MERQIVIO SECURITY SCAN

How secure does your webshop look from the outside?

Check publicly visible security risks around HTTPS, security headers, WordPress exposure and sensitive endpoints. The quick check is free; the full report with evidence and remediation priorities costs €9.95.

🔒

What we can check externally

  • HTTPS and transport security
  • Security headers such as CSP, HSTS and anti-framing
  • Public WordPress version and user information
  • debug.log, readme.html and directory listing
  • XML-RPC and other publicly visible WordPress signals

An external scan cannot prove that WordPress contains no malware. The Merqivio Security plugin is designed to check files, logins and changes from inside WordPress.

SAFE & PLATFORM-INDEPENDENT

We do not need access to your webshop

Merqivio checks only information and technical signals that are publicly reachable from the internet. Shopify, WooCommerce, PrestaShop, Magento, Shopware, OpenCart or custom-built: our external scans do not require an admin account.

✓ No passwords or admin account✓ No FTP, hosting or database credentials✓ No changes to your webshop✓ Publicly reachable information only
No penetration test or break-in attempt

The Security Scan does not attempt to log in, guess passwords, run brute-force attacks or actively exploit vulnerabilities. Merqivio assesses publicly visible security signals only.

Works with many webshop platforms
ShopifyWooCommercePrestaShopMagentoShopwareOpenCartCustom

Available checks vary by scan and platform. WordPress-specific Security checks and the Merqivio Security plugin apply only to WordPress/WooCommerce.

Explore platform-independent webshop scans →