Home/Services/WordPress Penetration Testing
security service

WordPress Penetration Testing

WordPress penetration testing across Europe: plugins, themes, wp-admin and custom code tested by hand. Fixed price, free retest. Get a quote.

Manual, expert-ledEvidence-based findingsFree remediation retest

WordPress penetration testing checks the platform that runs a large share of the web, and the plugins bolted onto it, for the flaws attackers exploit every day. We test your WordPress site by hand across Europe and show you the realistic ways in, starting with the one that causes most compromises we see: an out-of-date plugin nobody remembered to update.

WordPress powers an enormous number of business sites, and that popularity is exactly why it is attacked so relentlessly. Automated bots crawl the whole internet looking for known-vulnerable plugins, exposed login pages and weak credentials, and they do not care whether your site is a Fortune 500 brand or a local firm. In most WordPress compromises we clean up, the entry point was not some clever zero-day. It was a plugin two versions behind with a public advisory, or an admin account with a password that had been reused elsewhere.

What WordPress penetration testing covers

We test the whole WordPress stack: core, the active theme, every plugin, the wp-admin area, the XML-RPC and REST interfaces, and the server configuration underneath. WordPress security testing that only checks core misses the point, because core is the best-maintained part. The risk lives in the third-party code and the way the site has been configured over the years.

Plugin and theme testing for known vulnerabilities and insecure custom code
wp-admin, login and user-role testing for privilege escalation and takeover
XML-RPC and REST API abuse, including user enumeration and brute-force amplification
Exposed wp-config, backups, debug logs and directory listings
File upload and media handling tested for web shells and path abuse
Injection and cross-site scripting through forms, shortcodes and custom fields

Where WordPress sites actually get breached

WordPress compromises follow a very consistent pattern. The technology varies, the root causes rarely do, and a good WordPress website penetration testing engagement goes straight for them.

Vulnerable plugins and themes

By a wide margin the most common cause. The plugin ecosystem is WordPress’s greatest strength and its biggest liability. A form builder, a page builder, an SEO plugin or an abandoned widget with a known flaw gives an attacker a foothold, and there are new advisories every week. We identify every plugin and theme, check them against known vulnerabilities, and test whether an exposed one is actually reachable and exploitable on your site.

Weak authentication and brute force

The wp-login page is a magnet. Without rate limiting, an attacker can throw stolen credential lists at it endlessly, and XML-RPC can amplify that by bundling many login attempts into a single request. We test for weak or reused admin passwords, missing multi-factor authentication, and whether your login can be brute-forced or enumerated for valid usernames.

User enumeration

WordPress leaks usernames in more places than most owners realise: author archive URLs, the REST API users endpoint, and login error messages that distinguish a valid user from an invalid one. Each leak hands an attacker half of a login. We check every route and report the ones that talk.

Exposed sensitive files

A wp-config.php backup left in the web root, a debug.log with credentials in it, a database dump from a migration, a readable git directory. These leak the keys to the site and cost nothing for an attacker to find. Content discovery routinely surfaces them.

How we test

Every WordPress pen testing engagement is run manually by a certified offensive engineer (OSCP, OSWE). We use Burp Suite as the working proxy and WordPress-aware tooling to inventory plugins and themes quickly, but the exploitation and the judgement are a person’s work. A scanner will list your plugins; a tester will tell you which vulnerability actually matters on your specific site and prove it.

Fingerprinting and inventory

We start by identifying the WordPress version, the theme, every plugin and their versions, and the hosting setup. This builds the map of the attack surface and immediately flags any component with a known advisory, which we then verify by hand rather than trusting a version number that may have been patched in place.

Authenticated and unauthenticated testing

We test both as an anonymous visitor and with credentials for each role you use, from subscriber up to administrator. This is where privilege escalation surfaces: a subscriber who can reach an admin-only action through a plugin’s endpoint, or an author who can inject script that runs in an administrator’s browser and takes over the site.

Reporting and retest

You get an executive summary and a technical report with every finding scored by CVSS, its impact explained in plain terms, exact reproduction steps, and a specific fix, whether that is a plugin update, a configuration change or a code correction. After you remediate, the retest is included so you can confirm the site is genuinely secure.

48h
typical time to first critical findings
100%
manual verification of every finding
Free
retest after you fix

Custom code and page builders

Many WordPress sites are far more than a blog now. They run membership systems, online stores, booking flows and custom post types built by an agency or an in-house developer. That custom code is not covered by any plugin advisory, so it needs testing on its own terms.

Custom plugins and functions

Code written specifically for your site is where we find the bespoke bugs: a custom AJAX handler that trusts input it should not, a shortcode that renders user data unescaped, an endpoint added to functions.php with no capability check. These never appear in a vulnerability database because they exist only on your site.

Membership and e-commerce add-ons

If your site sells or gates content, the plugins that handle payments, subscriptions and access control deserve extra attention. We test whether a low-tier member can reach premium content, whether a checkout trusts a price from the browser, and whether account and order data is properly isolated between users.

Third-party integrations

Forms that post to a CRM, payment links, chat widgets and analytics all extend trust to code you do not control. We test how your site handles data going to and coming back from these services, and whether any of them can be abused to inject content or exfiltrate information from your visitors.

Get a fixed quote

Want this tested on your own systems?

Free 20-minute scoping call, a fixed price with no hourly surprises, and a free retest once you fix what we find.

Get a fixed quote

Compliance and standards

A WordPress site handles the same personal and payment data as any other, so the same obligations apply, and the report is written to prove coverage.

