The same checks WPVanguard runs against client sites.
A WordPress security audit checklist built from the WPVanguard scanner we run as a SaaS. Six categories, dozens of individual checks, all of them battle-tested against real WordPress sites in the wild.
Battle-tested against thousands of real WordPress sites
Security audit
✓Hosting + SSL hardened
✓Admin + users reviewed
✓Plugins + core scanned
✓File permissions checked
✓Malware + injection scan
✓Backups + monitoring on
80-plus checks; here are the headline six.
We built WPVanguard to automate the audit checklist below. The checklist
itself is what informed the scanner. Use the checklist to run a manual
audit, or use WPVanguard to run the same checks automatically every week.
What is inside
Six audit categories, every check in each.
Each category covers a real failure mode we have seen on compromised WordPress sites. The full checklist is what runs against every WPVanguard scan.
01
Core file integrity
Verify wp-admin and wp-includes against checksums for the installed WordPress version. Detect modified core files. Detect injected files in core directories. The first thing the WPVanguard scanner runs against any site.
→ Tampered core files detected in seconds.
02
Plugin and theme audit
Inventory installed plugins and themes. Cross-reference against WPScan and Patchstack vulnerability databases. Surface known CVEs. Surface plugins that have not received an update in 12 plus months. Recommend updates with risk-ranked priority.
→ Vulnerable plugins surfaced with severity, not just count.
03
User and admin audit
Inventory all users with administrative capabilities. Detect hidden admins (admin users hidden from the user list via filter). Audit application passwords. Surface stale accounts. Recommend access reviews.
→ Hidden admin accounts surface in audit.
04
Malware pattern scan
Hash every file in wp-content. Cross-reference against malware signature database. Scan for common webshell patterns, eval-based malware, base64 encoded payloads, suspicious obfuscation. Scan uploads directory for executable file types.
→ Malware found before it gets used.
05
Database integrity
Check options table for spam content. Check posts for injected JavaScript. Check user_meta for capability injection. Check for unauthorized cron events. Check for SQL injection markers in known tables.
→ Database-level compromise detected, not just file-level.
06
Configuration hardening
wp-config.php audit (debug mode, salts, file editing). .htaccess hardening. File permission audit. SSL configuration. REST API exposure check. Application password availability. Recommend hardening with one-click apply where safe.
→ Hardening recommendations come with apply paths.
What honestly to expect
The downloadable version is in progress. The current internal version is
shared on request and goes out within four business hours. WPVanguard
runs the same checks automatically as a paid SaaS at wpvanguard.com.
How to use it
Run a baseline audit against your WordPress site today. Document findings.
Triage by severity. Fix the criticals immediately. Schedule the
non-criticals into your next maintenance window. Re-run monthly to catch
drift. Re-run after any major plugin update or unusual traffic event
immediately.
What the checklist does not replace
A real penetration test by a security firm. The checklist surfaces
common WordPress-specific issues. A pen test surfaces application logic
vulnerabilities the checklist will not catch. Both are valuable for
different stages of security maturity.
Common questions
Frequently asked
Is the checklist downloadable?
The downloadable version is in progress. The current internal version is shared on request and goes out within four business hours. WPVanguard runs all of these checks automatically as a paid service.
Can we run these checks ourselves?
Yes. Each item on the checklist can be run manually or with WP-CLI. WPVanguard packages them into a SaaS so you do not have to. For one-off audits, manual is fine. For ongoing monitoring, automation is cheaper.
How often should we run a security audit?
For active sites with frequent plugin updates, monthly or weekly. For low-change sites, quarterly. After any major plugin update or after any unusual traffic event, immediately.
What if the audit finds something?
Severity-ranked findings, with remediation steps for each. Critical findings (active malware, compromised admin) trigger emergency response procedures. Non-critical findings go into the next maintenance window. WPVanguard automates the common remediation steps.
Where to go next
If the checklist turns up more than you want to fix
Working through this yourself is the right first move. These are the services for what it finds.
WBComDesigns is amazing. The WP plugins and themes are of top notch quality with lots of features and updated very frequently. Supports are very responsive and helpful. I use Reign with TutorLMS, and the experience is surprisingly smooth.…
Hoang Phan·VN·
The job well done!
The job well done, well in time - Thanks so much Anmbiya and team!
Happy Client·ZA·
WBCOM Designs is Amazing!
WBCOM Designs has constantly updated and supported their plugins and themes. Recently the new BuddyNext project is Amazing! - and the new line of addons like Mediaverse, Jetonomy, Mediashield, and Listora.. are likewise Amazing! - and very…
Edward S.·US·
High quality WordPress plugins and themes
We’ve hosted a number of Wbcom Designs clients on Levamo, and our experience with their products has been very positive. Their plugins and themes are well built, their support has been reliable, and they seem to be very innovative and…
Michael Eisenwasser·US·
I have worked with Wbcom Designs on…
I have worked with Wbcom Designs on several custom development requests for my WordPress platform, and my experience has been excellent.
christian nicolas·BJ·
Love this company
Love this company. Loved the REIGN product. They were there the entire time helping me set things up; and when things went wrong? They were quick to take action and help find a solution.
Fable Fortitude·CA·
Seriously, one of the best "software tech experiences" I've ever had!
After 16 years of buying WordPress themes and plugins, I know exactly what bad support looks like and Wbcom Designs is the polar opposite. My setup was a nightmare: multiple tools, deep integrations, custom configurations that required…
Duston McGroarty·US·
I was using an excellent plugin created…
I was using an excellent plugin created by Wbcom Designs and had both an error and discovered a slight bug in one aspect of the plugin. After creating a support ticket - I got a super-quick response and discovered the error was on my part…
Edward Bonthrone·US·
Excellent Theme, Powerful Plugins and Outstanding Support
I am using the REIGN theme and several plugins from Wbcom Designs on my website. The theme is beautifully designed, and the plugins are user-friendly. Everything works smoothly, and the features are perfect for building professional…