Starting at only $ 79 a month.
Cancel at anytime! 14 Days Money Back Guarantee. No questions asked.
Best Value Deal
Still having doubts and trouble deciding? Get Answers.
Get the Facts & Proof about Aegisify Audit at https://secure.aegisify.com/facts-proof/
How can Aegisify AI help?
Ask about Aegisify or WordPress: errors, plugins, security, SEO, compatibility, troubleshooting, comparisons, or launch a free website scan.
Find the signal. Filter the noise. Act with evidence.
1,000+ WordPress Security Audit Touchpoints, Vulnerability, Code, Compliance, and Risk Intelligence Capabilities
Aegisify Audit combines WordPress security audit intelligence, external DAST, authenticated offensive testing, static code security analysis, software supply-chain vulnerability scanning, malware heuristics, file-integrity monitoring, WooCommerce security review, STIG/SRG-style posture checks, activity evidence, and SaaS reporting in one connected Agent-to-SaaS workflow.
Instead of treating external scans, local WordPress evidence, source code, dependencies, logs, configuration, and business risk as separate products,
Aegisify brings those signals together so site owners, agencies, ecommerce teams, and security operators can see what matters, understand why it matters,
and prioritize the next safe action.
One Connected WordPress Security Intelligence Workflow
The Aegisify Audit SaaS reviews the public attack surface, browser behavior, APIs, routes, sessions, and externally observable security conditions. The Aegisify Agent adds authenticated local evidence from WordPress core, plugins, themes, code, dependencies, database posture, WooCommerce, files, permissions, activity, telemetry, and approved logs. The SaaS can then correlate those evidence sources, assign severity and confidence, compare historical drift, and produce stored or PDF reports.
This inventory includes active tests, passive observations, inventory collectors, continuous sensors, conditional authenticated checks, and report evidence. It should not be interpreted as 292 separate exploit attempts or as a guarantee that every possible vulnerability will be detected.
External Exposure, TLS, and Browser Hardening
- HTTPS reachability and HTTP-to-HTTPS redirect behavior
- TLS certificate validity and expiration posture
- Mixed-content and downgrade indicators
- HSTS and Content Security Policy review
- Frame and clickjacking protection
- Referrer Policy and MIME-sniffing protection
- Permissions Policy and cache-control posture
- Secure, HttpOnly, and SameSite cookie attributes
- Sensitive public-file exposure
- WordPress login and administrative boundary exposure
- Public route, form, and parameter discovery
- JavaScript and source-asset discovery
SaaS DAST and Active Security Testing
The SaaS implementation contains 41 explicit DAST rules covering externally
observable application risk and safe active probes.
- Open redirects, reflected XSS, and stored-XSS candidates
- SQL injection and NoSQL injection indicators
- SSRF, path traversal, and parameter-pollution indicators
- CSRF and WordPress nonce posture
- Session fixation, logout invalidation, and timeout posture
- Unauthenticated administrative exposure
- IDOR/BOLA and privilege-escalation candidates
- HTTP verb tampering and sensitive caching
- Upload workflow discovery
- API authentication and unauthenticated method exposure
- Excessive data exposure and schema mismatch
- Mass-assignment and token-in-URL indicators
- GraphQL introspection, depth, and complexity indicators
- OpenAPI and Swagger discovery
- DOM-XSS, source-map, client-secret, and token indicators
- Third-party script inventory and attack-surface graphs
- Route-contract harvesting and role-replay coverage
Authenticated and Advanced Offensive Testing
- Authenticated route discovery
- Multi-role authenticated surface mapping
- Guest-versus-role comparisons
- Session fixation and session-aging review
- Logout invalidation and remember-me posture
- GraphQL schema and type-relationship mapping
- OpenAPI contract import
- Browser-assisted route discovery
- Object-level authorization replay candidates
- Safe workflow and stored-XSS candidates
WordPress Hardening and Misconfiguration Review
- WordPress version and core-version inventory
- XML-RPC status
- Production debug exposure
- WordPress file-editor controls
- File-modification controls
- Administrative SSL enforcement
readme.htmlexposure- Privileged configuration and recovery posture evidence
Known Vulnerabilities and Software Supply Chain
- WordPress core, plugin, and theme vulnerability matching
- CVE identifiers, CVSS details, and fixed versions when available
- Available core, plugin, and theme updates
