How the snapshot runs
Each step is a lightweight, read-only check. Nothing is written back to your site.
Checks the URL and refuses private/internal addresses (SSRF-safe) before any request.
Reads transport security and response headers — HSTS, CSP, X-Frame-Options and more.
Detects WordPress, version exposure, and plugin/theme traces already visible in page assets.
Looks at login/XML-RPC reachability and a tiny fixed allowlist of sensitive files.
Explains the findings in plain language as an External Exposure Score — no content stored.
An external snapshot is limited by design. For exact plugin versions, malware, file integrity, and backup health, connect the PowerSEC plugin for a full internal scan.