Website Security Check
Website Security Check detects if your WordPress website has vulnerabilities and security flaws. Get a full security report for your website.
Consider an alternative
Website Security Check shows warning signs in 2026 — compare the alternatives below before installing. It runs on 100+ sites, is rated 5/5 and was last updated 6 years ago, and scores 32/100 on our health check.
- Small user base (100+ active installs)
- Very few reviews so far
- No update in 6 years
- Only tested up to WordPress 5.5 (latest is 7.1)
How does it stack up?
Side-by-side on installs, updates, ratings & supportDaily downloads
Download spikes usually follow a new release — each site that auto-updates counts as a download.
Rankings
Where Website Security Check stands todayWordPress.org search rankings
Live position in the plugin search, top 100| Keyword | Position |
|---|---|
| security | >100 |
| security check | >100 |
| website security check | >100 |
| wordpress security check | >100 |
Version adoption
Share of active sites per release.
Rating breakdown
★★★★★★★★★★ 5 from 2 reviews
About Website Security Check
From the official readme · v1.2.00Description
Website Security Check detects if your WordPress website has vulnerabilities and security flaws. Get a full security report for your website.
Check your website with our Free Website Security Check
Why is Your WordPress CMS Security Check Important:
- 55.9% of vulnerabilities came from plugins.
- Over 90,978 attacks happening per minute on both big and small WordPress sites
- 84% of all security vulnerabilities on the internet are the result of Cross-Site Scripting or XSS attacks.
Most of the casual bloggers start thinking about site security only after they get into first problems and majority of websites get hacked from entirely preventable issues, like not keeping things updated or using insecure passwords.
The majority of hacking attempts are made by bots, and you may be able to prevent hacker bots attacks by hiding your WordPress paths: wp-content, wp-include, plugins, themes, etc.
Just by changing the main paths, you may be able to protect your website against things like brute-force attacks, SQL-injection, and requests to your PHP files.
The test includes checking for updated plugins, themes and different files and functions which are known to hold security breaches.
Is WordPress CMS Vulnerable?:
- WordPress is one of the most popular CMS (Content Management System) options on the Internet these days.
- Around 33% of websites are made with WordPress.
- Even if WordPress is known for being a secure CMS, sometimes hackers do find vulnerabilities. Most site owners don’t know that the biggest risk comes from the installed plugins and themes. You obviously need to be careful with them, as plugin vulnerabilities represented 55.9% of the known entry points reported by respondents.
What happens if wp-login page is visible:
- wp-login page is certainly one of the most vulnerable pages on your website.
- If this path is visible means that an authentication path is visible and hackers can perform brute force login attempts.
- A successful brute force attack can give hackers access to your admin area. An unsuccessful one can slow down your website or crush your server.
- There are many strategies for dealing with this problem. The simplest one is to hide WordPress login page.
What happens if WordPress XML-RPC is visible:
- XML-RPC is an API that allows anyone to interact with your WordPress website.
- XML-RPC is also a way to manage your site without having to login manually via the wp-login page.
Why hackers try to access your WordPress website using xmlrpc.php file?:
- Instead of 100 login attempts, the hackers could reduce their login attempts to 10 or less and still try 100 or even thousands of passwords to each request.
- XML-RPC service is always at high risk for WordPress websites. For your safety, you should disable this service.
- By disabling xml-rpc you can protect your website from DDoS attacks, brute force attacks, malicious pingback response.
If you like Website Security Check please help us and write us a positive review.
https://wordpress.org/support/plugin/website-security-check/reviews/#new-post
Try also our security plugin: Hide My Wp Ghost Free
Installation
Manually install the Website Security Check plugin:
1. Log In as an Administrator on your WordPress site.
2. In the menu displayed on the left, there is a “Plugins” tab. Click it.
3. Now click “Add New”.
4. There, you have the “Upload” button. Click the “Upload” button
5. Upload the website-security-check.zip file.
6. After the upload it’s finished, click Activate Plugin.
7. Start checking your website security with one click
9. Enjoy!
Website Security Check
Security
WordPress Security Check
Frequently asked questions
Does this plugin work on WP Multisite?
Yes, the plugin works on both Single Website and WP Multisite. The plugin also works with Apache, Nginx, IIS and LiteSpeed servers
Is this Plugin free of charge?
Yes. The plugin will always be free. We will include all the required Security updates.
Is this plugin going to protect my website from all hackers?
This plugin will not protect your website from hackers but it will detect the security flaws.
Changelog
1.2.00
- Compatible with WordPress 5.5
- Fixed some task issues
1.1.20
- Compatible with WordPress 5.4
1.1.08
- Compatible with WordPress 5.3.1
- Added dashboard security meter
- Added new tasks in Security check
- Update the compatibility with more plugins
1.0.07
- Compatible with WordPress 5.3
1.0.06
- Update security tasks
- Compatible with WordPress 5.2.2
1.0.05
- Update compatibility with HTTPS
- Fix minor bugs
- Compatible with WordPress 5.2.1
For developers
Is this your plugin? Show off the numbers.
Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.
Best Website Security Check alternatives
All security plugins →FAQ
Website Security Check: quick answers
Straight answers, pulled from live WordPress.org data.
Live data from WordPress.org · checked Oct 10, 2026
Is Website Security Check free?
Yes. Website Security Check is free to download and use from the official WordPress.org plugin directory.
Is Website Security Check safe to use in 2026?
Website Security Check shows warning signs in 2026 — compare the alternatives below before installing. It runs on 100+ sites, is rated 5/5 and was last updated 6 years ago, and scores 32/100 on our health check.
How many websites use Website Security Check?
Website Security Check is active on 100+ WordPress websites and has been downloaded 5,711 times since it launched in February 2019. It was downloaded 141 times in the last 30 days.
Does Website Security Check work with WordPress 7.1?
Website Security Check is officially tested up to WordPress 5.5.23, while the latest release is 7.1.3. It may still work, but try it on a staging site first.
What PHP version does Website Security Check need?
Website Security Check requires PHP 5.6 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.
When was Website Security Check last updated?
The latest version, 1.2.00, was released on August 27, 2020 (6 years ago).
Who makes Website Security Check?
Website Security Check is developed and maintained by John Darrel.
What are the best alternatives to Website Security Check?
The most popular alternatives to Website Security Check are Wordfence Security (5M+ installs), Really Simple Security (3M+ installs) and Jetpack (3M+ installs).
Powered by PageForge
Want thousands of pages that rank like these? Build them in an afternoon.
This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.
- CSV, Google Sheets & API data sources
- AI content, schema & internal links per page
- Works with Elementor, Gutenberg, Yoast & Rank Math
- Free on WordPress.org — no credit card

