BadgerScan Pro

Your free scan sees the outside. Pro sees the backside.

BadgerScan Pro is a WordPress plugin. Install it in your dashboard and it scans your site from the inside: the exact plugins, themes, and core an attacker targets, plus the admin settings and exposed files a passive external scan can only guess at.

C$10/mo per site (or C$100/yr, plus tax). Create an account, install the plugin, and your scans show up in your dashboard.

Need a full on-site audit, not just the website? See BadgerAudit →

Plans

From a free self-scan to a fully managed site. Start free today; the analyst and managed tiers are opening soon.

Free
C$0

No account needed

The plugin, standalone. Scan your site and get an A to F grade with prioritized findings, right in wp-admin.

  • ✓ Unlimited authenticated scans
  • ✓ Plain-English grade + fixes
  • ✓ Core-file integrity + backdoor checks
Download the plugin

No account or card, ever.

Most popular
Pro
C$10 /mo per site

or C$100/yr · two months free

The full picture, automated.

  • ✓ Full external + internal report + PDF
  • ✓ The specific CVEs for your versions
  • ✓ Alerts on grade drops / new CVEs
  • ✓ Daily scans + full history
Get started

Cancel anytime.

Waitlist
Analyst Review
C$150 one-off

Per site, no subscription

A full report plus a remediation plan: autogenerated, then reviewed by a CyberBadger analyst. Exactly what to fix, in priority order. Opening soon: join the waitlist and we'll email you when it's ready.

  • ✓ Everything in the Pro report
  • ✓ Analyst-reviewed remediation plan
  • ✓ Prioritized, step-by-step fixes

One email when it opens.

Waitlist
Managed
C$100 /mo

or C$1,000/yr · per site

Hands-off. We keep WordPress, plugins, and themes updated and maintained, with Pro scanning and reporting included. Opening soon: join the waitlist and we'll reach out when it's ready.

  • ✓ Managed updates + maintenance
  • ✓ Pro scanning + reporting included
  • ✓ We watch, patch, and report

One email when it opens.

Prices in CAD, plus tax.

Why Pro pays for itself

The free scan tells you where you stand today. Pro is what keeps you covered, and gives you something to show for it.

Told the day something breaks

You get an email the moment a new vulnerability hits a plugin you actually run, or your grade drops. That early warning is the difference between a quick update and an expensive cleanup.

A report you can show

A branded inside-and-outside report and PDF for your cyber-insurer, a client doing due diligence, or your board. Insurers increasingly ask for proof you are watching. This is it.

Watched, so you do not have to remember

Daily scans and full history, automatically. No reminder to set, no logging in to check. Your site is looked at every day whether you think about it or not.

A hacked-site cleanup runs into the thousands. Pro is C$10 a month.

More than one site?

Simple, per site: every site is C$10/mo (or C$100/yr, two months free).

PlanForPrice (CAD)
Proper siteC$10/mo · C$100/yr
Agencyclient portfolios + white-labelBy quote

Managing client sites? Talk to us about agency pricing →

Registered charities

Nonprofits get Pro free, and half off everything else.

Registered Canadian charities get Pro free for up to 2 sites, and 50% off the rest of the ladder. A tight budget should not mean a soft target.

See the nonprofit discount →

A guess vs. certainty

Free external scan

What an anonymous visitor can infer from outside.

  • Version guessed from the page (often hidden by caching)
  • Public files & technology fingerprint
  • User enumeration via the public API
  • CVEs matched to a best-guess version

A strong first signal, but it's an educated guess.

BadgerScan Pro · authenticated

What's actually true inside wp-admin.

  • Exact plugin, theme & core versions, matched to real CVEs, not guessed from outside
  • Outdated & abandoned plugins (the #1 way WordPress sites get breached)
  • Admin accounts: a leftover “admin” user, too many admins, open registration
  • Risky config: debug mode on, file editing enabled, XML-RPC, REST user exposure
  • Exposed backups & secrets: .sql dumps and wp-config backups in the web root
  • Whether a security plugin / firewall is actually active

Certainty, not a guess, and the fixes that matter.

EASY BY DESIGN

If you can install a plugin, you can run it.

No software to download, no machines to enroll, no IT ticket. It's the WordPress install you've done a hundred times.

✓
Installs like any plugin
Upload the .zip in your WordPress dashboard. No agents, no IT, no command line.
✓
Reads only, never changes
It inventories what's there and reports it. It never edits your site or touches content.
✓
Plain-English grade
The same honest letter grade as the free scan, now with the inside story behind it.
✓
Remove it anytime
Deactivate and delete like any other plugin. Nothing is left behind.

See your site's backside.

Create a free account and install the plugin. It takes a couple of minutes.

Not ready for the plugin? Run a free external scan or talk to our team.