{"uid":"cap_laejpMCaGJd4Bv92XGt8l","slug":"wordpress-security-posture-assessor-d69e0eee","name":"WordPress Security Posture Assessor","description":"WordPress security posture check — PASSIVE hygiene assessment from public signals: detects WordPress, flags version disclosure (generator tag, readme.html), xmlrpc.php exposure, user enumeration, uploads directory listing, login exposure, missing security headers, and HTTPS. Returns a 0-100 posture score with prioritized remediation. Flags security practice, not exploitable vulnerabilities — no CVE matching, no intrusion. For site owners and authorized auditors. ?url=","url":"https://api.webbersites.com/api/wp/assess","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"queryParams":{"type":"object","required":["url"],"properties":{"url":{"type":"string","description":"WordPress site URL to assess (homepage)"}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object","properties":{"grade":{"type":"string"},"findings":{"type":"array"},"is_wordpress":{"type":"boolean"},"posture_score":{"type":"number"}}}}}}},"responseSchema":{"type":"json","example":{"url":"https://example.com","grade":"C","findings":[{"fix":"Disable XML-RPC if unused…","area":"xmlrpc","detail":"xmlrpc.php is reachable…","severity":"medium"}],"disclaimer":"Passive hygiene assessment from public signals only.","is_wordpress":true,"posture_score":71,"finding_counts":{"low":3,"medium":2}}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.005","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.005/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.005","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.005","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_wsWDOlMYI9R0slW5F8nF9","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.005","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Performs a passive WordPress security hygiene check on a public site URL, returning a 0-100 posture score and prioritized remediation findings.","exampleAgentPrompt":"Can you run a passive security posture check on my WordPress site at https://myblog.example.com and tell me the score, grade, and what I should fix first?","exampleUseCases":null,"resultDescription":"Returns a JSON object containing a 0-100 posture score, a letter grade, a boolean indicating whether the site is WordPress, and an array of prioritized findings covering issues like version disclosure via generator tag or readme.html, xmlrpc.php exposure, user enumeration risk, uploads directory listing, login page exposure, missing security headers, and HTTPS status.","failureModes":["Non-WordPress site returns is_wordpress: false with limited findings","Invalid or unreachable URL returns an error response","Rate limiting or network timeout if target site is slow","Private/localhost URLs may be rejected for security reasons","Score may be incomplete if target blocks crawler user agents"],"whenToPreferThis":"Use this endpoint when you need a quick, passive, read-only WordPress-specific security hygiene assessment from publicly observable signals — especially useful for site owners or authorized auditors who want actionable remediation priorities without running active exploits or CVE scans. Prefer this over generic web security scanners when the target is known to be WordPress and you need a structured posture score.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T12:56:48.138Z","isFirstParty":false}