From SSL analysis to a four-source vulnerability intelligence engine, EzyAudit AI covers every critical security surface β and tells you exactly how to fix what it finds.
Full certificate chain validation, expiry alerts (30/14/7-day warnings), key strength and signature-algorithm analysis (flags weak SHA-1 signatures and undersized keys), hostname and SAN coverage, TLS version enforcement, cipher-suite analysis, legacy-vulnerability checks (Heartbleed, POODLE, FREAK, Logjam), and HSTS verification.
Checks for all critical security headers: HSTS, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Permissions-Policy, Referrer-Policy, and Cross-Origin-Opener-Policy, plus weak Content-Security-Policy detection.
Validates SPF (and enforcement strength), DMARC (flagging weak p=none policies), DKIM, DNSSEC, MTA-STS, TLS-RPT, and CAA records to protect your domain from spoofing, phishing, and mail interception. Flags missing or misconfigured records.
Automatically identifies the WordPress version (flagging outdated or insecure core against the official WordPress.org release data), installed plugins, and themes from HTML source, asset URLs, and readme files β without authentication.
Verifies all HTTP requests redirect to HTTPS, checks for mixed-content issues, and validates that HTTPS is enforced across the full domain.
Detects exposed server banners, PHP and WordPress version leaks, debug logs, exposed .git/.svn/.env files, configuration and database backups, and other sensitive files reachable from the web.
Checks your domain against the Google Safe Browsing blocklist and scans the homepage for signs of compromise: injected cryptocurrency miners, obfuscated JavaScript, and hidden malicious iframes.
Detects both network and edge firewalls (Cloudflare, Sucuri, Imperva, Akamai, AWS WAF and more) and application-layer security plugins such as Wordfence, Solid Security, NinjaFirewall and Shield.
Probes for publicly exposed databases (MySQL, PostgreSQL, Redis, MongoDB) and risky services (FTP, SSH, RDP, VNC, Memcached), and flags server-hardening gaps such as dangerous HTTP methods (TRACE, PUT, DELETE), wildcard crossdomain/CORS policies, exposed server-status pages, and dangling-CNAME subdomain-takeover risks.
Compares your exact installed plugin version against structured version ranges from each source. If your version is patched, the finding is suppressed. Precise results, not noisy slug-matching.
Live feed of vulnerabilities actively being exploited in the wild, maintained by the US Cybersecurity and Infrastructure Security Agency. Updated daily.
National Vulnerability Database with a full 365-day lookback window. Parses structured CPE version data (versionEndExcluding) for exact range matching β no regex guesswork.
WordPress-specific intelligence for the top most-installed plugins. Returns exact fixed_version data per CVE and enriches NVD records with precise version information.
33,000+ WordPress CVEs with detailed severity scores, patched version data, and real-time updates from one of the most respected names in WordPress security.
All four sources update automatically every 24 hours via a background cron job. Force Update Now available in WP Admin β EzyAudit AI β Vuln Database.
Each finding includes an AI-generated plain-English explanation of what it means for your specific site, why it matters, and step-by-step fix instructions.
A risk-weighted grade that reflects the severity and exploitability of findings β not just a count of issues. Understand your real risk level at a glance.
Download polished PDF reports with executive summary, finding cards, severity breakdown, and remediation priority list. White-label ready for agencies.
Agency plan users can brand every report with their own logo, company name, and colour scheme. Your brand, your deliverable, powered by EzyAudit AI.
Track security score changes over time to measure the impact of your fixes and demonstrate security improvements to clients.
Every issue includes severity level, CVE identifier (where applicable), CVSS score, affected component version, and a direct link to the vulnerability disclosure.
Enable automated scanning on any verified domain for ongoing security oversight. Choose how often each domain is re-scanned - daily, weekly, or monthly - and get an instant alert whenever a new critical issue appears or your security score drops.
Receive email notifications when SSL certificates approach expiry, new vulnerabilities are discovered in your stack, or your security score drops.
Manage all your domains from a single unified dashboard. See at-a-glance security scores, last scan dates, and outstanding findings across every site.
Run a comprehensive 95-point security scan in 90 seconds. Get your score, your grade, and AI-generated fix instructions immediately.
Connect with our support team:
Or check our FAQ page for common questions →