WordPress Security Scan
Suspicious code, outdated software and risky settings found, with AI filtering out false alarms.
Birtikta's security scan checks a WordPress site for suspicious code, outdated software, modified core files, risky configuration and dangerous file permissions, then has AI review the serious findings to filter out false alarms. You get a score out of 100, a letter grade and a list of issues with a recommendation for each, and you can scan one site or all of them automatically every week.
AI checks the serious findings
Pattern-based scanners raise many false alarms. Birtikta sends critical and high findings to AI in two stages: a quick first look, then a detailed review of the file content for anything still flagged. Core files are also compared with the official WordPress checksums.
Automatic scans on a schedule
Switch on automatic scan for a site, or for all sites at once, and it is scanned every week. From the Professional plan up you can choose daily scans. When a scan finds critical or high issues, the Malicious Code Tracking alarm lets you know.
What the WordPress security scan checks
Suspicious code
Known shell signatures, backdoor patterns and risky functions in PHP files across the site.
Outdated software
An old WordPress version, and plugins or themes with an update waiting.
Plugin updateCore file integrity
WordPress core files that differ from the official versions.
Risky configuration
Debug mode on, file editing allowed, no SSL, or a user named "admin".
File permissions
wp-config.php or .htaccess left open with 777 permissions.
Vulnerability database
Browse known plugin and theme vulnerabilities, updated every day, with severity scores.
Good to know
The scan finds problems; it does not remove them. If malicious code needs cleaning, our malware cleanup service can take care of it. Plugin and theme findings are based on available updates, while the vulnerability database is a separate page you can search.
Frequently Asked Questions
Suspicious code such as known shell signatures and backdoor patterns, an outdated WordPress version, plugins and themes with pending updates, core files that differ from the official versions, risky settings like debug mode or file editing, missing SSL, a user named admin, and 777 permissions on wp-config.php or .htaccess.
Critical and high findings are reviewed by AI in two stages. Items the AI judges safe are filtered out, and the rest come with an explanation, so you spend less time on false alarms.
Automatic scan runs weekly by default. Daily scans are available on the Professional plan and above. You can also start a scan for one site or all sites at any time.
Each scan produces a score from 0 to 100 and a grade from A+ to F, along with the number of critical, high, medium, low and informational issues.
No. The scan detects problems and suggests what to do. For cleaning an infected site, see the malware cleanup service.
Yes. Mark it as Not a Threat and it will not be shown in future scans of that site.