Find the doors left open on your site — before an attacker does.
An attacker's first move isn't an exploit — it's reconnaissance: asking your server for files and endpoints that shouldn't be reachable. Relvato runs that same first pass on the site you've verified you own, non-intrusively, and tells you what's exposed before someone malicious finds it.
- ✓Reachable .env, .git, wp-config and database-backup files
- ✓Open XML-RPC (brute-force & pingback amplification)
- ✓Username enumeration via the REST API and author pages
- ✓Directory listing and version/software disclosure
- ✓Missing security headers (HSTS, CSP, X-Frame-Options, and more)
- ✓Read-only and non-intrusive — no exploitation, ever
Most break-ins start with something left open — a stray .env or database backup, an exposed .git folder, XML-RPC enabled for brute-forcing, usernames leaking through the REST API, or missing security headers. A vulnerability scan of your plugins won't see any of that, because it's about configuration and exposure, not code. Relvato checks it continuously and flags a newly-exposed secret the day it appears.
Works on any site — from WordPress to AI-built sites.
- Requests a curated set of public URLs on your verified site and reads the responses — strictly read-only, no exploitation, no brute force, and it identifies itself as Relvato.
- Flags reachable secrets and backups (.env, .git, wp-config backups, database dumps), open enumeration (XML-RPC, REST/author usernames), directory listing and version disclosure.
- Checks your security headers (HSTS, CSP, X-Frame-Options and more) and reports what's exposed or missing, so you can lock it down.
Is this an active penetration test or attack?
No. It's strictly non-intrusive reconnaissance: read-only GET requests to public URLs on the site you've verified you own. It never sends exploit payloads, brute-forces logins, fuzzes inputs, or changes anything — so it can't damage a live store. It also identifies itself as Relvato in the request, rather than acting like a stealth attacker.
How is it different from the vulnerability scan?
The vulnerability scan checks your installed plugins and themes against known CVEs — it's about vulnerable code. The exposure scan checks configuration and what's reachable from the outside — exposed files, open endpoints, weak headers — which no code-level scanner sees. They're complementary: one finds vulnerable software, the other finds open doors.
Does it work on non-WordPress sites?
Yes. The generic checks (exposed .env/.git/backups, directory listing, missing security headers) apply to any site; the WordPress-specific probes (XML-RPC, REST user enumeration, readme version) simply don't match elsewhere. No plugin is required — it's pure external observation.
Won't scanning my own site cause problems?
It's deliberately gentle: a small, curated list of requests at a low rate, each with a short timeout, from an identified user-agent. It only runs on a domain you've verified, and you opt in by enabling the check. It's the same non-intrusive first pass a security professional would run on a site they're authorized to test.
What happens when it finds something?
An exposed secret or backup fails the check and alerts you immediately — those are close-it-now issues. Hardening gaps (missing headers, enabled XML-RPC, enumeration) are flagged as warnings to review. Anything that's expected on your site you can mark as reviewed so it won't nag you again.
Put this check on autopilot.
Free while you set it up — 100 checks or 30 days. No card, no sales call.