan.

Frequently asked questions

Is it safe to run on a production site?

Yes. All checks are read-only. The plugin sends a few requests to your own site to inspect headers and look for exposed files, which is harmless. Keep a current backup before you change any settings, as good practice.

Does it fix things automatically?

No. The scanner reports each problem and tells you how to fix it. You make the changes yourself, such as editing wp-config.php, adjusting file permissions, or updating settings.

Why does a check say it could not complete?

Some checks send a request to your own site. If your host blocks these requests, those checks are skipped instead of failed, and the result explains what to check by hand.

Changelog

Plain-language readme and updated directory tags. No functional changes.

1.2.6

  • Rewrote the readme in plainer language and updated the tags for the plugin directory. No functional changes.

1.2.5

  • Printable report stylesheet is now registered and enqueued via wp_enqueue_style()/wp_print_styles() instead of a hard-coded link tag.

1.2.4

  • Moved the printable report’s CSS to a bundled stylesheet (no inline style tag) and removed the inline print-button script.
  • Removed an unnecessary wp-admin/includes/plugin.php include in the login-protection check.
  • Corrected the Contributors username.

1.2.3

  • Removed the duplicate Plugin URI header (it matched the Author URI); kept the Author URI.

1.2.2

  • Output all logos via escaped image tags for cleaner markup.
  • Documented the WordPress.org Plugin API usage under a new “External services” readme section.

1.2.1

  • Resolved WordPress.org Plugin Check findings: removed the unused Domain Path header and the discouraged load_plugin_textdomain() call, rewrote the CSV export without direct filesystem functions, scoped template variables, tidied the uninstall routine, and updated “Tested up to”.

Full changelog on WordPress.org →

For developers

Is this your plugin? Show off the numbers.

Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.

Active installs badge Rating badge Health score badge

Best Aardwolf Security Scanner alternatives

All hardening plugins →
Alternatives
Rank Plugin Active installs Rating Updated Health
1 NETSENSAI Shield NETSENSAI Shield Hardens and protects your site by locking down login, REST API, XML‑RPC, file editor, and… by Rafal Gierlicki 1K+ ★★★★★★★★★★ 5 (5) 2 months ago 78
2 Security Hardener Security Hardener Basic hardening: secure headers, login honeypot, user enumeration blocking, generic login… by Marc Armengou 200+ ★★★★★★★★★★ No reviews 2 months ago 65
3 Lockora Security Audit Lockora Security Audit Lockora Security Audit checks WordPress security posture, hardening, core integrity… by Guido Schad 200+ ★★★★★★★★★★ 5 (4) 3 weeks ago 76
4 SAR One Click Security SAR One Click Security Adds some extra security to your WordPress with only one click. by Samuel Aguilera 200+ ★★★★★★★★★★ 5 (7) 2 years ago 41
5 CMS ADMINS Security Check Report CMS ADMINS Security Check Report Read-only security audit for WordPress: 61 checks, an A to F grade, and a checklist that… by Patrick Schlesinger 100+ ★★★★★★★★★★ No reviews 2 weeks ago 68
6 Secure HTTP Headers Secure HTTP Headers Secure HTTP headers - Essential, and easy. by shasha310 100+ ★★★★★★★★★★ 3 (2) 5 years ago 26
7 Aipatch Security Scanner Aipatch Security Scanner WordPress security scanner with 36 checks, malware scanning, core integrity verification… by Esteban 100+ ★★★★★★★★★★ No reviews 5 months ago 53
8 Dessky Security Dessky Security Dessky Security is the ultralight plugin for basic Security Hardening. It is specially… by dessky 60+ ★★★★★★★★★★ 5 (2) 3 months ago 66
9 Bastora Security Audit Bastora Security Audit 62-Punkte-Sicherheits-Check mit Firewall, Schadcode-Scanner, URL-Reputation, Captcha… by Bastora 60+ ★★★★★★★★★★ 5 (1) 1 week ago 75
10 EDZNET Security Guard EDZNET Security Guard Requires 2FA for administrators, blocks new admin creation, refuses URL-credential logins… by EDZNET 60+ ★★★★★★★★★★ No reviews 1 month ago 64

FAQ

Aardwolf Security Scanner: quick answers

Straight answers, pulled from live WordPress.org data.

Live data from WordPress.org · checked Oct 9, 2026

Is Aardwolf Security Scanner free?

Yes. Aardwolf Security Scanner is free to download and use from the official WordPress.org plugin directory.

Is Aardwolf Security Scanner safe to use in 2026?

Aardwolf Security Scanner works, but test it on a staging site before relying on it in 2026. Was last updated 3 months ago, and scores 55/100 on our health check.

How many websites use Aardwolf Security Scanner?

Aardwolf Security Scanner is active on <10 WordPress websites and has been downloaded 273 times since it launched in July 2026. It was downloaded 69 times in the last 30 days.

Does Aardwolf Security Scanner work with WordPress 7.1?

Aardwolf Security Scanner is officially tested up to WordPress 7.0.7, while the latest release is 7.1.3. It may still work, but try it on a staging site first.

What PHP version does Aardwolf Security Scanner need?

Aardwolf Security Scanner requires PHP 7.2 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.

When was Aardwolf Security Scanner last updated?

The latest version, 1.2.6, was released on July 25, 2026 (3 months ago).

Who makes Aardwolf Security Scanner?

Aardwolf Security Scanner is developed and maintained by aardwolfsec.

What are the best alternatives to Aardwolf Security Scanner?

The most popular alternatives to Aardwolf Security Scanner are NETSENSAI Shield (1K+ installs), Security Hardener (200+ installs) and Lockora Security Audit (200+ installs).

Powered by PageForge

Want thousands of pages that rank like these? Build them in an afternoon.

This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.

  • CSV, Google Sheets & API data sources
  • AI content, schema & internal links per page
  • Works with Elementor, Gutenberg, Yoast & Rank Math
  • Free on WordPress.org — no credit card
Sarah is here to help!
Hi there! 👋 Need help finding what you're looking for?
Sarah
Sarah
Online & Ready to Help
Hi there! 👋 Need help finding what you're looking for?

We'll use this to continue our conversation

Just now ✓ Verified

Join 500+ SEO Pros Scaling Their Strategy

Get exclusive programmatic SEO tactics, AI content workflows, and the latest PageForge updates delivered straight to your inbox. Stay ahead of the algorithm.

We care about your data in our privacy policy.