WPSec is a remote scanner that checks WordPress sites for vulnerable plugins, themes, outdated core, and exposed files. It answers a narrow, useful question: is this WordPress install exposed? Lavawall® is not a WordPress scanner. Its free Scout scanner maps your whole external attack surface, and the Lavawall® platform adds endpoint, Microsoft 365, and compliance coverage a CMS scan cannot see.
Where Lavawall® wins
Scout scans the whole external footprint of a domain, subdomains, TLS, exposed services, and the SPF, DKIM, and DMARC records that decide whether attackers can spoof you, across any stack, not just WordPress.
Continuous monitoring re-checks your posture on a schedule and alerts when a new asset appears or a setting regresses.
Microsoft 365, Entra ID, Azure, and Google Workspace breach detection with endpoint correlation, well beyond a single site's CMS.
GRC compliance evidence across 15+ frameworks, turning your posture into auditable control coverage.
Multi-tenant and white-label, so an MSP can run branded scans for every client from one console.
Where WPSec wins
Deep, WordPress-specific vulnerability detection: plugin, theme, and core CVEs, and common WordPress misconfigurations.
Purpose-built reporting for agencies and site owners who manage many WordPress installs.
Fast, focused answer when the site in question is WordPress and CMS-level vulnerabilities are the concern.
Feature comparison
| Feature | Lavawall® (Scout + platform) | WPSec |
|---|---|---|
| WordPress plugin / theme / core CVE scan | No, not a WordPress scanner | Yes, this is its focus |
| Domain and subdomain discovery | Yes | No |
| SPF / DKIM / DMARC assessment | Yes | No |
| TLS and exposed-service checks | Yes | Limited |
| Continuous monitoring and alerting | Yes | Scheduled site scans |
| Microsoft 365 / Google Workspace breach detection | Yes | No |
| GRC framework evidence (CMMC, NIST, SOC 2, PCI, HIPAA) | 15+ frameworks | No |
| Endpoint patching and configuration monitoring | Yes | No |
| Multi-tenant, white-label MSP console | Yes | Agency reporting |
| Free tier | Yes, two domains free forever | Yes, limited free scan |
Who should pick which?
Pick Lavawall® if…
You are an MSP or lean IT team and want your whole external attack surface watched across every stack, not one WordPress site scanned.
You need the outside view joined to endpoint and Microsoft 365 security and to compliance evidence, from one console.
You want a free, white-label scan to show prospects their own exposure.
Pick WPSec if…
Your concern is specifically WordPress: plugin, theme, and core vulnerabilities on the sites you manage.
You want a focused CMS scanner and agency-style reporting for many WordPress installs.
Frequently asked
- Does Lavawall® replace WPSec?
- If your need is scanning a WordPress site for vulnerable plugins, themes, and core files, WPSec is purpose-built for that and Lavawall® is not a WordPress scanner. Scout maps the wider attack surface, and the platform covers endpoints, Microsoft 365, and compliance that a CMS scan never touches.
- Does Lavawall® scan websites at all?
- Scout assesses your internet-facing exposure, domains, subdomains, TLS, open services, and email authentication, rather than crawling a WordPress install for plugin-level CVEs. The two answer different questions and can be used together.
- Is Scout free like WPSec's basic scan?
- Yes. Two domains scan free, forever, with Scout. Paid tiers add continuous monitoring, more domains, and the full endpoint, Microsoft 365, and GRC platform.