Industry Context — Common BS Fingerprints in Security, Surveillance & Cybersecurity
WPScan
(https://wpscan.com) 📸 Data Snapshot: May 24, 2026Analyze the raw signals below. How would a machine score this business’s credibility?
Here are the exact signals captured from up to six pages of the site — the same raw inputs the evaluation engine analyzed. They are grouped by signal type so you can weigh each the way the machine does.
🏗️ Semantic Structure — heading hierarchy & page identity (Info Density · Commodity Fingerprint)
HOMEPAGE WPScan: WordPress Security Scanner (https://wpscan.com)
WPScan: WordPress Security Scanner
WPScan is an enterprise vulnerability database for WordPress. Be the first to know about vulnerabilities affecting your WordPress core, plugins & themes.
NAV_HEADING_REPEATED_BODY_FOOTER WPScan Terms of Service | WPScan (https://wpscan.com/terms/)
WPScan Terms of Service | WPScan
These terms of service (“TOS”) and the Order Form in which they are referenced (together the “Agreement”) shall govern Customer’s subscription to use the WPScan enterprise solution (the “Services”) offered by Automattic Inc. (“Automattic”). By executing an order form referencing the TOS (“Order Form”), Automattic and Customer agree to be bound by both the TOS and the…
NAV_HEADER_HEADING_REPEATED_FOOTER WordPress Theme vulnerabilities | WPScan (https://wpscan.com/themes/)
WordPress Theme vulnerabilities | WPScan
Discover the latest WordPress theme vulnerabilities. With WPScan's constantly updated database, protect your website from potential theme exploits.
NAV_HEADER_HEADING_REPEATED_FOOTER WordPress Vulnerabilities | WPScan (https://wpscan.com/wordpresses/)
WordPress Vulnerabilities | WPScan
Discover the latest WordPress security vulnerabilities. With WPScan's constantly updated database, protect your site from potential WordPress exploits.
📝 The Narrative — clean text per page (Info Density · Semantic Coherence)
HOMEPAGE (https://wpscan.com) WPScan: WordPress Security Scanner
[H1] It’s like having your own team of WordPress security experts Be the first to know about vulnerabilities affecting your WordPress installation, plugins, and themes. Get started [H1] Check your WordPress site for vulnerabilities Scan your site and get a free, instant report of your site safety. [H2] Trusted by the world’s largest brands “WPScan is a fantastic product. It’s fast, well written and comprehensive. It does one thing and does it really well.”Mario Heiderich, CEO of pentesting firm Cure53 “The WPScan vulnerability database itself is of immense value. There is no other collection of WordPress vulnerabilities like this available anywhere else.”Security Boulevard [H2] Cataloging 73,239 WordPress core, plugin, and theme vulnerabilities The WPScan database is continuously updated by leading WordPress security professionals. Learn how it works Screening WordPress vulnerabilities for over 10 years Crack team of WordPress security experts Continually monitoring the web for new vulnerabilities Flexible API that streamlines your workflow [H2] Security solutions for everyone [H3] Enterprise Get a quote WordPress protection with custom solutions for large enterprises. Custom pricing by number of sites Instant email alerts Vulnerabilities details by ID Latest API endpoints Webhooks: Slack & HTTP Description & PoC API data CVSS Risk Scores [H3] Researcher Start for free Security researchers are welcome to use the CLI scanner and API for non‑commercial purposes. CLI tools for researchers Capped at 25 API calls per day [H3] Need a small business plan? Jetpack Protect is a free plugin that uses WPScan data to alert you about threats to your website. Upgrade for WAF and one‑click fixes. Get Jetpack Protect View all FAQ View our Enterprise Terms of Service
SUB-PAGE (https://wpscan.com/terms/) WPScan Terms of Service | WPScan
[H1] WPScan Terms of Service These terms of service (“TOS”) and the Order Form in which they are referenced (together the “Agreement”) shall govern Customer’s subscription to use the WPScan enterprise solution (the “Services”) offered by Automattic Inc. (“Automattic”). By executing an order form referencing the TOS (“Order Form”), Automattic and Customer agree to be bound by both the TOS and the Order Form. “Customer” means the party that enters in an Order Form with Automattic. [H3] 1. General. Subject to the terms of this Agreement, including Customer’s payment of all applicable Subscription Fees (as set forth on the Order Form), Automattic shall provide the Services on the terms set forth herein. [H3] 2. License Grant. During the Term (defined below) and subject to Customer’s compliance with the terms of this Agreement, Automattic hereby grants Customer a non‑assignable, non‑transferable, non‑exclusive, revocable license to use the Services, but only in accordance with the terms herein and any other applicable legal restrictions set forth in any third party software used in association with the Services. [H3] 3. Usage Restrictions. Customer is prohibited from storing or downloading (in any fashion or for any length of time) any data relating to the Services, including but not limited to: any database provided by Automattic, instant