The same checks WPVanguard runs against client sites.
A WordPress security audit checklist built from the WPVanguard scanner we run as a SaaS. Six categories, dozens of individual checks, all of them battle-tested against real WordPress sites in the wild.
Battle-tested against thousands of real WordPress sites
Security audit
✓Hosting + SSL hardened
✓Admin + users reviewed
✓Plugins + core scanned
✓File permissions checked
✓Malware + injection scan
✓Backups + monitoring on
80-plus checks; here are the headline six.
We built WPVanguard to automate the audit checklist below. The checklist
itself is what informed the scanner. Use the checklist to run a manual
audit, or use WPVanguard to run the same checks automatically every week.
What is inside
Six audit categories, every check in each.
Each category covers a real failure mode we have seen on compromised WordPress sites. The full checklist is what runs against every WPVanguard scan.
01
Core file integrity
Verify wp-admin and wp-includes against checksums for the installed WordPress version. Detect modified core files. Detect injected files in core directories. The first thing the WPVanguard scanner runs against any site.
→ Tampered core files detected in seconds.
02
Plugin and theme audit
Inventory installed plugins and themes. Cross-reference against WPScan and Patchstack vulnerability databases. Surface known CVEs. Surface plugins that have not received an update in 12 plus months. Recommend updates with risk-ranked priority.
→ Vulnerable plugins surfaced with severity, not just count.
03
User and admin audit
Inventory all users with administrative capabilities. Detect hidden admins (admin users hidden from the user list via filter). Audit application passwords. Surface stale accounts. Recommend access reviews.
→ Hidden admin accounts surface in audit.
04
Malware pattern scan
Hash every file in wp-content. Cross-reference against malware signature database. Scan for common webshell patterns, eval-based malware, base64 encoded payloads, suspicious obfuscation. Scan uploads directory for executable file types.
→ Malware found before it gets used.
05
Database integrity
Check options table for spam content. Check posts for injected JavaScript. Check user_meta for capability injection. Check for unauthorized cron events. Check for SQL injection markers in known tables.
→ Database-level compromise detected, not just file-level.
06
Configuration hardening
wp-config.php audit (debug mode, salts, file editing). .htaccess hardening. File permission audit. SSL configuration. REST API exposure check. Application password availability. Recommend hardening with one-click apply where safe.
→ Hardening recommendations come with apply paths.
What honestly to expect
The downloadable version is in progress. The current internal version is
shared on request and goes out within four business hours. WPVanguard
runs the same checks automatically as a paid SaaS at wpvanguard.com.
How to use it
Run a baseline audit against your WordPress site today. Document findings.
Triage by severity. Fix the criticals immediately. Schedule the
non-criticals into your next maintenance window. Re-run monthly to catch
drift. Re-run after any major plugin update or unusual traffic event
immediately.
What the checklist does not replace
A real penetration test by a security firm. The checklist surfaces
common WordPress-specific issues. A pen test surfaces application logic
vulnerabilities the checklist will not catch. Both are valuable for
different stages of security maturity.
Common questions
Frequently asked
Is the checklist downloadable?
The downloadable version is in progress. The current internal version is shared on request and goes out within four business hours. WPVanguard runs all of these checks automatically as a paid service.
Can we run these checks ourselves?
Yes. Each item on the checklist can be run manually or with WP-CLI. WPVanguard packages them into a SaaS so you do not have to. For one-off audits, manual is fine. For ongoing monitoring, automation is cheaper.
How often should we run a security audit?
For active sites with frequent plugin updates, monthly or weekly. For low-change sites, quarterly. After any major plugin update or after any unusual traffic event, immediately.
What if the audit finds something?
Severity-ranked findings, with remediation steps for each. Critical findings (active malware, compromised admin) trigger emergency response procedures. Non-critical findings go into the next maintenance window. WPVanguard automates the common remediation steps.
Want continuous WordPress security monitoring?
Use WPVanguard or run the checklist.
WPVanguard runs the same checks automatically every week. Manual checklist is yours on request.
Seriously, one of the best software tech experiences I've ever had!
After 16 years of buying WordPress themes and plugins, I know exactly what bad support looks like and Wbcom Designs is the polar opposite. My setup was a nightmare: multiple tools, deep integrations, custom configurations that required…
Duston McGroarty·US·
Great service, great plugins
I was using an excellent plugin created by Wbcom Designs and had both an error and discovered a slight bug in one aspect of the plugin. After creating a support ticket I got a super-quick response and discovered the error was on my part…
Edward Bonthrone·US·
Excellent Theme, Powerful Plugins and Outstanding Support
I am using the REIGN theme and several plugins from Wbcom Designs on my website. The theme is beautifully designed, and the plugins are user-friendly. Everything works smoothly, and the features are perfect for building professional…
S W Malcolm·US·
The best development team ever
It has been a very pleasurable experience working with Wbcom Designs. Anmybia Siddiqui has been a stellar leader of the dev team. Her communications are very professional and productive. Anmybia and her team have completed every task we…
Real America's Voice News·US·
Top notch support
Top notch support. I have been frustrated generally by the slow support for most themes and plugins, but they are helpful and quick to reply. Highly recommend.
Woods·DE·
I was impressed
I have worked with many WordPress plugins over the past 14 years part time. I have learned that if the support is not prompt and effective it is a sign to move on. Tonight, Wbcom has impressed me and I will be hiring them for some more…
Steve Valencia·US·
Perfect plugins for community sites
I wanted to build a community website and these guys created the perfect plugins for me. To be honest, I want to buy every single one of their plugins. If I had more money I would.
Sora Seaton·US·
Excellent Plugins and Outstanding Support
We use BuddyPress with several free BP plugins from Wbcom Designs, and we are extremely satisfied. The plugins add real value for our community, are updated regularly, and are continuously improved. They integrate seamlessly with their…
Peter Gibson·DE·
Great and very supportive
This company have been great and very supportive. I highly recommend them.
Steve s·GB·
Excellent template and first-class support
The template from Wbcom Designs is truly great, modern, flexible, and easy to use. The support is very helpful and friendly. For questions or problems you receive fast, competent assistance and feel well taken care of. Highly recommended.