What plugins is this WordPress site using?
Paste any URL and we fingerprint the active plugins behind it — from page assets, REST API routes, and HTML hints — and flag any that carry known security vulnerabilities. Free, no signup.
Plugin fingerprint
Surfaces active plugins from page assets, REST routes, and HTML hints — including plugins that don't announce themselves in the markup.
Known-CVE flags
Cross-references detected plugins against a public vulnerability database, so an outdated plugin with a known exploit gets flagged.
Theme + hosting too
The same scan also identifies the active theme, the hosting provider, the stack, and the WordPress core version behind the site.