email alerts, vulnerability data, latest API endpoints, webhooks: slack & HTTP, description of and proof of concept API data, CVSS Risk Scores (“Service Data”) other than for the purpose of using the Services, in accordance with this Agreement. Customer warrants that Customer shall not circumvent the Services by any means, including, without limitation, using email alert updates regarding Service Data, webhooks or other custom callbacks to the Service Data, or utilizing endpoints. Customer agrees that the Service Data is a vital part of Automattic’s Services and shall not do anything to undermine or dilute Automattic’s Service Data. The Customer further warrants that Customer will not use, access, download, reverse engineer or exploit any of the Service Data to create any similar or competing service and/or product of the Services. [H3] 4. Service Limits. Customer’s access and use of the Services is subject to Automattic’s API guidelines (https://developer.wordpress.com/guidelines/). Customer is responsible for maintaining the security of its access to the Services and is fully responsible for all activities that occur under its account and any other actions taken in connection with its use of the Services. Customer shall immediately notify Automattic of any unauthorized uses of the Services, its account or any other breaches of security. Automattic will not be liable for any acts or omissions by Customer, including any damages of any kind incurred as a result of such acts or omissions. [H3] 5. Ownership. Customer acknowledges and agrees that the Services and Service Data are the property of Automattic and its’ licensors and that the software, and all databases, data, and know‑how used in the provision and operation of the Services or Service Data are owned exclusively by Automattic and its licensors. Where applicable, the software, and all databases, data, and know‑how used in the provision and operation of the Services or Service Data are protected by copyright and other applicable intellectual property laws and Customer shall claim no ownership or interest therein. Nothing in this Agreement grants Customer any rights to, and Customer agrees not to store, modify, adapt, alter, copy, reverse engineer or disassemble the Services or Service Data, including without limitation any software, database or data contained therein, in any way. [H3] 6. Fees and Payment. Subscription Fees for the Services are as set forth on the Order Form. All payments shall be made in advance for the provision of Services and in United States Dollars or as otherwise agreed between the parties in writing. Any payments more than thirty (30) days overdue will bear a late payment fee of 1.5% per month, or, if lower, the maximum rate allowed by applicable law. In addition, Customer will pay all taxes, shipping, duties, withholdings, backup withholding and the like. When Automattic has the legal obligation to pay or collect such taxes, such amount shall be paid by Customer directly to Automattic. Customer will reimburse Automattic for all reasonable travel and other related expenses incurred by Automattic in its performance hereunder. Where the Customer has chosen to proceed with an Order Form specifying a number of sites, in the event Customer exceeds the number of sites set forth on the Order Form, as part of the Services for a given month, Automattic reserves the right to charge Customer for the exceeding number of sites. [H3] 7. Term and Termination. This Agreement shall commence as of the Effective Date and shall continue for the initial term set forth on the Order Form (the “Initial Term”). Following the Initial Term, this Agreement shall automatically renew for additional successive terms of the same duration as the Initial Term (each, a “Renewal Term”) at a 5% increase per year of the Initial Term (e.g. max 15% increase for a 3 year Initial Term), unless either party gives notice to the other party of its intention not to renew this Agreement no later than thirty (30) days before the end of the Initial Term or then‑current Renewal Term, as applicable. Ahead of each Renewal Term, Automattic may further increase the Subscription Fees for a Renewal Term subject to giving the Customer 45‑days notice of such increase. The Initial Term, together with any subsequent Renewal Term(s), shall be collectively referred to as the “Term.” Either party may terminate this Agreement by written notice to the other party in the event that such other party materially breaches this Agreement and does not cure such breach within thirty (30) days of written notice of such breach. Upon termination of this Agreement for any reason, Customer must, at request of Automattic, return or destroy all Service Data and cease using the Services, immediately. If the Agreement is terminated for any reason other than Automattic’s material breach, all amounts due or outstanding, will become immediately due and payable. [H3] 8. Trademarks. Automattic’s trademarks, service marks, graphics and logos used in connection with the Services are trademarks or registered trademarks of Automattic or Automattic’s licensors. Other trademarks, service marks, graphics and logos used in