How can we help you?
Search the archive:
🗐
Learn how Aegisify Audit works, what it reviews, how data is handled, and the security, privacy, and technical evidence behind the platform.
Explore the facts behind Aegisify and see how its WordPress security platform turns technical evidence into clear, informed action. The Aegisify Facts & Proof Center explains how external scanning and the customer-authorized WordPress Agent work together across SAST-style code analysis, DAST-style exposure checks, plugin and theme intelligence, dependencies, configuration, APIs, activity events, optional logs, and AI-assisted risk prioritization.
It also documents what technical data may be processed, what remains outside the routine audit scope, how customers control telemetry and Agent connections, how security concerns can be responsibly disclosed, how product improvements are communicated, and how sanitized audit reports connect findings with evidence, severity, potential business impact, remediation priorities, and retesting, giving WordPress professionals, security leaders, marketers, and executives the transparency needed to evaluate Aegisify without guesswork.
Whether you are evaluating Aegisify for the first time or managing an active WordPress environment, our team is here to help. We work with website owners, developers, agencies, and organizations that need clearer visibility into WordPress security, risk, privacy, and performance.
Have a question about Aegisify Audit, your account, a technical issue, or how our platform may support your organization? Send us a message, and we will help guide you to the appropriate resource or team member.
Tell Us How We Can Help
Share a few details about your website, question, challenge, or objective so we can better understand your needs. Your message will be directed to the appropriate Aegisify team member for review.
When requesting a callback, include your preferred contact time and time zone, and we will make reasonable efforts to reach you during that window.

What Will Be Reviewed?
Aegisify begins with the security evidence that can be observed from the public internet. The documented external scan covers 59 website security checks across five primary areas:
- Transport and header posture: HTTPS availability, HTTP-to-HTTPS redirection, browser security headers, cookie attributes, and mixed-content signals.
- Public exposure and sensitive artifacts: WordPress installation files, XML-RPC, debug logs, backup files, database dumps, configuration copies, dependency manifests, environment files, source-control metadata, diagnostic pages, and directory-listing exposure.
- Web and API attack-surface visibility: Public login and administrator boundaries, REST API exposure, user-enumeration signals, GraphQL and OpenAPI endpoints, robots.txt hints, public forms, and WordPress component fingerprints.
- OWASP-style risk indicators: Safe reflected-input and redirect probes, client-side risk patterns, anti-CSRF or nonce indicators, and public authentication or session exposure.
- Public security-readiness signals: A security.txt disclosure contact, a public privacy-notice signal, and limited public indicators relevant to security-control readiness.
The scan reports what was observed. It does not guarantee that every possible vulnerability has been found.
What Does the Documented 59-Check External Scan Mean?
The current Aegisify website states that the Free Test performs 59 external website security checks. In Aegisify Audit 1.2.12, that total can be explained as 29 landing-page, response, active-probe, and public-policy checks plus 30 targeted public path and API probes.
- 29 landing-page and response checks: 2 transport checks, 5 browser security-header checks, 3 cookie-attribute checks, 1 mixed-content check, 7 browser-facing JavaScript pattern checks, 2 POST-form and anti-CSRF checks, 1 generator-metadata check, 3 WordPress component-fingerprint checks, 2 safe active probes, 1 limited public control-signal summary, 1 security.txt check, and 1 public privacy-notice check.
- 30 targeted public probes: WordPress login and administrator paths; readme, XML-RPC, logs, backups, database dumps, installation and configuration artifacts; Composer, Node, Git, and Subversion metadata; WordPress directory-listing paths; PHP diagnostics; robots.txt; REST API and user-enumeration routes; GraphQL; and OpenAPI.
The free public test uses up to 40 lightweight live HTTP touchpoints and a limited runtime. Several checks can be evaluated from the same response, so 59 checks does not mean exactly 59 HTTP requests or exactly 59 findings on every run.
Related controls may also be consolidated into one finding row. The number of surfaced results depends on the website response, the public surfaces that exist, and the scan budget.
What Is External-Only?
The external scan reviews only information available from the public website and its publicly reachable routes. It does not require the Aegisify Agent, WordPress administrator access, saved credentials, or authenticated WordPress telemetry.
External-only evidence can include HTTP response codes, redirects, headers, cookies, public HTML signals, login and administrator entry points, public REST or API routes, exposed files, public WordPress fingerprints, and safe non-destructive probe responses.
