Exposure

What the outside world can already see about a WordPress site.

Every public WordPress site gives away some information to anyone who asks. Some of it matters for security, most of it can’t be read from the outside at all. Here is the honest picture — and where the line runs between guessing and actually knowing.

Three honest statuses

We don’t pretend to see more than we can.

A lot of “security scanners” guess and then present the guess as fact. We use three clear labels instead.

Detected

Visible in the public source of the site — readable by anyone, including anyone looking for a way in.

Not publicly detectable

Cannot be read from the outside. Anyone claiming to know this without access is guessing.

Needs Verploy Connector

Only measurable from inside the site, through the connector you install and control.

What’s visible, what isn’t

The typical WordPress site, from the outside.

This is the general picture for a standard install. Your own site may hide more or less, depending on how it’s configured.

WordPress core version

Detected

Often exposed through the page source, feeds or a readme file — unless it has been deliberately hidden.

Active theme & some plugins

Detected

Asset paths and readme files reveal many themes and plugins, sometimes with a version number attached.

Login page & author names

Often detected

The admin login is at a predictable address, and author archives can leak usernames unless they’re blocked.

Premium & paid plugins

Not publicly detectable

Many paid plugins leave no public fingerprint, so an outside scan simply misses them.

Server health & disk space

Mostly hidden

The SSL certificate is public, but PHP version, memory and free disk space usually aren’t readable from outside.

Whether an update is actually needed

Needs Verploy Connector

Knowing the exact installed versions of everything — and which really have a pending update — takes access from inside.

Which vulnerabilities really apply

Needs Verploy Connector

A version guessed from the outside can be wrong. Matching a site to the vulnerabilities that truly affect it needs the exact versions.

Whether a fix is safe to apply

Needs Verploy Connector

Only a test on a copy of the real site shows whether an update breaks anything before it goes live.

Why we don’t scan strangers’ sites

A public vulnerability scanner is a gift to attackers.

A tool that lists the weak points of any site you type in is exactly what someone looking for a target would use. So we don’t build that.

  • Verploy only analyses sites that are connected through the Verploy Connector — sites you own or manage.
  • That connection proves the site is yours before any check runs.
  • From inside, the results are exact instead of guessed — no false alarms, no missed paid plugins.

Get the full picture of your own sites.

Connect a site and Verploy reads the exact versions, the vulnerabilities that truly apply, and whether each update is safe to put live — the parts no outside scan can reach.