Privacy Policy
CoreScanWP is built with privacy as a default, not as a feature you have to enable. This page describes exactly what data the service touches and what it does with it.
What we collect
When you scan a site, your browser sends CoreScanWP the URL you typed and whether the deep-scan toggle was on. We use that URL to fetch the public pages of the site you are scanning. We do not collect:
- Your name, email address, or any identifier you have not given us
- Tracking pixels, third-party analytics, or marketing cookies
- The contents of any private site (we only read public pages)
- Any data from sites you scanned in previous visits
What we log
Our server keeps short-lived access logs in the form most web servers keep: the requested URL, the timestamp, the response status, and the requesting IP address. These logs are automatically deleted after 14 days and are only used to debug errors and stop abuse.
Cookies and browser storage
CoreScanWP saves two small values in your own browser:
- Remembering your cookie-consent choice so the banner does not reappear on every visit
- Remembering the language you last chose so the switcher can restore it
We do not set any tracking cookies. We do not share any browser-stored data with third parties.
Third-party data
CoreScanWP cross-checks detected plugin versions against the NIST National Vulnerability Database, which is a US-government-run open data feed. The cross-check happens in your browser against a JSON file we ship; no plugin name or scan result is ever sent to NIST.
When the scanner resolves a hosting provider, it looks up the IP address against ipinfo.io to find the network owner. Only the IP address of the site you are scanning is sent.
Your rights
Because we do not collect personal data, we do not maintain a user profile to access, modify, or delete. If you believe we are storing data about you and you want it removed, email hello@corescanwp.com and we will respond within seven days.
Changes to this policy
When this policy materially changes we will update the date at the top of the page and post a note on the home page for at least 30 days.
Contact
Questions, concerns, or takedown requests can go to hello@corescanwp.com.