PCI DSS, ISO 27001 and SOC 2

Where a WordPress store or membership site takes card payments, PCI DSS 4.0 requirement 11.4 covers it and our reporting is built to satisfy it. For ISO 27001 the results support control A.8.29, and SOC 2 auditors accept independent testing as evidence under the security criteria.

GDPR

WordPress sites collect personal data through forms, comments, accounts and analytics, and testing supports the technical measures GDPR expects. A dated report is straightforward evidence if a customer or regulator asks how you protect that data.

When to test your WordPress site

WordPress sites drift faster than most, because plugins update on their own schedule and editors add embeds, forms and third-party scripts without anyone reviewing the security impact. Test after installing or replacing a significant plugin, after a redesign or theme change, before launching a membership or store feature, and on a regular cadence for any site that holds accounts or takes payments. A site that has grown by accretion over several years is exactly the kind that benefits most, because nobody remembers what every plugin does or why it was added.

Testing after a suspected compromise

If your WordPress site has behaved strangely, spam pages have appeared, or your host has flagged malware, a test answers the question that matters after cleanup: how did they get in, and is the door still open? Cleaning the visible symptoms without finding the entry point is why so many WordPress sites get reinfected within weeks. We identify the likely route in, whether that was a vulnerable plugin, a weak admin login or an exposed file, so the fix addresses the cause rather than the symptom. If you are dealing with an active compromise right now, our incident response team can help you contain and recover it as well.

Why manual testing beats a plugin scan

WordPress security plugins and online scanners have their place. They catch known-vulnerable components and obvious misconfigurations, and every site should run one. But they cannot judge context. They will not tell you that a low-risk information leak plus a weak admin password equals a full takeover, they cannot test the custom code your agency wrote, and they miss privilege-escalation chains that depend on how your roles are set up. A person who has broken WordPress sites before finds those, and that judgement is what separates real WordPress penetration testing from an automated report you could have run yourself.

Pricing

Pricing depends on how many plugins and custom features the site runs, whether it has accounts or a store, and how deep you want the test to go. Here is the shape of a typical European engagement.

Engagement What’s included Timeline Price
Security audit / VA WordPress core, plugin and theme review with configuration audit, verified findings and free retest 2–4 working days from €1,200
Standard pentest Full manual test of a WordPress site, unauthenticated plus each role, custom code and OWASP Top 10 coverage 3–5 working days from €2,500
Business site Membership or store site with payments and integrations, business-logic testing, exec and technical reports 5–8 working days €3,500–€8,000
Compliance add-on Framework mapping and an attestation letter for PCI DSS, ISO 27001, SOC 2 or GDPR with any tier from €800
Custom / multi-site A WordPress multisite network or several sites, scoped to your needs on scoping custom

Every engagement is fixed-price, quoted after a free 20-minute scoping call, so there are no hourly surprises and a retest is always included. Get a fixed quote

FAQ

How much does WordPress penetration testing cost?
A plugin and configuration audit starts from €1,200, and a full manual test of a WordPress site starts from €2,500. A membership or store site with payments typically runs €3,500–€8,000. The price is fixed after a free scoping call.
Do you test our plugins and custom code, not just WordPress core?
Yes, and that is where most real risk lives. We check every plugin and theme against known vulnerabilities and test any custom code your site runs, since that code appears in no advisory database.
Will testing take my site down?
No. We can test a staging copy to remove all risk, or test production carefully with any intrusive checks agreed in advance and run out of hours. Brute-force and load-heavy checks are never run without your sign-off.
How long does the test take?
An audit runs 2–4 working days and a full WordPress test 3–5, plus the report. Anything critical, such as a way to take over an admin account, is reported to you the same day.
What will you deliver?
An executive summary and a technical report with each finding scored by CVSS, its impact explained, exact reproduction steps and a specific fix, whether that is a plugin update, a config change or a code correction. A free retest confirms the fixes hold.
Can you test a WooCommerce store built on WordPress?
Yes. We test the checkout, payment integration, coupon logic and customer accounts alongside the usual WordPress plugin and configuration risks, so both the shop and the platform are covered.
Does this satisfy PCI DSS or ISO 27001?
Yes. Reports map to PCI DSS 4.0 requirement 11.4, ISO 27001 control A.8.29 and the SOC 2 security criteria, with an attestation letter available for auditors and customers.
Are the findings kept confidential?
Yes. We work under NDA, handle any credentials and evidence securely, and remove our access and test data when the engagement ends.

Related services

Who needs this

Any business running WordPress for something that matters: membership and e-learning sites, WooCommerce stores, lead-generation and brand sites with custom plugins, and agencies handing over a build who want it checked before it quietly becomes their client’s problem.

why safetybis

Security you can prove

The same standard on every engagement, big or small.

Evidence, not opinions

Every finding ships with a reproduction and proof of concept — no vague "maybe vulnerable".

Humans over scanners

Certified engineers find the logic flaws and chained attacks automated tools walk straight past.

Fixed price, free retest

You know the cost up front, and verifying the fix is part of the deal — not a second invoice.

500+
assessments delivered
<30min
incident first response
12k+
infections removed
98%
fixed within one retest
$ safetybis quote --service "WordPress Penetration Testing"

Ready to lock this down?

Free scoping call, fixed price, free retest. Tell us what you're running and we'll take it from there — usually within one business day.

get in touch

Tell us what you're running

Scoping is free. We reply within one business day, and under 30 minutes for active incidents.