What it checks
Out-of-date software
Software your site says it runs that its maker no longer supports or has since updated.
How it is checked
Sentinel reads the version your site states about itself and compares it with the maker's own list of current releases.
- Software versions. The WordPress and PHP versions your site states, against each maker's current releases, and any other version numbers it gives away.
What it can find
Your site runs software its maker no longer supports
Fix soonA real weakness that an attacker would look for.
- What it is
- The site says it runs a version that no longer receives security fixes from its maker.
- Why it matters
- Every weakness found in it from now on stays open, and attackers work from published lists of exactly those.
- How to fix it
- Upgrade to a version the maker still supports. For PHP this is usually one setting in the hosting control panel, after checking the site still works on the newer version.
Your site's software is behind the current release
Should fixMakes an attack easier or more damaging.
- What it is
- The site says it runs a version that is older than the maker's current release.
- Why it matters
- Updates often close security holes. The longer a site stays behind, the more known weaknesses it carries.
- How to fix it
- Update to the current release, after taking a backup.WordPress: Dashboard, Updates. Automatic updates for minor releases are on by default; check they have not been switched off.
Your server tells visitors exactly what software it runs
Worth tidyingGood practice that is missing.
- What it is
- The site announces the name and exact version of its server software with every page.
- Why it matters
- It saves an attacker the work of finding out, and lets them go straight to the weaknesses known for that version.
- How to fix it
- Turn off version banners in the web server and PHP settings.