{"id":343921,"date":"2026-07-22T19:37:17","date_gmt":"2026-07-22T19:37:17","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/aardwolf-security-scanner\/"},"modified":"2026-07-22T19:37:05","modified_gmt":"2026-07-22T19:37:05","slug":"aardwolf-security-scanner","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/aardwolf-security-scanner\/","author":23536486,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.2.5","stable_tag":"1.2.5","tested":"7.0.2","requires":"5.6","requires_php":"7.2","requires_plugins":null,"header_name":"Aardwolf Security Scanner","header_author":"Aardwolf Security","header_description":"Scans your WordPress site for common attack vectors covered in a penetration test and suggests configuration remediations to keep the bad guys out.","assets_banners_color":"001a68","last_updated":"2026-07-22 19:37:05","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"https:\/\/aardwolfsecurity.com\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":46,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.2.5":{"tag":"1.2.5","author":"aardwolfsec","date":"2026-07-22 19:37:05"}},"upgrade_notice":{"1.1.0":"<p>Adds scheduled scans with email alerts, CSV\/PDF export, and a known-vulnerability check.<\/p>","1.0.0":"<p>Initial release.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3619131,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3619131,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3619131,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3619131,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.2.5"],"block_files":[],"assets_screenshots":[],"screenshots":[]},"plugin_section":[],"plugin_tags":[31093,272860,6464,600,6460],"plugin_category":[54],"plugin_contributors":[272861],"plugin_business_model":[],"class_list":["post-343921","plugin","type-plugin","status-publish","hentry","plugin_tags-hardening","plugin_tags-penetration-testing","plugin_tags-scanner","plugin_tags-security","plugin_tags-vulnerability","plugin_category-security-and-spam-protection","plugin_contributors-aardwolfsec","plugin_committers-aardwolfsec"],"banners":{"banner":"https:\/\/ps.w.org\/aardwolf-security-scanner\/assets\/banner-772x250.png?rev=3619131","banner_2x":"https:\/\/ps.w.org\/aardwolf-security-scanner\/assets\/banner-1544x500.png?rev=3619131","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/aardwolf-security-scanner\/assets\/icon-128x128.png?rev=3619131","icon_2x":"https:\/\/ps.w.org\/aardwolf-security-scanner\/assets\/icon-256x256.png?rev=3619131","generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p><strong>Aardwolf Security Scanner<\/strong> runs a battery of passive, read-only checks against\nyour own WordPress site \u2014 the same low-hanging fruit a penetration tester looks\nfor first \u2014 and gives you a prioritised, plain-English list of what to fix and\nhow.<\/p>\n\n<p>It does <strong>not<\/strong> attack your server, exploit anything, or send any data off-site.\nEvery check runs locally on your own install.<\/p>\n\n<h4>What it checks<\/h4>\n\n<ul>\n<li><strong>Software updates<\/strong> \u2014 outdated WordPress core, plugins and themes, plus dormant\/inactive extensions that widen your attack surface.<\/li>\n<li><strong>Accounts &amp; authentication<\/strong> \u2014 the default <code>admin<\/code> username, username enumeration via author archives and the REST API, insecure registration defaults, and missing login brute-force protection.<\/li>\n<li><strong>Configuration hardening<\/strong> \u2014 the dashboard file editor, exposed debug output, missing\/placeholder security keys and salts, the default <code>wp_<\/code> table prefix, and forcing HTTPS on the admin area.<\/li>\n<li><strong>Information exposure<\/strong> \u2014 a reachable XML-RPC endpoint, the version-leaking <code>readme.html<\/code>, the generator meta tag, directory browsing, and sensitive files (debug logs, <code>.git<\/code>, <code>.env<\/code>, config backups) left in the web root.<\/li>\n<li><strong>HTTP security headers<\/strong> \u2014 missing <code>X-Frame-Options<\/code>, <code>X-Content-Type-Options<\/code>, <code>Referrer-Policy<\/code>, <code>Content-Security-Policy<\/code> and HSTS.<\/li>\n<li><strong>Transport &amp; environment<\/strong> \u2014 sites still on plain HTTP and end-of-life PHP versions.<\/li>\n<li><strong>File permissions<\/strong> \u2014 world-readable\/writable <code>wp-config.php<\/code> and root directory.<\/li>\n<li><strong>Known vulnerabilities<\/strong> \u2014 installed plugins that have been removed from the WordPress.org directory (often a sign a plugin was pulled for an unresolved security issue).<\/li>\n<\/ul>\n\n<p>Each finding comes with a severity rating and a specific, actionable remediation.<\/p>\n\n<h4>Scheduled scans &amp; email alerts<\/h4>\n\n<p>Run scans automatically in the background (daily or weekly via WP-Cron) and get\nan email when your security posture regresses \u2014 the score drops, problems\nincrease, or a high-risk issue appears. You can also choose to be emailed after\nevery scheduled scan.<\/p>\n\n<h4>Export reports<\/h4>\n\n<p>Export the latest scan as a <strong>CSV<\/strong> file, or open a clean, print-styled <strong>PDF\nreport<\/strong> that you can save or share (uses your browser's \"Save as PDF\").<\/p>\n\n<h4>About Aardwolf Security<\/h4>\n\n<p>This plugin is provided by <a href=\"https:\/\/aardwolfsecurity.com\/\">Aardwolf Security<\/a>.\nAutomated checks are a great first line of defence, but they are not a\nsubstitute for a manual penetration test by a qualified assessor.<\/p>\n\n<h3>External services<\/h3>\n\n<p>This plugin connects to one external service, the official <strong>WordPress.org Plugin API<\/strong> (<code>https:\/\/api.wordpress.org\/plugins\/info\/1.0\/<\/code>).