WordPress OSINT, maintenance or security needs? Reach out!
TLDWP

Plugin: wp-security-hardening (Used by 2,380 domains)

WP Hardening (discontinued)

πŸ‘€ WebProtect.ai πŸ“¦ v1.2.8 πŸ”— Plugin Homepage

WP Hardening is a tool which performs a real-time security audit of your website to find missing security best practices. Using our β€˜Security Fixer’ you can also fix these with a single click from your WordPress backend.

Discontinuation Notice

IMPORTANT: This plugin is discontinued

This is to inform you that this plugin is no longer being maintained or updated. We have placed a discontinuation request with the WordPress team, and the plugin will soon be β€˜closed’ for new installations.

This plugin was launched as a side project and has sadly reached the end of its journey. Thank you for your understanding and for using our plugin. We apologize for any inconvenience this may cause.

What This Means for You

  1. No Further Updates: There will be no more updates, bug fixes, or new features.
  2. No Support: Support for this plugin is no longer available.

We recommend that you deactivate and delete this plugin from your WordPress site as soon as possible. Please seek alternative plugins to replace the functionality provided by this plugin.

Features

Hardening Audit

  1. WordPress Version Check
    It checks if your website is on the latest version or not.
  2. Checking Outdated Plugins
    It checks if your website is running the updated plugins or not.
  3. Checking PHP Version
    WP Hardening also checks if your website is running on a secure version of PHP.
  4. Checking File & Folder Permissions
    WP Hardening also checks if your website is built on the secured version of PHP or not.
  5. Database Password Strength
    We check the strength of passwords used on your database. Not having a secured password can become an easy target for Brute-Force attacks.
  6. Checking Firewall Protection
    We’ll check if your website is being protected by a firewall or not. Firewalls leverage a great monitoring and filtering system on your website.

Security Fixers

Admin & API Security

  1. Stop User Enumeration Hackers & bad bots can easily find usernames in WordPress by visiting URLs like yourwebsite.com/?author=1. This can significantly help them in performing larger attacks like Bruteforce & SQL injection.
  2. Change Login URL Prevent admin password brute-forcing by changing the URL for the wp-admin login area. You can change the url only when this fixer is disabled.
  3. Disable XMLRPC XMLRPC is often targeted by bots to perform brute force & DDoS attacks (via pingback) causing considerable stress on your server. However, there are some services which rely on xmlrpc. Be sure you definitely do not need xmlrpc before disabling it.
  4. Disable WP API JSON Since 4.4 version, WordPress added JSON REST API which largely benefits developers. However, it’s often targeted for bruteforce attacks just like in the case of xmlrpc. If you are not using it, best is to disable it.
  5. Disable File Editor If a hacker is able to get access to your WordPress admin, with the file editor enabled it becomes quite easy for them to add malicious code to your theme or plugins. If you are not using this, it’s best to keep the file editor disabled.
  6. Disable WordPress Application Passwords WordPress application passwords have full permissions of the user that generated them, making it possible for an attacker to gain control of a website by tricking the site administrator into granting permission to their malicious application.

Disable Information Disclosure & Remove Meta information

  1. Hide WordPress version number
    This gives away your WordPress version number making life of a hacker simple as they’ll be able to find targeted exploits for your WordPress version. It’s best to keep this hidden, enabling the button shall do that.
  2. Remove WordPress Meta Generator Tag
    The WordPress Meta tag contains your WordPress version number which is best kept hidden
  3. Remove WPML (WordPress Multilingual Plugin) Meta Generator Tag
    This discloses the WordPress version number which is best kept hidden.
  4. Remove Slider Revolution Meta Generator Tag
    Slider revolution stays on the radar of hackers due to its popularity. An overnight hack in the version you’re using could lead your website vulnerable too. Make it difficult for hackers to exploit the vulnerabilities by disabling version number disclosure here
  5. Remove WPBakery Page Builder Meta Generator Tag
    Common page builders often are diagnosed with a vulnerability putting your website’s security at risk. With this toggle enabled, the version of these page builders will be hidden making it difficult for hackers to find if you’re using a vulnerable version.
  6. Remove Version from Stylesheet
    Many CSS files have the WordPress version number appended to their source, for cache purposes. Knowing the version number allows hackers to exploit known vulnerabilities.
  7. Remove Version from Script
    Many JS files have the WordPress version number appended to their source, for cache purposes. Knowing the version number allows hackers to exploit known vulnerabilities.

