Watchful LogoWatchful Logo
  • Features
  • Premium Pricing
  • GDPR
  • Login
  • Create a free account

Getting Started

3
  • Add your sites
    • Add a website to Watchful
    • Add a WordPress site to Watchful
    • Add a Joomla! site to Watchful

Securing Your Sites

1
  • Vulnerability Scanner
    • Vulnerability Scanner checks
View Categories
  • Home
  • Documentation
  • Securing Your Sites
  • Vulnerability Scanner
  • Vulnerability Scanner checks

Vulnerability Scanner checks

The Watchful Vulnerability Scanner checks your WordPress and Joomla! sites for security risks, configuration problems, vulnerable software, suspicious files, malware, and other potential issues.

Results from each vulnerability scan are stored in Watchful so you can review previous results, repeat scans, and monitor changes over time.

What the Vulnerability Scanner checks #

A vulnerability scan includes the following checks:

  • Configuration and security best practices
  • Known core and plugin vulnerabilities
  • Core filesystem integrity
  • File and folder permissions
  • Malware signatures
  • Frontend malware
  • Blacklist status

Configuration and security best practices #

The configuration and security best practices scan checks your site against common security and configuration best practices.

If Watchful detects a problem with your website or server configuration, the issue is displayed in the scan results so you can investigate and correct it.

Depending on your CMS and server configuration, Watchful checks for the following:

  • Unsupported PHP versions
  • PHP files in the document root that are writable by the web server
  • Two-factor authentication for user logins
  • The Strict-Transport-Security security header
  • The X-Frame-Options security header
  • The Content-Security-Policy security header
  • HTTPS enforcement and certificates approaching expiration
  • Web-accessible .zip or .sql archives in the document root
  • Backend file editors
  • Exposed XML-RPC
  • The presence of readme.html
  • Debug notices or debug mode
  • robots.txt configuration
  • Known administrator usernames
  • The presence of .htaccess or web.config
  • Known database table prefixes
  • Additional CMS installations
  • Session lengths longer than 15 minutes
  • Open comments in the K2 component
  • Search engine friendly URLs
  • Error reporting
  • Magic Quotes
  • mod_zlib
  • mod_xml
  • Akeeba Kickstart files
  • PHP maximum execution time
  • Installation directories
  • Administrator password strength
  • GZIP page compression
  • Caching
  • Changes to configuration files
  • Guest registration
  • Debug log files
  • Directory browsing in the uploads folder
  • Deactivated plugins or extensions
  • Deactivated themes
  • The default readme.html file
  • Configuration file permissions
  • Available theme updates
  • Information revealed during failed login attempts
  • Database debug mode
  • PHP version information exposed in HTTP headers
  • WordPress version information in meta tags
  • WordPress security keys and salts

Known core and plugin vulnerabilities #

Watchful checks for known vulnerabilities affecting WordPress and Joomla! core software and installed plugins and extensions.

Detected vulnerabilities are included in the scan results so you can identify affected software and determine what action is required.

Important: Known core and plugin vulnerability detection requires Watchful Premium.

Core filesystem integrity #

The core filesystem integrity scan checks whether files distributed as part of WordPress or Joomla! core have been modified or are missing.

If Watchful detects a difference, the affected file path is displayed in the scan results. You can then investigate the change and replace the file with an original copy when appropriate.

File and folder permissions #

File and folder permissions determine who can read, modify, or execute files on your server.

Common permissions for PHP-based content management systems include:

  • 0644 for individual files
  • 0755 for folders

The file and folder permissions scan checks the files and folders in your WordPress or Joomla! installation. Files or folders with unexpected permissions are flagged in the scan results.

Malware signatures #

The malware signatures scan performs a deep, server-side scan of your site’s filesystem for common malware signatures and suspicious code.

If suspicious code is detected, Watchful displays the affected file and the suspicious pattern in the scan results.

Note: False positives can occur with signature scanners. Review suspicious files carefully and contact the relevant software vendor if you are unsure whether detected code is legitimate.

Malware scanner #

The malware scanner checks the public-facing portion of your website for signs of malicious or suspicious content. Since the frontend of your website may contain compiled code and scripts/assets from third-party sites, this scan is important for monitoring overall security on your website.

The malware scanner checks for issues including:

  • Website malware
  • Injected spam
  • Website defacements
  • Internal server errors

Blacklist scanner #

The blacklist scanner checks whether your site has been identified as unsafe by external security services.

Watchful checks the following services:

  • Google Safe Browsing
  • McAfee
  • Sucuri Labs
  • ESET
  • PhishTank
  • Yandex
  • Opera

A blacklist result should be investigated promptly.

Ignore detected issues #

Not every detected issue requires action. For example, you may determine that a particular result is expected for your site or represents a risk you have chosen to accept.

Watchful allows you to ignore a detected issue:

  • On a single site
  • Across all sites in your Watchful dashboard

Important: Ignoring an issue does not resolve the underlying condition. Only ignore a result after reviewing it and determining that no action is required.

Automate vulnerability scans #

You can run vulnerability scans manually whenever you need them.

Watchful Premium also allows you to automate vulnerability scans so your sites are checked regularly without starting each scan manually.

Important: Automated vulnerability scans require Watchful Premium.

Scan history and retention #

Watchful stores vulnerability scan results so you can review previous scans and monitor changes over time.

Scan results are retained according to your Watchful plan:

PlanRetention
Free7 days
Legacy30 days
Premium90 days

Troubleshooting #

If a vulnerability scan does not complete successfully, see Troubleshooting the Vulnerability Scanner.

Joomla! Security Vulnerability Scanner WordPress
Vulnerability Scanner checksVulnerability Scanner checks
Table of Contents
  • What the Vulnerability Scanner checks
    • Configuration and security best practices
    • Known core and plugin vulnerabilities
    • Core filesystem integrity
    • File and folder permissions
    • Malware signatures
    • Malware scanner
    • Blacklist scanner
  • Ignore detected issues
  • Automate vulnerability scans
  • Scan history and retention
  • Troubleshooting

About Watchful

Since 2012 Watchful has been helping digital agencies grow and be successful by providing professional solutions for safely managing websites. Watchful currently supports WordPress and Joomla.

More about Watchful »
  • Features
  • Blog
  • Success Stories
  • Podcast
  • About Us
  • Contact
  • Knowledge base
  • News & Events
  • Brand Assets
  • Status
  • RESTful API
  • Watchful Apps
  • Free account
  • How-to
  • Testimonials
  • Twitter
  • Facebook
  • Swag Store

  • Privacy Policy
  • Terms of Service
Copyright © 2026 Watchful LLC