Planned
WordPress hardening checks
Review update posture, debug settings, file editing, account access, and other checks tied to WordPress guidance.
In development ยท Planned free WordPress plugin
See what your WordPress site is exposing. We're building a free plugin that brings security checks, public-file verification, and AI-assisted review into one dashboard.
The plugin is being built. There is no download yet. Built by AmazingPlugins. Name and requirements may change before release.
| Path | /wp-content/debug.log |
|---|---|
| Evidence | Public request returned file-like content, unlike a missing path. |
| Next step | Remove public access, then run the check again. |
Each area will report what it checked, when it checked, and what it couldn't confirm. These features are planned, not available to install today.
Planned
Review update posture, debug settings, file editing, account access, and other checks tied to WordPress guidance.
Planned
Check likely exposed logs and backups from an independent public vantage, then recheck after a fix.
Planned
Surface known vulnerable versions, file-integrity changes, and suspected malware with source and scan limits.
Planned
Add two-factor login, rate limits, and tested request rules with a recovery route.
Planned
Let an authorized assistant read findings and request scans. Fixes will need approval inside WordPress.
A file can exist on your server without being reachable by a visitor. It can also look blocked from inside the server while a CDN still serves an old copy. The planned verifier will test candidate URLs from outside your WordPress installation after you opt in.
The service will receive your site hostname and candidate URL paths. It will inspect a small response prefix to judge the result, then discard it. It won't store file contents. A timeout, login page, or challenge will be marked inconclusive rather than safe.
The check will cover tested paths and one public route at a recorded time. It won't certify your whole site. Read the WordPress security checklist for steps you can take today.
On supported WordPress versions, the planned MCP connection will let an authenticated assistant read findings and request a bounded scan. If it suggests a supported fix, you'll see the exact proposed change in WordPress first.
The assistant won't be able to approve its own proposal or run arbitrary commands. Some findings will still need a manual fix. MCP is planned for WordPress 6.9+ with the official MCP Adapter; the standard dashboard is targeted at WordPress 6.6+ and PHP 8.1+.
Have an urgent security issue now? Use a released security plugin while Amazing Security is in development. Our Wordfence Free comparison and Custonis comparison show the current differences.