<\/p>\n\n<ul>\n<li><strong>What it is used for:<\/strong> the \"Known Vulnerabilities\" check queries this API to find out whether any of your installed plugins have been removed\/closed on the WordPress.org directory (which often indicates a plugin was pulled for an unresolved security issue).<\/li>\n<li><strong>What data is sent, and when:<\/strong> the directory <em>slug<\/em> of each installed plugin (e.g. <code>akismet<\/code>) is sent when a scan runs. No personal data, site content, or credentials are transmitted. Responses are cached for 24 hours to minimise requests.<\/li>\n<li><strong>Terms &amp; privacy:<\/strong> this is a WordPress.org service, governed by the <a href=\"https:\/\/wordpress.org\/about\/\">WordPress.org Terms<\/a> and <a href=\"https:\/\/wordpress.org\/about\/privacy\/\">Privacy Policy<\/a>.<\/li>\n<\/ul>\n\n<p>The plugin also makes loopback HTTP requests to <em>your own site<\/em> (its own URL) to inspect response headers and check for publicly exposed files. These stay on your own server and are not sent to any third party.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>aardwolf-security-scanner<\/code> folder to <code>\/wp-content\/plugins\/<\/code>, or install the ZIP via Plugins \u2192 Add New \u2192 Upload Plugin.<\/li>\n<li>Activate the plugin through the Plugins screen.<\/li>\n<li>Go to <strong>Security Scanner<\/strong> in the admin menu and click <strong>Run Security Scan<\/strong>.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"is%20it%20safe%20to%20run%20on%20a%20production%20site%3F\"><h3>Is it safe to run on a production site?<\/h3><\/dt>\n<dd><p>Yes. All checks are passive and read-only. The plugin makes a few loopback HTTP\nrequests to your own site to inspect headers and exposed files, which is\nharmless. Always keep a current backup before changing configuration, as a\nmatter of good practice.<\/p><\/dd>\n<dt id=\"does%20it%20fix%20things%20automatically%3F\"><h3>Does it fix things automatically?<\/h3><\/dt>\n<dd><p>No. The scanner reports findings and gives you clear, specific remediation\nsteps for each one, but the changes themselves (editing <code>wp-config.php<\/code>,\npermissions, web-server rules, settings) are yours to make.<\/p><\/dd>\n<dt id=\"why%20does%20a%20check%20say%20%22could%20not%20complete%22%3F\"><h3>Why does a check say \"could not complete\"?<\/h3><\/dt>\n<dd><p>Some checks make a loopback request to your own site. If your host blocks\nloopback connections, those checks are skipped rather than failed. The result\nwill explain what to verify manually.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.2.5<\/h4>\n\n<ul>\n<li>Printable report stylesheet is now registered and enqueued via wp_enqueue_style()\/wp_print_styles() instead of a hard-coded  tag.<\/li>\n<\/ul>\n\n<h4>1.2.4<\/h4>\n\n<ul>\n<li>Moved the printable report's CSS to a bundled stylesheet (no inline ) and removed the inline print-button script.<\/li>\n<li>Removed an unnecessary wp-admin\/includes\/plugin.php include in the login-protection check.<\/li>\n<li>Corrected the Contributors username.<\/li>\n<\/ul>\n\n<h4>1.2.3<\/h4>\n\n<ul>\n<li>Removed the duplicate Plugin URI header (it matched the Author URI); kept the Author URI.<\/li>\n<\/ul>\n\n<h4>1.2.2<\/h4>\n\n<ul>\n<li>Output all logos via escaped  tags (removed raw inline-SVG output) for cleaner, escape-late-compliant markup.<\/li>\n<li>Documented the WordPress.org Plugin API usage under a new \"External services\" readme section.<\/li>\n<\/ul>\n\n<h4>1.2.1<\/h4>\n\n<ul>\n<li>Resolved WordPress.org Plugin Check findings: removed the unused Domain Path header and the discouraged load_plugin_textdomain() call, rewrote the CSV export without direct filesystem functions, scoped template variables, tidied the uninstall routine, and updated \"Tested up to\".<\/li>\n<\/ul>\n\n<h4>1.2.0<\/h4>\n\n<ul>\n<li>Removed the optional WPScan API integration and the one-click hardening feature; these are planned for a future Pro add-on. The free directory-removal check (which needs no API key) remains.<\/li>\n<\/ul>\n\n<h4>1.1.1<\/h4>\n\n<ul>\n<li>Scheduled scans now let you choose the time of day (and the day of the week for weekly scans), interpreted in your site's timezone.<\/li>\n<li>Fixed the oversized admin menu icon.<\/li>\n<li>Failed checks now show a problem-phrased title (e.g. \"Usernames are publicly enumerable\") instead of the healthy-state wording.<\/li>\n<li>The user-enumeration check now tests the live vectors (REST users endpoint and the ?author= redirect) rather than stored user data.<\/li>\n<\/ul>\n\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>Added scheduled scans (daily\/weekly) with email alerts on regression.<\/li>\n<li>Added CSV and printable PDF report export.<\/li>\n<li>Added a Known Vulnerabilities check: flags plugins removed from the WordPress.org directory (free) and cross-checks CVEs via an optional WPScan API token.<\/li>\n<li>Bumped \"Tested up to\" and refreshed the settings screen.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release: 22 security checks across six categories, security score, and optional one-click hardening.<\/li>\n<\/ul>","raw_excerpt":"Scan your WordPress site for the common attack vectors a penetration tester would probe, and get plain-English configuration fixes.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/343921","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=343921"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/aardwolfsec"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=343921"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=343921"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=343921"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=343921"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=343921"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=343921"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}