WordPress security, explained clearly

Find risky WordPress code before it turns into a hacked site.

WP Luminary scans the plugins, themes, core files, and key settings already on your WordPress site for vulnerabilities, backdoors, and suspicious changes, then explains what it found in plain language.

WP Luminary is not released yet. The waitlist is how to hear first when access opens.

What it scans

Coverage that matches how WordPress sites actually get compromised.

The scan is built for the parts of a WordPress site that attackers most often abuse.

Installed plugins

Plugins are how most WordPress sites get taken over. The scan looks for actions that never check whether the user was allowed to perform them, logins that can be skipped entirely, database queries an attacker can rewrite (SQL injection), and code that lets one customer open another customer’s records.

Themes

Theme files are a favourite hiding place for backdoors. The scan flags injected and deliberately obfuscated code, and edits that quietly leave a way back in after you think the site has been cleaned up.

WordPress core files

Core files should match a clean WordPress install exactly. Anything added, altered, or removed gets flagged — including web shells dropped into folders that should only ever hold uploaded images.

Database options

Attackers persist in the database as well as in files. The scan reviews stored settings for injected scripts that run in your visitors’ browsers (cross-site scripting), unexpected administrator accounts, and redirects sending your traffic somewhere else.

How it works

Three steps from scan to action.

The goal is not just to detect problems. It is to make them understandable enough to fix.

  1. 01

    Scan what is already on your site

    WP Luminary checks your active plugins, theme files, WordPress core files, and important database settings.

  2. 02

    Judge what matters

    The analysis looks for vulnerable code, tampering, and backdoors, then weighs how likely each finding is to be real.

  3. 03

    Explain what to do next

    Each finding is translated into plain language so a non-developer can understand the risk and take action.

Plans

Three tiers, explained plainly.

The tiers differ by analysis depth, false-positive discipline, and how many sites they suit. Each card leads to the waitlist while launch access is still closed.

Starter

Catch the vulnerabilities that get you hacked.

Indicator-of-compromise and vulnerability scanning across your plugin, theme, and core files plus your database options. Catches the missing permission checks, injection flaws, and known-vulnerable plugin versions that account for most WordPress break-ins. Single site.

Your code is never stored by the AI model that analyses it.

Join the waitlist

Privacy

Deep scans. Your code is never retained.

A stronger analysis model than Starter, so subtler problems surface: permission gaps that only matter when chained together, deliberately obfuscated backdoors, and tampering designed to survive a cleanup. More site seats.

Same no-retention guarantee as Starter.

Join the waitlist

Pro

Our most thorough scan.

Our most capable analysis model, and the most disciplined about what it reports. Two results from our own comparison run:

  • On a genuinely clean test file, the Pro model returned zero false-positive findings, while a lower tier model still surfaced a low-severity note that it then explained away.
  • On a real webshell fixture, the Pro model also recommended blocking PHP execution in the uploads directory, beyond flagging the malicious file for removal.

Pro runs our most capable model for the deepest analysis available. That model doesn't yet support the no-retention guarantee our other tiers offer. If that's a hard requirement for your site, Privacy is the better fit.

Join the waitlist
Comparison

See the tradeoffs at a glance.

Every tier runs the same checks. What changes is how deep the analysis goes, how well it separates real findings from noise, and how many sites you cover.

Seat counts are indicative while we finalise plans.

Plan detail StarterPrivacyPro
Scan depth Baseline vulnerability and compromise checks.Deeper analysis for subtler issues.Deepest analysis available.
False-positive discipline Good for broad coverage, with some cautious notes.Stronger filtering than Starter.Returned zero false-positive findings on our clean-file test.
Retention guarantee Never stored by the AI model that analyses your code.Never stored by the AI model that analyses your code.Not currently covered by that guarantee.
Site seats 1 site5 sitesUnlimited sites

Seat counts are indicative while we finalise plans.

Starter

Scan depth
Baseline vulnerability and compromise checks.
False-positive discipline
Good for broad coverage, with some cautious notes.
Retention guarantee
Never stored by the AI model that analyses your code.
Site seats
1 site

Privacy

Scan depth
Deeper analysis for subtler issues.
False-positive discipline
Stronger filtering than Starter.
Retention guarantee
Never stored by the AI model that analyses your code.
Site seats
5 sites

Pro

Scan depth
Deepest analysis available.
False-positive discipline
Returned zero false-positive findings on our clean-file test.
Retention guarantee
Not currently covered by that guarantee.
Site seats
Unlimited sites

Starter and Privacy differ by scan depth and site capacity, not by whether your code is retained — both carry the same guarantee.

Waitlist

Join the list for launch news.

WP Luminary is not released yet. Leave your email and we will send launch updates, early access news, and plan details as they are finalised.

We only use this list for WP Luminary updates. If you are already confirmed, we will tell you instead of adding you twice.