Version disclosure
WordPress often reveals its exact version in your page source, which tells attackers precisely which known weaknesses to try.
What it is
By default, WordPress adds its version number to your pages — in a meta tag in the HTML and in the addresses of its scripts and stylesheets. Anyone viewing your source can read it.
On its own a version number is harmless, but it tells an attacker exactly which release you're running, and therefore which published vulnerabilities apply to your site.
Why it matters
Attackers work from lists of known vulnerabilities tied to specific versions. If your site openly announces "WordPress 6.1", they can go straight to the exploits that affect 6.1 instead of guessing. Hiding the version doesn't fix underlying flaws, but it removes an easy shortcut and slows down automated attacks.
How Pentrawl checks it
Pentrawl inspects your page source for the WordPress generator meta tag and version strings in asset URLs. If a version is exposed, we flag it as a warning.
How to fix it
Keep WordPress fully updated so the version that shows matters less, and remove the version from your page source. Most security plugins can do this, or it can be done with a small snippet in your theme.
add_filter('the_generator', '__return_empty_string');