What Hackers See On My Website: The Outside of Your WordPress Site
Long before anyone touches your login page, your website quietly tells the outside world a great deal about itself, and a little of that knowledge is all an attacker needs to start.
By Nathan Cross, Co-Founder, Network & Security Engineering·
Reconnaissance comes before the attack
When people ask what hackers see on my website, the honest answer is: a surprising amount, and none of it requires a password. Most break-ins do not start with a dramatic hack. They start with reconnaissance: an automated tool, or a person, simply looking at your website from the public internet and noting down everything it freely admits. None of it touches the inside of your site. It is the digital equivalent of someone walking past your shop, reading the sign, checking which door is unlocked and noting the brand of lock on the back gate.
A passive external scan does exactly the same thing, on your side, so you can see what they see. It looks at your DNS records, your email security settings, your TLS certificate, your HTTP security headers, any files you have accidentally left exposed, and any software versions your site happens to announce. Here is what each of those reveals.
Your DNS and email settings are public by design
Your domain name system (DNS) records are meant to be readable by everyone, because that is how the internet finds your site and routes your email. The trouble is that the same records tell an attacker who hosts your site, who runs your email, and which services you depend on. That shapes their next move.
The bigger external risk is email spoofing. Three records, SPF, DKIM and DMARC, tell receiving mail servers whether a message claiming to be from your domain is genuine (Cloudflare). If those records are missing or weak, anyone can send email that appears to come from you, which is the engine behind invoice fraud and convincing phishing aimed at your customers and staff. A passive scan can read these in seconds, and so can the attacker.
Your certificate and headers describe the front door
Your TLS certificate (the padlock in the browser) is presented to every visitor, so its details are entirely public: who issued it, when it expires, and whether it is configured correctly. An expired or misconfigured certificate is both a trust problem for customers and a signal that the site may not be closely maintained.
Your HTTP security headers are just as visible. These are small instructions your server sends with every page that tell the browser how to behave, for example whether to force a secure connection or block certain attacks. When they are absent, an attacker learns that some common, free protections were never switched on, which often hints at a site that has not been hardened (WordPress.org). All of this is readable without logging in.
Exposed files and leaked versions: more of what hackers see on my website
Websites frequently leave files in public that were never meant to be browsed: backup archives, configuration samples, log files, installer scripts, directory listings. A scanner that simply requests common filenames will find them, and so will an attacker. A single exposed backup can contain database credentials or customer data.
Version leaking is the quiet one. WordPress, and especially its plugins and themes, often announce their exact version number in the page source, in file paths, or in a readme file. Once an attacker knows you are running a specific plugin at a specific version, they can look up its known vulnerabilities and walk straight to the weakness. This matters because plugins account for roughly 96% of WordPress vulnerabilities, while only a handful are ever found in WordPress core itself (Patchstack). The version number on the outside is the first half of the attack; the vulnerable plugin on the inside is the second.
Why the outside view is only half the story
A good external scan tells you what is leaking and what is misconfigured at the perimeter, and you should absolutely fix those things. But the perimeter is not where most WordPress sites are actually compromised. The damage usually happens inside: an out-of-date plugin with a known flaw, a theme nobody updates, an admin account without two-factor authentication, file changes you cannot see from the street.
From the outside, you can sometimes guess at a version number. From the inside, you can know it. BadgerScan runs the passive external check for free, then Pro adds a read-only WordPress plugin that reads the exact plugin, theme and core versions, checks admin configuration and 2FA, and looks for file changes. It fuses the inside and outside into one plain-English letter grade and one deduplicated fix-list, so you are not left juggling two reports that half-agree.
The plugin is strictly read-only. BadgerScan never performs penetration testing or active exploitation. It looks, it reports, and where you would rather a person handled it, a local Canadian team can do the fixing.
What to do with what you find
Start by running the free external scan and treating it as your attacker's-eye view. Close any exposed files immediately, fix or add your SPF, DKIM and DMARC records so your domain cannot be spoofed, renew or correct your certificate, and switch on the security headers you are missing.
Then go inside. The external view will tell you the site looks reasonable; the internal view will tell you whether the plugins quietly running it are safe. Small businesses are squarely in the firing line: in Verizon's 2025 Data Breach Investigations Report, ransomware or extortion appeared in 88% of breaches at small and medium businesses, versus 39% at larger organizations (Verizon 2025 DBIR). Seeing what attackers see is the cheap, fast first step toward not becoming one of those numbers.
See what attackers see, in about a minute
Run the free BadgerScan external check to view your site the way a hacker does: DNS, email spoofability, certificate, headers and exposed files. Then add Pro to scan the inside of your WordPress site and get one combined grade and one fix-list. Want a person to handle the fixes? Our Hamilton and Burlington team can take it from here. Start your free scan now.
Run a free security scanFrequently asked questions
Is a passive external scan the same as hacking my site?
No. A passive external scan only reads information your site already publishes to the public internet: DNS records, your TLS certificate, HTTP headers, exposed files and any version numbers your pages announce. It does not log in, guess passwords, or attack anything. BadgerScan never performs penetration testing or active exploitation.
If my external scan looks clean, am I safe?
Not necessarily. A clean external result means your perimeter is tidy, which is good, but most WordPress compromises come from the inside: an outdated plugin with a known vulnerability, a theme nobody updates, or an admin account without two-factor authentication. The external view cannot see those reliably. That is why the internal view matters more.
Why does my plugin version number matter so much?
Because once an attacker knows the exact version of a plugin you run, they can look up its published vulnerabilities and target that specific flaw. Plugins account for roughly 96% of WordPress vulnerabilities (Patchstack), so a leaked version number is often the first step in a real attack. Reading those versions accurately is something the internal scan does.
How do I stop people sending email that looks like it comes from me?
You need three DNS records configured correctly: SPF, DKIM and DMARC. Together they let receiving mail servers verify that a message claiming to be from your domain is genuine (Cloudflare). BadgerScan's free external check flags whether yours are missing or weak, and our team can set them up for you if you would rather not touch DNS.