
Scan any WordPress site to surface webshells, outdated cores and the exposed endpoints attackers love.
TRUSTED BY 6,000+ SECURITY-CONSCIOUS TEAMS
Probes known backdoor paths and webshell fingerprints.
Identifies WordPress version via meta and readme leaks.
Flags xmlrpc, wp-login, REST user enumeration and more.
Detects debug.log, directory listing and open uploads.
Checks CSP, HSTS, X-Frame-Options and other headers.
Weighted security score with actionable remediation.
Enter any site — WordPress or unknown. HTTPS is added automatically.
Read-only checks against public paths — no exploits, no brute force.
Get a weighted score plus per-finding remediation guidance.
Yes — ShellHunt only performs unauthenticated GETs against well-known public paths. No exploits, credentials or brute force.
Only scan sites you're authorized to test. You are responsible for compliance with local laws and terms of service.
A family of PHP webshells commonly dropped into WordPress uploads or plugin directories after compromise. ShellHunt probes the paths where they typically appear.
No public scanner can. ShellHunt covers the most common misconfigurations and drop points — pair it with a full audit for high-risk sites.