connection with Automattic’s products, services and sites may be the trademarks of other third parties. Customer’s use of the Services does not grant any rights or licenses to reproduce or otherwise use any Automattic or third‑party trademarks. [H3] 9. Disclaimer. Except as otherwise expressly stated, the Services is provided “as is”, and Automattic, its suppliers and its licensors make no representations or warranties, express or implied, including but not limited to warranties of merchantability, fitness for a particular purpose, title or non-infringement of proprietary rights. Automattic makes no representations and warranties regarding uptime for the Services and the accuracy of the Services. [H3] 10. Limitation of Liability. In no event will Automattic, its suppliers or its licensors be liable to Customer or any other party for any direct, indirect, special, consequential or exemplary damages, regardless of the basis or nature of the claim, resulting from or related to this Agreement or any use of the Services including without limitation any lost profits, business interruption, loss of data or otherwise, even if Automattic, its suppliers or its licensors were expressly advised of the possibility of such damages. In no event will the aggregate liability for any and all claims against Automattic, its suppliers and its licensors arising out of or related to use of the Services exceed the amounts actually paid by Customer to Automattic during the 6‑month period prior to the date a claim is made. Customer agrees that this Section 10 represents a reasonable allocation of risk. [H3] 11. Representations and Warranties. Customer represents and warrants that its performance under this Agreement and its use of the Services (i) will be in accordance with this Agreement and with any applicable laws, rules, and regulations; and (ii) will not violate, misappropriate, or infringe any intellectual property right of any third party. [H3] 12. Indemnification. Customer shall defend, indemnify and hold harmless Automattic, its contractors and its licensors, and their respective directors, officers, employees and agents from and against any and all claims and expenses, including attorneys’ fees, arising out of its use of the Services, including but not limited to out of Customer’s violation of any representation or warranty contained in this Agreement or Customers breach of Section 3 (Usage Restrictions). [H3] 13. Intellectual Property Rights All rights, title, and interests, including, but not limited to, all copyrights, trade secret rights, patent and trademark rights, whether foreign or domestic, in and to the Services (including, but not limited to, any source or object code, images, photographs, animations, video, audio, music, text, and apps incorporated into the Services), any accompanying printed materials, and any copies of the Services, are owned by and shall remain the sole property of Automattic. [H3] 14. Confidentiality. Both parties agree that all business, technical and financial information (including, without limitation, the identity of and information relating to both parties customers or employees) that either party develops, learns, or obtains in connection with this agreement or that are received by or for either party in confidence, constitute “Confidential Information.” Both parties will hold in confidence and not disclose or, except in performing the services, use any Confidential Information. However, neither party shall be obligated under this paragraph with respect to information which is or becomes readily publicly available without restriction through no fault of the respective party. Upon termination and as otherwise requested, both parties will promptly return all items and copies containing or embodying Confidential Information, except that each party may keep its personal copies of its compensation records and this Agreement. [H3] 15. Changes. No amendment, modification, extension, release, discharge or waiver of this Agreement, or any provision hereof, shall be valid or binding unless in writing and signed by a duly authorized representative of each Party. Notwithstanding the foregoing, Automattic may, in its sole discretion: (i) change or modify the basis for calculating fees and other charges with respect to the Services, to which Customer will be informed; or (ii) add new features or remove existing features offered through the Services. Customer’s continued use of the Services after any change outlined in (i) or (ii), or as required by Automattic from time to time, will be deemed as Customer’s acceptance. [H3] 16. Audit. If Automattic has a reasonable basis to believe that Customer is not in compliance with any of its obligations or usage restrictions (including, if applicable, Customer exceeds the agreed upon number of sites per year in the Order Form) under this Agreement, Automattic may audit or engage a third party to audit the Customer’s compliance with this Agreement, with ten (10) days’ prior notice. If a third party is engaged to perform an audit, should such audit confirm Customer’s non‑compliance with Customer’s obligations under this Agreement, Customer will bear the cost of