Free · no signup · no email
Is your WordPress site fast — and quietly exposed?
Enter your URL for a plain-language audit: mobile and desktop PageSpeed, Core Web Vitals, and a handful of read-only WordPress security checks. Nothing is stored, nothing is changed.
What this checks
- Mobile & desktop performance scores from Google PageSpeed Insights.
- Largest Contentful Paint (LCP) rated against Core Web Vitals thresholds.
- Whether the site runs WordPress, and which version it discloses.
- Public username enumeration via the REST API (/wp-json/wp/v2/users).
- Whether xmlrpc.php is live (a brute-force / DDoS amplification vector).
- Exposed uploads directory listing and a public readme.html.
- Whether WordPress core is behind the latest stable release.
This is an informational, read-only audit — every check is a plain GET request. It doesn't attempt logins, enumerate plugins, or exploit anything.
Tired of patching WordPress?
Most of these issues simply don't exist on a headless CMS. WPEscape moves your content, media, SEO and multilingual setup off WordPress cleanly.