Ausculte Scan

Free external WordPress audit covering TLS, headers, exposure, DNS and performance

ToolWebsite Security ScannersCloud

Pricing: Free

Reviewed by the Cyber Vendor Guide editorial team against the public sources cited below · Last reviewed August 2026 · How we review listings

What is Ausculte Scan?

Ausculte Scan is a free browser-based scanner that audits a WordPress site from the outside, with no account and no installation. Its documentation states it runs 38 checks across security (HTTPS and TLS, protective headers, user enumeration, exposed version and sensitive files, REST API exposure), performance, technical SEO and email DNS (SPF, DMARC, MX), producing a score out of 100. The documentation describes the scan as read-only, stating it writes nothing and tests no passwords, and that it issues roughly 15 ordinary requests without connecting to the admin panel. The same operator, WP Admin Lab, publishes a companion plugin in the WordPress.org directory. Reports are in French.

Best for: WordPress site owners wanting a fast, non-invasive external posture check before committing to an authenticated audit.
Pros
  • Explicitly non-invasive, and documented as such: the vendor methodology page states the scan writes nothing, tests no passwords and generates no abnormal load
  • States its own limitations rather than overselling: the same page says it cannot find weak passwords, existing malware or a discreetly outdated extension, and calls the score a prioritisation tool rather than a guarantee
  • Free with no account or installation, per the product page
  • Backed by a published artifact: the Ausculte plugin is listed in the official WordPress.org directory and was updated in August 2026
Things to check
  • The operator is not identifiable: the mentions legales gives a trading name, an email and the host, with no legal form, registration number or directeur de publication, and the about page states the team is deliberately anonymous
  • Very new and thinly adopted: the domain was created in March 2026 and the WordPress.org plugin listing shows fewer than 10 active installs and no ratings
  • External-only by design, so per its own documentation it cannot detect weak credentials, malware already present, or a quietly outdated plugin
  • Reports are French-language only
  • No independent reviews or third-party evaluations were found on G2, Capterra, Product Hunt, Reddit or Hacker News

Reported in public reviews and vendor documentation. See sources below.

Key Features

38 external checks across security, performance, technical SEO and email DNS
HTTPS and TLS certificate checks, including mixed content
Security header inspection
User enumeration and exposed WordPress version detection
Sensitive file exposure checks (.git, .env) and directory listing detection
REST API and XML-RPC exposure checks
SPF, DMARC and MX record validation
Performance checks: TTFB, HTTP/2, compression, page weight, render-blocking resources, caching
Score out of 100 with findings prioritised by impact
No account, registration or installation required
Companion WordPress.org plugin for in-dashboard health checks

Are you Ausculte Scan? Improve this listing with screenshots, case studies and more.

Sources & references

Where the information on this listing comes from. Always verify pricing and capabilities against the vendor before a purchasing decision.

Spot an error, or do you represent Ausculte Scan? Request a correction.

Quick Info
PricingFree
ModelFree
Founded2026
CloudYes
Self-HostedNo

Last updated: Aug 18, 2026