[ 01 / 06 ][ hero ]
| WordPress security scanner |

Detect wp2shell in seconds.

Scan any WordPress site to surface webshells, outdated cores and the exposed endpoints attackers love.

TRUSTED BY 6,000+ SECURITY-CONSCIOUS TEAMS

NEBULA
ORBIT
VANTA
QUASAR
HELIO
PULSAR
[ 02 / 06 ][ features ]

Every check an auditor runs, in one request.

wp2shell detection

Probes known backdoor paths and webshell fingerprints.

Version fingerprint

Identifies WordPress version via meta and readme leaks.

Exposed endpoints

Flags xmlrpc, wp-login, REST user enumeration and more.

Config leaks

Detects debug.log, directory listing and open uploads.

Header audit

Checks CSP, HSTS, X-Frame-Options and other headers.

Instant report

Weighted security score with actionable remediation.

[ 03 / 06 ][ how to use ]
01

Paste a URL

Enter any site — WordPress or unknown. HTTPS is added automatically.

02

We probe safely

Read-only checks against public paths — no exploits, no brute force.

03

Read the report

Get a weighted score plus per-finding remediation guidance.

[ 04 / 06 ][ what we check ]

Detection surface.

  • 01wp2shell + common webshell drop paths (uploads, plugins, root)
  • 02WordPress core version + outdated release warning
  • 03readme.html and version disclosure files
  • 04xmlrpc.php exposure (pingback DDoS, brute-force vector)
  • 05wp-login.php public access
  • 06Directory listing on wp-content/uploads
  • 07REST /wp-json/wp/v2/users enumeration
  • 08wp-content/debug.log exposure
  • 09Missing CSP / HSTS / X-Frame-Options headers
[ 05 / 06 ][ faqs ]

Common questions.

Is this scan safe / non-intrusive?

Yes — ShellHunt only performs unauthenticated GETs against well-known public paths. No exploits, credentials or brute force.

Do I need to own the site I scan?

Only scan sites you're authorized to test. You are responsible for compliance with local laws and terms of service.

What is wp2shell?

A family of PHP webshells commonly dropped into WordPress uploads or plugin directories after compromise. ShellHunt probes the paths where they typically appear.

Will it catch every vulnerability?

No public scanner can. ShellHunt covers the most common misconfigurations and drop points — pair it with a full audit for high-risk sites.