- Disabled automatic updates and inactive components
- Installed plugin and theme inventory
- Composer manifest and advisory-tool discovery
- npm, Yarn, and pnpm manifest and audit-tool discovery
- Python dependency and
pip-auditvisibility - Dependency evidence for deeper Agent-side risk analysis
Static Code Security Analysis
- Unsafe database-query concatenation and prepared-query misuse
- Unsafe uploads, dynamic evaluation, and dynamic includes
- Unsafe deserialization and SSRF-prone requests
- Missing capability and nonce checks
- Weak REST permission callbacks
- Sensitive option modification and unsafe shortcode output
- Token, secret, and sensitive-data logging indicators
- Dangerous database tooling and excessive-grant references
- Direct-access guards, updater safety, and uninstall safety
- JavaScript DOM-XSS, unsafe templating, and browser token storage
- Insecure JavaScript REST requests and missing nonce headers
- Python shell execution, pickle, dynamic SQL, SSRF, and debug indicators
- Bundled PHPCS/WPCS checks for SQL, validation, escaping, redirects, settings, internationalization, performance, and forbidden functions
Malware Heuristics, Integrity, Permissions, and Drift
- PHP and PHTML inspection in plugin and theme directories
- Executable-file inspection in uploads
- Dangerous execution-function indicators
- Encoding, decompression, and decode-and-execute chains
- Long encoded payload and variable-function indicators
- PHP files found in upload locations
- Suspicious-file heuristics
- Baseline file hashing
- New, changed, and removed file detection
- World-writable files and directories
- Recently modified executable-file review
STIG/SRG-Style Compliance Posture
- Secure, HttpOnly, and SameSite cookies
- HSTS, CSP, frame protection, Referrer Policy, and MIME protection
- XML-RPC restrictions
- REST authentication and public
admin-ajax.phpboundaries - Disabled WordPress file editors
- Strict database SQL modes
- Excessive ALL, FILE, SUPER, GRANT OPTION, CREATE USER, and PROCESS privileges
- Disabled
local_infileand restrictedsecure_file_priv - Database SSL availability or enforcement
- Database engine and version identification
WooCommerce and Commerce Risk Intelligence
- WooCommerce version, update status, and API surface
- Checkout availability, TLS, and checkout implementation mode
- Guest checkout and account-creation settings
- Payment-gateway inventory and tokenization indicators
- Payment debug logging and test-versus-live indicators
- Webhook inventory, missing secrets, and insecure destinations
- REST API-key metadata and privilege review
- Legacy API and HPOS posture
- Action Scheduler backlog and failures
- Outdated template overrides and sensitive commerce logs
- Privileged commerce users and business-impact evidence
- Commerce risk scoring and workflow correlation
WordPress Activity and Security Evidence
The Agent records 47 event types that support continuous auditing and
incident context.
- Login, logout, and password-reset activity
- User creation, modification, deletion, role, and capability changes
- Plugin activation, deactivation, update, and deletion
- Theme activation, update, and deletion
- WordPress core updates
- Post and page creation, update, deletion, and restoration
- Option, media, comment, taxonomy, category, and menu changes
- Administrative and system-change evidence
Telemetry, Logs, Correlation, Risk Scoring, and Reporting
- Agent connectivity and capability reporting
- WordPress, PHP, and site telemetry
- Cron and operational-health visibility
- Recovery-mode visibility
- Approved debug-log and application-log retrieval
- WordPress activity ingestion
- External and internal evidence correlation
- Finding severity and confidence
- Drift and historical comparison
- Stored report generation
- PDF security report generation
- Connected evidence for prioritization and human review
Do Not Forget Aegisify’s Defensive Security Tools
Aegisify Audit helps identify, analyze, correlate, and report WordPress security risk. Aegisify Shields and Aegisify WAF
add defensive controls that help reduce exposure, strengthen WordPress, and protect application traffic. Together,
they support a connected detect, understand, and defend security workflow.
Aegisify distinguishes between observed, suspected, verified, active-safe, authenticated replay, and write-safe findings. These labels help customers understand whether a result came from passive evidence, a safe probe, an authenticated comparison, or a controlled test. View our Facts and Proof Center.

Got Questions? We got Answers.
Still need answers, contact us today! Or request a demo, get front row.


