WordPress vs custom sites: what VibeScan checks differently
CMS fingerprinting, plugin exposure, and vibe-coded SPA blind spots—how scans adapt to how your site was actually built.
By VibeScan Team
CMS fingerprinting, plugin exposure, and vibe-coded SPA blind spots—how scans adapt to how your site was actually built.
By VibeScan Team
Not every website is the same under the hood. A WordPress blog, a Webflow export, and a Next.js app on Vercel all fail in different ways.
When we detect WordPress, Drupal, Joomla, or similar platforms, we lean into CMS-specific checks:
wp-admin and login exposurexmlrpc.php, readme files, and common leak paths/wp-content/uploadsCMS sites are attacked by bots 24/7. You don't need to be a target—just online.
Even "just a landing page" gets checked for:
.env, backup files, and git foldersModern apps often hide issues behind client-side routing:
VibeScan's ONLY_WEBSITE mode runs a broad catalog—identity, DNS, TLS, headers, exposure, CMS, OWASP surface, email, performance, and risk scoring.
Fingerprinting tells us which checks matter most for your stack. You see grouped results: Identity & Domain, HTTP & Headers, CMS & Applications, OWASP & Input Surface—not a flat dump of 1,000 lines.
Whether you clicked "Publish" in a no-code builder or merged a PR at 2 a.m., run one scan per environment. Compare staging vs production. Fix what fails on production before you announce.
Run a VibeScan on your site and see which checks pass—and which ones need your attention.