such third‑party audit. [H3] 17. No Refunds. Customer is not entitled to any refund, rebate, compensation, or restitution for prepaid fees for any reason whatsoever. [H3] 18. Publicity. Customer must receive prior written approval to use Automattic’s name and logo for promotional purposes. If approval is granted, Customer agrees to abide by Automattic’s published trademark guidelines at all times, available athttps://automattic.com/press/brand‑materials/. [H3] 19. Survival. Upon termination, all rights and obligations created by this Agreement will terminate, except that the parties will continue to be bound by those terms that would by their nature survive such termination, including without limitation sections 2, 3, 5, 10, 11, 12, 13 and 14. [H3] 20. Miscellaneous. This Agreement constitutes the entire agreement between Automattic and Customer and supersedes and cancels all previous written and oral agreements and communications relating to the subject matter hereof. Any pre‑printed or standard terms of any purchase order, quote, confirmation, code of conduct or similar form, even if signed by the parties after the Effective Date hereof, shall have no force or effect. This Agreement is governed by the laws of the state of California, excluding its conflict of law provisions, and the proper venue for any disputes arising out of or relating to any of the same will be the state and federal courts located in San Francisco County, California. If any part of this Agreement is held invalid or unenforceable, that part will be construed to reflect the parties’ original intent, and the remaining portions will remain in full force and effect. A waiver by either party of any term or condition of this Agreement, any breach thereof, in any one instance, will not waive such term or condition or any subsequent breach thereof. This Agreement is not assignable or transferable by either party, provided that this Agreement may be assigned in its entirety by either party to a parent or affiliated company or to a successor‑in‑interest in connection with a sale of all or substantially all of a party’s assets or business. Last Updated – June 27, 2024
SUB-PAGE · THIN (https://wpscan.com/themes/) WordPress Theme vulnerabilities | WPScan
[H1] WordPress Theme Vulnerabilities Show Previous Letters 0-9 a b c d e f g h i j k l m n o p q r s t u v w x y z Show Next Letters Slug 15zine Published 2020-09-21 Title 15Zine < 3.3.0 - Reflected Cross-Site Scripting Slug 5star Published 2014-08-01 Title 5star by Templatic - CSRF File Upload Previous 1 Next
SUB-PAGE (https://wpscan.com/wordpresses/) WordPress Vulnerabilities | WPScan
[H1] WordPress Vulnerabilities Published 2025-09-22 Title WP < 6.8.3 - Contributor+ Sensitive Data Disclosure Published 2025-09-22 Title WP < 6.8.3 - Author+ DOM Stored XSS Published 2024-06-24 Title WordPress < 6.5.5 - Contributor+ Path Traversal in Template-Part Block Published 2024-06-24 Title WordPress < 6.5.5 - Contributor+ Stored XSS in Template-Part Block Published 2024-06-24 Title WordPress < 6.5.5 - Contributor+ Stored XSS in HTML API Published 2024-04-09 Title WP < 6.5.2 - Unauthenticated Stored XSS Published 2024-01-30 Title WordPress < 6.4.3 - Admin+ PHP File Upload Published 2024-01-30 Title WordPress < 6.4.3 - Deserialization of Untrusted Data Published 2023-12-06 Title WP 6.4-6.4.1 - POP Chain Published 2023-10-12 Title WP < 6.3.2 - Unauthenticated Post Author Email Disclosure Published 2023-10-12 Title WP < 6.3.2 - Contributor+ Comment Disclosure Published 2023-10-12 Title WP < 6.3.2 - Subscriber+ Arbitrary Shortcode Execution Published 2023-10-12 Title WP < 6.3.2 - Denial of Service via Cache Poisoning Published 2023-10-12 Title WP 5.6-6.3.1 - Reflected XSS via Application Password Requests Published 2023-10-12 Title WP 5.6-6.3.1 - Contributor+ Stored XSS via Navigation Block Published 2023-10-12 Title WP 6.3-6.3.1 - Contributor+ Stored XSS via Footnotes Block Published 2023-05-16 Title WP < 6.2.1 - Contributor+ Content Injection Published 2023-05-16 Title WP < 6.2.2 - Shortcode Execution in User Generated Data Published 2023-05-16 Title WP < 6.2.1 - Contributor+ Stored XSS via Open Embed Auto Discovery Published 2023-05-16 Title WP < 6.2.1 - Thumbnail Image Update via CSRF Published 2023-05-16 Title WP < 6.2.1 - Directory Traversal via Translation Files Published 2022-12-13 Title WP <= 6.2 - Unauthenticated Blind SSRF via DNS Rebinding Published 2022-10-17 Title WP < 6.0.3 - Multiple Stored XSS via Gutenberg Published 2022-10-17 Title WP < 6.0.3 - Data Exposure via REST Terms/Tags Endpoint Published 2022-10-17 Title WP < 6.0.3 - Stored XSS via RSS Widget Previous 1 2 3 4 5 Next
🛡️ Trust Signals — reviews, proof links, trust-theatre flag (Trust & Proof)
| Page | Reviews | Proof links |
|---|---|---|
| / (home) | 5 | 1 |
| /terms/ | 5 | 1 |
| /themes/ | 5 | 1 |
| /wordpresses/ | 5 | 1 |
🔗 Identity & Technical Layer — schema JSON-LD: identity chains, entity gaps (Identity & Authority)
Your Diagnosis
Before revealing the machine’s verdict, predict the BS score for each signal. Higher = more BS (more fluff, less verifiable substance). Drag each slider, then submit to compare your judgment against the engine.