An external scan cannot confirm the complete installed plugin and theme inventory, inspect private files, review database configuration, validate internal user privileges, examine local dependency data, or perform full WordPress-side code analysis.
What Requires the Aegisify Agent?
The Aegisify Agent is required when the audit needs authorized evidence from inside the WordPress environment. Depending on the selected scan profile and enabled telemetry, Agent-assisted review can add:
- WordPress core, plugin, theme, must-use plugin, version, activation, update, and software-health inventory.
- Known vulnerability and dependency correlation using the installed software and package evidence available from the site.
- SAST-style code analysis using bundled PHPCS and WordPress Coding Standards coverage, Aegisify WordPress rules, JavaScript checks, and supported Python-assisted rules.
- File, permission, configuration, hardening, integrity, change, administrator, role, capability, scheduled-task, backup, and recovery-readiness evidence.
- WordPress activity events and optional diagnostic logs when the authorized customer enables those telemetry sources.
- Deeper WooCommerce evidence involving checkout, Store API, payments, webhooks, HPOS, Action Scheduler, template overrides, extensions, and internal business-logic context.
Authenticated DAST profiles may also require approved credentials or session material for role-aware and post-login testing.
What Data Is Collected?
For the external scan: Aegisify may process the submitted domain or URL, scan timestamps, HTTP responses, response codes, redirects, headers, cookie signals, public page and route evidence, publicly reachable artifact results, scan findings, and remediation context.
When the Agent is connected: Supported telemetry may include domain and site identity, WordPress environment details, plugin and theme inventory, dependencies, configuration posture, code and file signals, external-exposure correlation, WordPress activity events, optional diagnostic logs, and scan or report data.
Routine Agent-assisted auditing is not designed to collect full WordPress database backups, complete customer content libraries, payment card information, WordPress user passwords, private communications, or unrelated business documents as a normal audit requirement.
Agent activity and diagnostic logs are optional and remain subject to customer-controlled telemetry settings. Customers can deactivate the Agent and remove or rotate the associated security key.
What Will the Buyer Receive?
The free external test provides an on-screen findings report that organizes observed public evidence by severity and category, with the affected path, explanation, supporting evidence, and recommended next step.
The subscribed audit workflow can add broader WordPress and Agent-assisted evidence, risk summaries, finding prioritization, business-impact context, remediation guidance, and report exports in CSV, PDF, and XML formats.
The report structure is designed to help technical and business reviewers understand the assessment scope, what was observed, why the finding may matter, which actions deserve attention first, and what should be retested after approved changes.
How Are SAST, DAST, Dependencies, APIs, and WooCommerce Covered?
- DAST: The external and advanced dynamic profiles make live requests to the running website, inspect real responses, discover public routes and APIs, and use safe canary probes rather than destructive exploitation.
- SAST: Agent-assisted static analysis reviews supported WordPress PHP, JavaScript, and related code signals from inside the authorized site.
- Dependencies: Agent inventory and package evidence can be correlated with vulnerability and software-risk intelligence.
- APIs: Coverage can include REST namespaces, public routes, JavaScript-exposed endpoints, GraphQL, OpenAPI or Swagger definitions, authentication boundaries, authorization signals, and inventory gaps.
- WooCommerce: Public testing can identify externally visible Store API, checkout, payment, webhook, account, cart, coupon, and order surfaces. Agent-assisted review adds internal WooCommerce configuration and compatibility evidence such as HPOS, Action Scheduler, templates, extensions, and payment-related context.
The exact evidence depends on the selected scan profile, the website surfaces that are present, the Agent connection, enabled telemetry, and any approved authentication context.
Why Does Aegisify Lead With Proof Before Feature Volume?
Security buyers should be able to review evidence before relying on a long feature list. Aegisify provides public proof resources that explain the scan boundary, Agent role, telemetry controls, report structure, and available audit depth:
- The documented 59-check external scan
- The sanitized WordPress Security Audit report example
- The Aegisify Security and Trust Center
- Agent telemetry, privacy, and data-handling controls
- The external-versus-Agent-assisted workflow explanation
- The scan-profile and coverage matrix
These resources help buyers understand what is external-only, what requires authorized WordPress access, what technical data may support the audit, and what the final report is designed to provide.
What Is the Single Next Action?
Start with the public external scan. Review the findings first, then decide whether deeper Agent-assisted WordPress evidence is appropriate for your environment.


























