FAQ

Common questions about Audit My CMS

Short answers about ownership verification, passive CMS health and security checks, agency workflows, and scan limits.

What is a CMS security checker?

A CMS security checker reviews public website signals from a content management system, such as CMS fingerprints, visible component versions, public exposure, headers, TLS, DNS, forms, and third-party services. Audit My CMS keeps this passive and does not log into the CMS.

Can I run a free CMS security audit?

Yes. You can start a free CMS security audit for a website you own or manage. After ownership verification, the scanner queues a passive public review and shows the result page when it finishes.

What does a website CMS audit include?

A website CMS audit can include CMS detection, public component evidence, vulnerability applicability, exposed files, security headers, TLS, DNS and email security, SEO and privacy indicators, third-party services, form signals, and external attack surface observations.

What does Audit My CMS scan?

Audit My CMS scans WordPress, Drupal, Joomla, OpenCart, PrestaShop, and TYPO3 sites you own or manage. It checks public CMS signals, vulnerabilities, exposed files, security headers, SEO and privacy indicators, third-party scripts, accessibility issues, and remediation-focused details.

Does Audit My CMS support WordPress, Drupal, and Joomla?

Yes. Audit My CMS supports public checks for WordPress, Drupal, Joomla, OpenCart, PrestaShop, and TYPO3. The exact findings depend on which CMS and component signals are visible from public pages and assets.

Who is Audit My CMS for?

Audit My CMS is built for agencies, freelancers, maintainers, and website owners who need a practical CMS health and security report for discovery, maintenance, pre-launch review, or remediation planning.

Do I need to prove website ownership?

Yes. Before a scan can be queued, you must upload a small verification token file to the target website. This prevents scanning unrelated websites without authorization.

Is the scan passive?

Yes. The scanner uses public HTTP requests, public page signals, and rate-limited probes. It does not exploit vulnerabilities, brute force logins, or access private CMS areas.

Is this the same as a penetration test?

No. Audit My CMS is a passive CMS security checker and website audit tool. It is useful for public exposure review, maintenance triage, and remediation planning, but it does not replace an authorized penetration test or authenticated code review.

Why can a scan be incomplete?

A scan can be incomplete if a firewall, CDN, security plugin, host, or rate limit blocks scanner requests. When that happens, the result page shows scan completeness information and may recommend allowing the scanner identity header and proxy-based scanner requests or running a fresh scan.

How long are result pages and report downloads available?

Public result pages are available only during the configured result retention period shown on the result page.

Can agencies use it for client maintenance?

Yes. Agencies can use the result as a discovery tool, a recurring maintenance check, a pre-launch review, or a starting point for remediation planning with clients.