WPEscape

Free · no signup · no email

Is your WordPress site fast — and quietly exposed?

Enter your URL for a plain-language audit: mobile and desktop PageSpeed, Core Web Vitals, and a handful of read-only WordPress security checks. Nothing is stored, nothing is changed.

What this checks

  • Mobile & desktop performance scores from Google PageSpeed Insights.
  • Largest Contentful Paint (LCP) rated against Core Web Vitals thresholds.
  • Whether the site runs WordPress, and which version it discloses.
  • Public username enumeration via the REST API (/wp-json/wp/v2/users).
  • Whether xmlrpc.php is live (a brute-force / DDoS amplification vector).
  • Exposed uploads directory listing and a public readme.html.
  • Whether WordPress core is behind the latest stable release.

This is an informational, read-only audit — every check is a plain GET request. It doesn't attempt logins, enumerate plugins, or exploit anything.

Tired of patching WordPress?

Most of these issues simply don't exist on a headless CMS. WPEscape moves your content, media, SEO and multilingual setup off WordPress cleanly.