In development ยท Planned free WordPress plugin

Amazing Security.

See what your WordPress site is exposing. We're building a free plugin that brings security checks, public-file verification, and AI-assisted review into one dashboard.

The plugin is being built. There is no download yet. Built by AmazingPlugins. Name and requirements may change before release.

Example findingPublic file check
Example: publicly reachable

A log file can be opened from the web

Path/wp-content/debug.log
EvidencePublic request returned file-like content, unlike a missing path.
Next stepRemove public access, then run the check again.
Illustrative interface, not a scan of your site. A real result would include the test time, host, and uncertainty.

The free release we're building

Each area will report what it checked, when it checked, and what it couldn't confirm. These features are planned, not available to install today.

Planned

WordPress hardening checks

Review update posture, debug settings, file editing, account access, and other checks tied to WordPress guidance.

Planned

Public file verification

Check likely exposed logs and backups from an independent public vantage, then recheck after a fix.

Planned

Vulnerability and file findings

Surface known vulnerable versions, file-integrity changes, and suspected malware with source and scan limits.

Planned

Login and firewall controls

Add two-factor login, rate limits, and tested request rules with a recovery route.

Planned

AI assistant access through MCP

Let an authorized assistant read findings and request scans. Fixes will need approval inside WordPress.

A public check needs a public vantage.

A file can exist on your server without being reachable by a visitor. It can also look blocked from inside the server while a CDN still serves an old copy. The planned verifier will test candidate URLs from outside your WordPress installation after you opt in.

The service will receive your site hostname and candidate URL paths. It will inspect a small response prefix to judge the result, then discard it. It won't store file contents. A timeout, login page, or challenge will be marked inconclusive rather than safe.

The check will cover tested paths and one public route at a recorded time. It won't certify your whole site. Read the WordPress security checklist for steps you can take today.

AI can suggest. You approve.

On supported WordPress versions, the planned MCP connection will let an authenticated assistant read findings and request a bounded scan. If it suggests a supported fix, you'll see the exact proposed change in WordPress first.

The assistant won't be able to approve its own proposal or run arbitrary commands. Some findings will still need a manual fix. MCP is planned for WordPress 6.9+ with the official MCP Adapter; the standard dashboard is targeted at WordPress 6.6+ and PHP 8.1+.

Have an urgent security issue now? Use a released security plugin while Amazing Security is in development. Our Wordfence Free comparison and Custonis comparison show the current differences.