Security Scan Results

https://whitehouse.gov

Screenshot of https://whitehouse.gov

whitehouse.gov

A

Excellent Security

10 issues detected

Scanned 4 months ago

10

Total

0

Critical

0

High

0

Medium

Info

WP_DEBUG is disabled (no PHP errors visible)

Info

Missing security header: Permissions-Policy -- Controls browser feature access

Info

5 of 6 security headers configured

Info

SSL certificate valid (49 days remaining) — issued by Let's Encrypt

Info

HTTP correctly redirects to HTTPS

Info

REST API user enumeration blocked

Low

wp-cron.php is publicly accessible (potential DDoS vector)

/wp-cron.php

How to fix: Disable WP-Cron in wp-config.php with define("DISABLE_WP_CRON", true) and use a real server cron job instead.

Low

External JS from popular domain: cdn.parsely.com (Tranco rank #3,428)

How to fix: This script is from a well-known domain (ranked in the top 100K globally). Likely legitimate, but verify it matches a service you intentionally added.

Low

1 external script(s) from popular domains (Tranco top 100K): cdn.parsely.com

How to fix: These scripts are from globally popular domains. They are very likely legitimate services but were not in our curated whitelist.

Checked against 11 blacklist services

Spamhaus DBL
SURBL
URIBL
SpamEatingMonkey
Barracuda
SORBS
Invaluement
URLhaus
OpenPhish
Google Safe Browsing
VirusTotal (70+ engines)

Looking good!

Your site passed the surface scan. For complete peace of mind, a deep scan checks file integrity, database injections, and hidden backdoors at the server level.

Run Deep Scan — $1
Scan another site