Basic Server Hardening

  1. Hide Directory Listing of WP includes
    WP-includes directory gives away a lot of information about your WordPress to hackers. Disable it by simply toggling the option to ensure you make reconnaissance of hackers difficult

Security Headers

  1. Clickjacking Protection
    Protect your WordPress Website from clickjacking with the X-Frame-Options response header. Clickjacking is an attack that tricks a user into clicking a webpage element which is invisible or disguised as another element.
  2. XSS Protection
    Add the HTTP X-XSS-Protection response header so that browsers such as Chrome, Safari, Microsoft Edge stops pages from loading when they detect reflected cross-site scripting (XSS) attacks.
  3. Content Sniffing protection
    Add the X-Content-Type-Options response header to protect against MIME sniffing vulnerabilities. Such vulnerabilities can occur when a website allows users to upload content to a website, however the user disguises a particular file type as something else. This can give them the opportunity to perform cross-site scripting and compromise the website.
  4. HTTP only & Secure flag
    Enable the HttpOnly and secure flags to make the cookies more secure. This instructs the browser to trust the cookie only by the server, which adds a layer of protection against XSS attacks.

DomainExposuresHeadersLast Checked
n*g*t*a*e*r*s*a*c*.no βœ… B 2026-06-14 12:46:47
f*r*u*a*i*s*i*f*.u*r*.cl βœ… B 2026-06-14 08:53:02
g*e*o*.fr βœ… F 2026-06-14 08:08:49
u*i*e*s*l*o*l*g*.e*u.lb βœ… F 2026-06-14 07:44:18
s*r*n*.be βœ… B 2026-06-14 07:34:16
w*w*.s*i*l*.sk βœ… D 2026-06-14 05:57:55
w*e*t*e*e*r*h.o*g.uk βœ… D 2026-06-14 04:54:24
w*e*t*e*e*r*h.a*.uk βœ… D 2026-06-14 04:54:24
l*v*s*o*k.k*r*l*.g*v.in βœ… F 2026-06-14 03:06:29
n*c*.n*g*l*n*.g*v.in βœ… A 2026-06-14 02:28:55
c*t*e*g*i*g*r*e*.p*o*e*t*g*l*e*y.eu βœ… D 2026-06-13 22:53:17
h*f*a*-*a*e.nl βœ… D 2026-06-13 15:31:09
e*p*t*y.p*o*e*t*g*l*e*y.eu βœ… F 2026-06-13 15:30:11
d*w.p*o*e*t*g*l*e*y.eu βœ… F 2026-06-13 15:30:11
l*c*b*n*r*e.fr βœ… F 2026-06-13 12:43:15
m*s*o*a*e*i*a.org βœ… F 2026-06-13 09:19:02
b*-*n*e*i*.fr βœ… F 2026-06-13 08:07:16
g*m*a*.cz βœ… F 2026-06-13 06:36:37
a*o*a*b*t.c*m.ve βœ… B 2026-06-13 04:58:56
t*x*l*g.d*c*i*s*n*w*i*h*.com βœ… C 2026-06-13 02:39:32
p*o*u*t*.s*t*s*h*l.com βœ… C 2026-06-13 00:34:59
z*k.nu βœ… D 2026-06-12 23:23:14
c*u.u*t.e*u.vn βœ… A 2026-06-12 22:05:32
b*b*.m*d*u*k*t*.g*.id βœ… D 2026-06-12 21:45:15
h*a*t*l*w*l*g.d*c*i*s*n*w*i*h*.com βœ… C 2026-06-12 21:09:33
c*u*s*e*m*t*u*-*r.net βœ… F 2026-06-12 21:08:57
c*i*t*n*c*u*i.it βœ… F 2026-06-12 20:58:03
s*i*l*b.v*.nl βœ… F 2026-06-12 19:52:22
m*n*o*e*h*s*.club βœ… B 2026-06-12 19:42:12
p*d*a*a*d.m*c*.md βœ… B 2026-06-12 19:16:29
c*s*i*n*r*v*t*e*u*t*.com βœ… C 2026-06-12 19:14:02
h*s*w*l*n*s*.com βœ… C 2026-06-12 17:46:56
a*u*m*n*r*l*a*t*l*.c*m.br βœ… F 2026-06-12 16:14:28
d*b*v*i*e*a*a*l*g.com βœ… C 2026-06-12 16:10:29
