Privacy controls
CyberFurl can load analytics only after you opt in. Core product features work without analytics consent.
Deep scan your WordPress installation for exposed core files, unauthenticated REST API endpoints, directory traversal vulnerabilities, and leaky configurations. Ensure strict access controls and mitigate remote code execution (RCE) vectors.
WordPress powers a massive segment of the web, making it a prime target for automated exploitation. Exposed configuration files like wp-config.php (or backups like .bak, .old), open XML-RPC interfaces vulnerable to amplification attacks, and unauthenticated wp-json REST API endpoints frequently leak sensitive user enumeration data or infrastructure details. Failing to harden these vectors enables brute-force attacks, credential stuffing, and full system compromise. Technical validation ensures that web application firewall (WAF) rules and server-level block directives are correctly implemented according to OWASP Top 10 guidelines and HTTP semantics (RFC 7231) access control best practices.
Leaving xmlrpc.php accessible allows attackers to perform massive pingback DDoS amplification attacks and bypass standard login rate limiting via system.multicall methods.
Text editors and backup scripts often leave artifacts like wp-config.php.save or wp-config.php.bak in the webroot, which web servers serve as plain text, instantly compromising database credentials.
The scanner initiates non-destructive HTTP GET and HEAD requests to common WordPress sensitive paths, including /xmlrpc.php, /wp-json/, and legacy files like /readme.html.
We test for common configuration backup permutations (e.g., wp-config.old, wp-config.txt, .env) to verify that server routing rules actively deny access to non-PHP execution extensions.
The engine queries the WP REST API endpoints to determine if anonymous access yields user enumeration data, taxonomy metadata, or settings disclosures without a valid nonce or OAuth token.
Analyzes HTTP response headers (such as X-Powered-By, Server, and link relations) to detect unnecessary version footprinting and evaluates the presence of hardening headers.
Verifies whether the xmlrpc.php file is exposed and explicitly tests if the pingback.ping or system.multicall methods are active and exploitable.
Deep inspects the /wp-json/ namespace to identify unauthorized disclosure of author IDs, usernames, and hashed email addresses.
Scans the webroot for over 50 common backup file extensions and text editor swap files that might leak the critical wp-config.php database credentials.
Checks critical directories like /wp-content/plugins/ and /wp-includes/ for open directory indexing that facilitates plugin version fingerprinting.
Analyzes generator meta tags, readme.html files, and CSS/JS query strings (?ver=) to determine if your exact WordPress core version is being broadcasted to automated scanners.
Tests for the public accessibility of debug.log files within the /wp-content/ directory, which often contain sensitive stack traces, API keys, and PHP warnings.
Don't let leaky configurations or exposed endpoints compromise your CMS. Run our comprehensive WordPress Exposure Checker to identify and remediate critical structural vulnerabilities before attackers weaponize them.