Terms of Use
By using CoreScanWP you accept these terms. If you don't, do not use the service.
The service
CoreScanWP is a free tool that reads public information from websites you submit, identifies WordPress installations, lists themes and plugins, detects hosting infrastructure, and cross-checks detected versions against published security advisories. The service is provided without any commercial obligation.
Acceptable use
You may use CoreScanWP to scan sites that you own, sites you are authorized to assess, or sites that are otherwise made available for public reconnaissance. Typical accepted uses include:
- Auditing your own WordPress installations
- Researching the technical stack of a prospect or partner
- Confirming the build of a site you are about to acquire
- Educational and academic curiosity
Prohibited use
You may not use CoreScanWP to:
- Conduct unauthorized vulnerability assessments against systems you do not own and do not have permission to test
- Plan, prepare, or stage any attack, intrusion, or unauthorized access against any system
- Circumvent rate-limits, technical controls, or terms of service of any third party
- Scrape, mirror, or rehost the service or its outputs without permission
- Submit URLs containing personal data, credentials, or any private path
If we believe you are using CoreScanWP for any prohibited purpose, we may block your access without notice.
No warranty
CoreScanWP is provided "as is." Detection results are best-effort and may be incorrect, incomplete, or out of date. You should independently verify any finding before acting on it, especially before reporting a vulnerability to a third party. We do not warrant that the service will be available, accurate, or fit for any particular purpose.
Limitation of liability
To the maximum extent permitted by law, CoreScanWP, its authors, and its contributors are not liable for any direct, indirect, incidental, or consequential damages arising from your use of the service. Your sole remedy is to stop using the service.
Intellectual property
The CoreScanWP name, design, and source code are the intellectual property of their respective authors. The underlying vulnerability data is drawn from the public NIST National Vulnerability Database, which is in the public domain as a work of the US Government.
Changes
We may update these terms from time to time. Material changes will be announced via a banner on the home page for at least 30 days. Continued use of the service after a change implies acceptance.
Contact
Questions can be sent to hello@corescanwp.com.