p*i*a*y*u*.c*b*r*h*s*v*n.com βœ… D 2026-06-12 14:56:08
m*c*i*e*f*m*e.fr βœ… F 2026-06-12 14:32:27
p*y*i*a*t*e*a*i*t*s*i*t*n*e*u.org βœ… C 2026-06-12 13:42:08
u*i*k*-*j*.a*.id βœ… F 2026-06-12 13:07:39
c*e*c*n*f*u*d*t*o*.c*m.au βœ… F 2026-06-12 12:50:37
d*r*t*e*-*a*r.de βœ… D 2026-06-11 22:53:39
c*p*m*.org βœ… D 2026-06-11 20:48:37
m*t*o*a*e*p.com βœ… F 2026-06-11 20:02:44
k*n*t*p*d*.ee βœ… A 2026-06-11 17:37:35
a*t*e*c*e*e*u.org βœ… C 2026-06-11 11:19:52
r*v*s*i*t*n*.de βœ… D 2026-06-11 08:07:09
p*s*a*n*s.u*h*r*j*y*.a*.id βœ… F 2026-06-11 04:10:07
f*b.u*h*r*j*y*.a*.id βœ… F 2026-06-11 04:10:07
f*.u*h*r*j*y*.a*.id βœ… F 2026-06-11 04:10:07
s*h*o*-*h*p.c*.uk βœ… D 2026-06-11 04:00:54
s*p*o*t.t*i*e*a*.com βœ… D 2026-06-11 03:44:50
e*a*o*a*d*g*t*l*s*r*i*e*.com βœ… C 2026-06-10 14:41:54
p*e*s*r*d*.c*m.au πŸ”“ D 2026-06-10 13:31:56
o*h*s.in βœ… F 2026-06-10 07:07:54
i*t.h*l.no βœ… F 2026-06-10 03:32:06
a*s*o*t*s*r*t*.org βœ… F 2026-06-10 02:32:57
b*l*t*n*a*e*a*i*o.u*l.es βœ… F 2026-06-10 01:23:46
m*l*y*i*.a*m*-*a*e*i*g.com βœ… F 2026-06-10 01:20:06
r*i*w*y*a*s*c*a*i*n.eu βœ… F 2026-06-09 20:30:39
i*f*.j*t*e*b*t.com βœ… B 2026-06-09 15:49:15
s*s*d*.p*o*e*t*g*l*e*y.eu βœ… F 2026-06-09 14:50:59
t*e*o*m*t*.co βœ… D 2026-06-09 09:40:22
c*u*t*r*t.hu βœ… F 2026-06-09 08:04:15
t*c*n*g*p.com βœ… F 2026-06-09 04:12:43
g*g*o*u*1.w*e*g*n*.com βœ… D 2026-06-09 01:58:08
d*v*-*b.t*m*.c*.id πŸ”“ F 2026-06-09 00:33:11
g*o*s*e*h*r*.n*.ca βœ… F 2026-06-08 23:44:27
s*n*u*a*i*a*e*.c*m.br βœ… D 2026-06-08 22:03:53
d*u*r.m*d*u*k*t*.g*.id βœ… D 2026-06-08 21:46:04
a*i*.s*i.e*u.au βœ… D 2026-06-08 21:41:36
c*s*m*.c*.at βœ… F 2026-06-08 21:30:48
p*h*u*p*a*l*y*e*d*s*g*.com βœ… F 2026-06-08 21:00:59
c*p*e.it πŸ”“ D 2026-06-08 19:28:02
h*b.k*m*-*a*.de βœ… B 2026-06-08 15:48:21
b*y*o*n*y*w*m*.gov βœ… D 2026-06-08 15:14:30
n*r*h*a*e.c*m.au πŸ”“ C 2026-06-08 10:31:15
r*s*u*y.m*s*a*i*g*e*s*t*.com βœ… D 2026-06-08 07:57:57
d*i*t*k*e*a*.lt βœ… F 2026-06-08 07:50:31
a*e*r.fr βœ… F 2026-06-08 07:17:54
s*e*.o*g.pl βœ… F 2026-06-08 05:03:42
p*l*f*b.p*l*m*l.ca βœ… F 2026-06-08 04:34:10
h*i*e*e*a*s*g*.net βœ… D 2026-06-08 03:54:12
e*p*c*-*r*h*2.d*m*-*l*e*t.site βœ… F 2026-06-07 22:58:17
d*d*.g*a.g*v.in βœ… B 2026-06-07 22:06:16
b*o*t*.fr βœ… F 2026-06-07 20:44:42
c*t*l*n*.gr βœ… B 2026-06-07 20:36:01
r*d*c*.o*l*m*t.no βœ… B 2026-06-07 18:49:18
n*u.e*u.in βœ… F 2026-06-07 16:22:09
d*p*-*h.g*t*u*.io βœ… F 2026-06-07 16:07:06
d*c*.p*y.s*b*.com βœ… A 2026-06-07 15:58:07
g*o*f*n*.us βœ… F 2026-06-07 15:26:33
b*o*.e*y*o*k.c*.uk βœ… B 2026-06-07 12:11:14
b*s*o*s*o*n*a*p*s.ie βœ… F 2026-06-07 11:19:45
b*j*u*n*c*l*m*r*i*.com βœ… F 2026-06-07 10:29:25
b*j*u*-*y*s*n*r*n*.com βœ… F 2026-06-07 10:23:37
b*j*u*e*i*p*s*o*e.com βœ… F 2026-06-07 10:17:37
f*n*i*s*r*.c*m.np βœ… F 2026-06-07 09:11:32
b*g*a*e*a*.com βœ… F 2026-06-07 08:49:58
k*l*c*t*.c*.il βœ… A 2026-06-07 07:45:41
d*k*o*.c*.il βœ… A 2026-06-07 07:45:41
m*d*i*e*r*f*.c*.il βœ… A 2026-06-07 07:45:41