Stuck? Reveal the heuristic lens — how the deterministic page-auditor reads each signal (no AI, pure pattern rules)
These are the structural rules a local, deterministic auditor applies — the same lens you can use to judge each signal. They describe what to look for, not this company’s result.
Classify each sentence as substantive or hollow. Grounding markers — numbers, currencies, dates, technical units, named entities — outweigh marketing adjectives. When fluff sits right next to hard evidence, the fluff is forgiven.
Pull the main entities out of the H1, then check whether they actually recur through the body. A page that announces one thing and then talks about another drifts. Headings with no real sentences underneath read as pseudo-substance.
Count trust words (review, testimonial, rating, verified) against real outbound proof links (Google, Trustpilot, Clutch, G2, Yelp). Lots of trust language with zero verification links is trust theatre. Unlinked logo galleries count against it.
Look at how much sentence length varies. Natural writing varies its rhythm; templated or mass-produced copy is statistically uniform. Very low variation reads as commodity content — unless unique named entities break the pattern.
Inspect the JSON-LD. Is there an Organization or Person schema, and does it carry sameAs links to real external profiles (LinkedIn, socials)? Missing schema or no identity declaration signals an anonymous entity.
Want to apply this lens yourself? The free BS Indicator Chrome extension runs these heuristic checks live on any page. Bear in mind it is a single-page, deterministic tool — it relies only on pattern rules for the page in front of it and does not perform the cross-page semantic correlation this audit uses, so its readout is a starting lens, not the full verdict.
Based on 370 businesses audited.
WPScan has 20.5 points less BS than the average for Security, Surveillance & Cybersecurity.
Security, Surveillance & Cybersecurity BS: WPScan (wpscan.com)
WPScan is a rare example of a product-led security site where the substance actually outweighs the signal. It functions more as a technical utility than a marketing brochure, providing immediate access to the data it claims to catalog.
Implement Organization and Person schema to formally link the ‘crack team’ to their professional credentials and connect the site to Automattic’s corporate identity. Increase the number of external proof links pointing to CVE entries or third-party security audits to substantiate the ‘enterprise’ trust claims. Replace the slightly generic H1 with a data-driven heading that highlights the database’s live update frequency.
The website perfectly aligns with the Security & Cybersecurity category, specifically focusing on vulnerability management and threat intelligence for the WordPress ecosystem. Technical indicators such as CVSS Risk Scores, API endpoints, and a database of 73,239 vulnerabilities confirm high industry specificity.
“The low score of 16 is driven by exceptional semantic coherence and high information density. The points accrued are primarily due to technical metadata failures (null schema) and standard marketing cliches in the hero section that do not reflect the high technical quality of the underlying content.”
This training module utilizes a snapshot of public data from WPScan, captured on May 24, 2026, to demonstrate how machine logic evaluates different types of business narratives.
Purpose: This data is presented under “Fair Use” / “Educational Exception” for the purpose of forensic semantic analysis, allowing users to compare human intuition against machine-generated evaluations.
Notice to WPScan: This analysis is part of a non-adversarial audit conducted by 1 Euro SEO. The results provided by 1EuroSEO are intended as professional feedback to help improve any website’s machine-readability and authority signals. The 1EuroSEO BS Detection Tool is a free tool, and anyone can test any company to see how their content is interpreted by AI models.
Any company can use the insights for free and improve its voice by comparing it to industry clichés or competitors. When a company has updated its content, it can always submit a new audit request, which will be reflected in a new current score.
To all users: You are encouraged to visit the live site at https://wpscan.com to view the most current version of its content and learn from the source what this company is about and what it offers.