security / cms & plugins / version disclosure
CMS & plugins

Version disclosure

WordPress often reveals its exact version in your page source, which tells attackers precisely which known weaknesses to try.

Severity if missing
Medium
Category
CMS & plugins
Standard
OWASP

What it is

By default, WordPress adds its version number to your pages — in a meta tag in the HTML and in the addresses of its scripts and stylesheets. Anyone viewing your source can read it.

On its own a version number is harmless, but it tells an attacker exactly which release you're running, and therefore which published vulnerabilities apply to your site.

Why it matters

Attackers work from lists of known vulnerabilities tied to specific versions. If your site openly announces "WordPress 6.1", they can go straight to the exploits that affect 6.1 instead of guessing. Hiding the version doesn't fix underlying flaws, but it removes an easy shortcut and slows down automated attacks.

The risk
An exposed version number lets attackers immediately match your site to known exploits for that exact release, speeding up targeted attacks.

How Pentrawl checks it

Pentrawl inspects your page source for the WordPress generator meta tag and version strings in asset URLs. If a version is exposed, we flag it as a warning.

How to fix it

Keep WordPress fully updated so the version that shows matters less, and remove the version from your page source. Most security plugins can do this, or it can be done with a small snippet in your theme.

Remove the generator tag
add_filter('the_generator', '__return_empty_string');
Check your domain's Version disclosure in seconds
Pentrawl scans this and 20+ other security checks in one automated pass.
Scan your website →