Top 50 Plugins

Plugin Count
elementor 1,834,974
contact-form-7 1,805,395
elementor-pro 1,069,674
woocommerce 831,175
revslider 628,526
jetpack 473,249
js_composer 440,228
wp-rocket 341,005
essential-addons-for-elementor-lite 300,145
gravityforms 270,579
complianz-gdpr 262,997
cookie-law-info 236,572
instagram-feed 232,313
google-site-kit 226,154
sitepress-multilingual-cms 225,560
google-analytics-for-wordpress 217,459
header-footer-elementor 213,861
elementskit-lite 211,389
bluehost-wordpress-plugin 191,844
gutenberg 164,589
gutenberg-core 162,474
cookie-notice 155,603
litespeed-cache 135,239
the-events-calendar 134,880
wpforms-lite 131,470
gtranslate 130,461
astra-sites 121,039
popup-maker 118,166
woocommerce-payments 114,462
tablepress 112,366
coblocks 101,429
honeypot 99,514
astra-addon 96,982
duracelltomi-google-tag-manager 95,600
wp-smushit 95,268
all-in-one-seo-pack 94,836
LayerSlider 93,178
bb-plugin 91,997
megamenu 88,536
premium-addons-for-elementor 88,535
akismet 87,226
mailchimp-for-wp 85,188
cleantalk-spam-protect 85,035
woocommerce-gateway-stripe 84,457
ml-slider 82,764
borlabs-cookie 81,569
fusion-builder 81,119
wp-pagenavi 80,609
ewww-image-optimizer 80,505
formidable 79,254

Top 50 Themes

Theme Count
hello-elementor 627,686
Divi 519,455
astra 431,031
flatsome 140,279
Avada 126,551
generatepress 124,831
pub 111,883
oceanwp 85,062
kadence 80,297
enfold 73,148
salient 67,774
twentytwentyfour 59,833
h4 57,433
twentyseventeen 57,275
bb-theme 55,987
betheme 52,878
cocoon-master 52,403
blocksy 51,939
dt-the7 47,031
twentytwentyfive 44,923
neve 40,199
Avada-Child-Theme 38,272
sydney 37,893
woodmart 33,918
gox 33,881
bridge 33,424
twentytwentyone 32,668
lightning 31,833
twentytwenty 30,617
swell 28,847
Impreza 27,049
bricks 26,563
twentytwentythree 24,358
Newspaper 24,061
voxel 23,714
kubio 20,713
sinatra 20,411
twentytwentytwo 20,219
uncode 19,485
epik-redesign 19,279
twentysixteen 18,605
storefront 18,237
pro 18,053
Total 14,987
extendable 14,808
yith-wonder 14,114
hello-theme-child-master 13,652
themify-ultra 13,248
yootheme 13,220
hestia 13,119