Aardwolf Security Scanner
Free WordPress security scanner. Audit your site for vulnerabilities, weak settings and exposed files, with a clear fix for every issue found.
Use with caution
Aardwolf Security Scanner works, but test it on a staging site before relying on it in 2026. Was last updated 3 months ago, and scores 55/100 on our health check.
- Small user base (<10 active installs)
- Very few reviews so far
How does it stack up?
Side-by-side on installs, updates, ratings & supportDaily downloads
Download spikes usually follow a new release — each site that auto-updates counts as a download.
Rankings
Where Aardwolf Security Scanner stands todayWordPress.org search rankings
Live position in the plugin search, top 100| Keyword | Position |
|---|---|
| hardening | >100 |
| security | >100 |
| security audit | >100 |
| security scanner | >100 |
| vulnerability | >100 |
About Aardwolf Security Scanner
From the official readme · v1.2.6Description
Aardwolf Security Scanner checks your WordPress site for the security problems attackers look for first. It runs a set of read-only checks, gives each finding a severity rating, and tells you how to fix it in clear language.
You can run a scan on demand or on a schedule. The plugin does not attack your server or change any files, and it does not send your data anywhere. Every check runs on your own install.
What it checks
- Software updates. Outdated WordPress core, plugins and themes, plus inactive plugins and themes that still sit on disk.
- Accounts and authentication. The default “admin” username, username enumeration through author archives and the REST API, risky registration defaults, and missing brute-force protection on the login form.
- Configuration. The dashboard file editor, exposed debug output, missing or placeholder security keys and salts, the default “wp_” table prefix, and whether the admin area is forced over HTTPS.
- Information exposure. A reachable XML-RPC endpoint, the version-leaking readme.html, the generator meta tag, directory browsing, and sensitive files such as debug logs, .git, .env and config backups left in the web root.
- HTTP security headers. Missing X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Content-Security-Policy and HSTS.
- Transport and environment. Sites still on plain HTTP, and end-of-life PHP versions.
- File permissions. World-readable or world-writable wp-config.php and site root.
- Known vulnerabilities. Installed plugins that have been removed from the WordPress.org directory, which often means a plugin was pulled for an unresolved security issue.
Each finding comes with a severity rating and clear steps to fix it. Every scan produces a security score out of 100 so you can track progress over time.
Scheduled scans and email alerts
Run a scan automatically once a day or once a week. The plugin can email you when the score drops, when the number of problems goes up, or when a high-risk issue appears. You can also choose to get an email after every scan.
Export reports
Save the latest scan as a CSV file, or open a clean printable report and save it as a PDF from your browser.
About Aardwolf Security
This plugin is made by Aardwolf Security. Automated checks are a good first line of defence, but they are not a replacement for a manual penetration test by a qualified tester.
External services
This plugin connects to one external service, the official WordPress.org Plugin API (https://api.wordpress.org/plugins/info/1.0/).
- What it is used for: the Known Vulnerabilities check asks this API whether any of your installed plugins have been removed from the WordPress.org directory.
- What data is sent, and when: the directory slug of each installed plugin (for example “akismet”) is sent when a scan runs. No personal data, site content or credentials are sent. Responses are cached for 24 hours.
- Terms and privacy: this is a WordPress.org service, covered by the WordPress.org Terms and Privacy Policy.
The plugin also sends requests to your own site (its own URL) to inspect response headers and look for exposed files. These stay on your own server.
Installation
- Upload the aardwolf-security-scanner folder to /wp-content/plugins/, or install the ZIP from Plugins, Add New, Upload Plugin.
- Activate the plugin from the Plugins screen.
- Open Security Scanner in the admin menu and click Run Security Scan.
Frequently asked questions
Is it safe to run on a production site?
Yes. All checks are read-only. The plugin sends a few requests to your own site to inspect headers and look for exposed files, which is harmless. Keep a current backup before you change any settings, as good practice.
Does it fix things automatically?
No. The scanner reports each problem and tells you how to fix it. You make the changes yourself, such as editing wp-config.php, adjusting file permissions, or updating settings.
Why does a check say it could not complete?
Some checks send a request to your own site. If your host blocks these requests, those checks are skipped instead of failed, and the result explains what to check by hand.
Changelog
Plain-language readme and updated directory tags. No functional changes.
1.2.6
- Rewrote the readme in plainer language and updated the tags for the plugin directory. No functional changes.
1.2.5
- Printable report stylesheet is now registered and enqueued via wp_enqueue_style()/wp_print_styles() instead of a hard-coded link tag.
1.2.4
- Moved the printable report’s CSS to a bundled stylesheet (no inline style tag) and removed the inline print-button script.
- Removed an unnecessary wp-admin/includes/plugin.php include in the login-protection check.
- Corrected the Contributors username.
1.2.3
- Removed the duplicate Plugin URI header (it matched the Author URI); kept the Author URI.
1.2.2
- Output all logos via escaped image tags for cleaner markup.
- Documented the WordPress.org Plugin API usage under a new “External services” readme section.
1.2.1
- Resolved WordPress.org Plugin Check findings: removed the unused Domain Path header and the discouraged load_plugin_textdomain() call, rewrote the CSV export without direct filesystem functions, scoped template variables, tidied the uninstall routine, and updated “Tested up to”.
For developers
Is this your plugin? Show off the numbers.
Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.
Best Aardwolf Security Scanner alternatives
All hardening plugins →FAQ
Aardwolf Security Scanner: quick answers
Straight answers, pulled from live WordPress.org data.
Live data from WordPress.org · checked Oct 9, 2026
Is Aardwolf Security Scanner free?
Yes. Aardwolf Security Scanner is free to download and use from the official WordPress.org plugin directory.
Is Aardwolf Security Scanner safe to use in 2026?
Aardwolf Security Scanner works, but test it on a staging site before relying on it in 2026. Was last updated 3 months ago, and scores 55/100 on our health check.
How many websites use Aardwolf Security Scanner?
Aardwolf Security Scanner is active on <10 WordPress websites and has been downloaded 273 times since it launched in July 2026. It was downloaded 69 times in the last 30 days.
Does Aardwolf Security Scanner work with WordPress 7.1?
Aardwolf Security Scanner is officially tested up to WordPress 7.0.7, while the latest release is 7.1.3. It may still work, but try it on a staging site first.
What PHP version does Aardwolf Security Scanner need?
Aardwolf Security Scanner requires PHP 7.2 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.
When was Aardwolf Security Scanner last updated?
The latest version, 1.2.6, was released on July 25, 2026 (3 months ago).
Who makes Aardwolf Security Scanner?
Aardwolf Security Scanner is developed and maintained by aardwolfsec.
What are the best alternatives to Aardwolf Security Scanner?
The most popular alternatives to Aardwolf Security Scanner are NETSENSAI Shield (1K+ installs), Security Hardener (200+ installs) and Lockora Security Audit (200+ installs).
Powered by PageForge
Want thousands of pages that rank like these? Build them in an afternoon.
This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.
- CSV, Google Sheets & API data sources
- AI content, schema & internal links per page
- Works with Elementor, Gutenberg, Yoast & Rank Math
- Free on WordPress.org — no credit card