Training Example: WPScan – Review the Data, Give Your Score & Compare to the Real AI Evaluation

Industry Context — Common BS Fingerprints in Security, Surveillance & Cybersecurity
Generic Claims: protecting your business, stay ahead of threats, world-class security, trusted by enterprises…
Red Flags: guaranteed prevention of all breaches, penetration testing without accreditation, security certifications for team without named individuals, no own-practice security certifications…
Semantic Drift Patterns: homepage claims enterprise SOC but services are basic antivirus resale, claims penetration testing expertise but no CREST or CHECK accreditation, homepage targets critical infrastructure but client list is SMB, claims 24/7 SOC but no staffing or operations evidence…
Proof Expectations: CREST, CHECK, or equivalent accreditation numbers, named team with security certifications (OSCP, CISSP, CEH), ISO 27001 certification for own operations, specific case studies with anonymized but detailed findings…

WPScan

(https://wpscan.com) 📸 Data Snapshot: May 24, 2026

Analyze the raw signals below. How would a machine score this business’s credibility?

Here are the exact signals captured from up to six pages of the site — the same raw inputs the evaluation engine analyzed. They are grouped by signal type so you can weigh each the way the machine does.

🏗️ Semantic Structure — heading hierarchy & page identity (Info Density · Commodity Fingerprint)
HOMEPAGE WPScan: WordPress Security Scanner (https://wpscan.com)
Title

WPScan: WordPress Security Scanner

Meta

WPScan is an enterprise vulnerability database for WordPress. Be the first to know about vulnerabilities affecting your WordPress core, plugins & themes.

H1 It’s like having your own team of WordPress security experts
H2 Trusted by the world’s largest brands
H2 Cataloging 73,239 WordPress core, plugin, and theme vulnerabilities
H2 Security solutions for everyone
H3 Enterprise
H3 Researcher
H3 Need a small business plan?
H3 Vulnerabilities
H4 About
H4 For Developers
H4 Other
NAV_HEADING_REPEATED_BODY_FOOTER WPScan Terms of Service | WPScan (https://wpscan.com/terms/)
Title

WPScan Terms of Service | WPScan

Meta

These terms of service (“TOS”) and the Order Form in which they are referenced (together the “Agreement”) shall govern Customer’s subscription to use the WPScan enterprise solution (the “Services”) offered by Automattic Inc. (“Automattic”). By executing an order form referencing the TOS (“Order Form”), Automattic and Customer agree to be bound by both the TOS and the…

H1 WPScan Terms of Service
H3 1. General.
H3 2. License Grant.
H3 3. Usage Restrictions.
H3 4. Service Limits.
H3 5. Ownership.
H3 6. Fees and Payment.
H3 7. Term and Termination.
H3 8. Trademarks.
H3 9. Disclaimer.
H3 10. Limitation of Liability.
H3 11. Representations and Warranties.
H3 12. Indemnification.
H3 13. Intellectual Property Rights
H3 14. Confidentiality.
H3 15. Changes.
H3 16. Audit.
H3 17. No Refunds.
H3 18. Publicity.
H3 19. Survival.
H3 20. Miscellaneous.
H3 Vulnerabilities
H4 About
H4 For Developers
H4 Other
NAV_HEADER_HEADING_REPEATED_FOOTER WordPress Theme vulnerabilities | WPScan (https://wpscan.com/themes/)
Title

WordPress Theme vulnerabilities | WPScan

Meta

Discover the latest WordPress theme vulnerabilities. With WPScan's constantly updated database, protect your website from potential theme exploits.

H1 WordPress Theme Vulnerabilities
H3 Vulnerabilities
H4 About
H4 For Developers
H4 Other
NAV_HEADER_HEADING_REPEATED_FOOTER WordPress Vulnerabilities | WPScan (https://wpscan.com/wordpresses/)
Title

WordPress Vulnerabilities | WPScan

Meta

Discover the latest WordPress security vulnerabilities. With WPScan's constantly updated database, protect your site from potential WordPress exploits.

H1 WordPress Vulnerabilities
H3 Vulnerabilities
H4 About
H4 For Developers
H4 Other
📝 The Narrative — clean text per page (Info Density · Semantic Coherence)
HOMEPAGE (https://wpscan.com) WPScan: WordPress Security Scanner
[H1] It’s like having your own team of WordPress security experts
Be the first to know about vulnerabilities affecting your WordPress installation, plugins, and themes.

Get started

[H1] Check your WordPress site for vulnerabilities
Scan your site and get a free, instant report of your site safety.

[H2] Trusted by the world’s largest brands
“WPScan is a fantastic product. It’s fast, well written and comprehensive. It does one thing and does it really well.”Mario Heiderich, CEO of pentesting firm Cure53
“The WPScan vulnerability database itself is of immense value. There is no other collection of WordPress vulnerabilities like this available anywhere else.”Security Boulevard
[H2] Cataloging 73,239 WordPress core, plugin, and theme vulnerabilities
The WPScan database is continuously updated by leading WordPress security professionals.
Learn how it works
Screening WordPress vulnerabilities for over 10 years
Crack team of WordPress security experts
Continually monitoring the web for new vulnerabilities
Flexible API that streamlines your workflow
[H2] Security solutions for everyone
[H3] Enterprise
Get a quote
WordPress protection with custom solutions for large enterprises.
Custom pricing by number of sites
Instant email alerts
Vulnerabilities details by ID
Latest API endpoints
Webhooks: Slack & HTTP
Description & PoC API data
CVSS Risk Scores
[H3] Researcher
Start for free
Security researchers are welcome to use the CLI scanner and API for non‑commercial purposes.
CLI tools for researchers
Capped at 25 API calls per day
[H3] Need a small business plan?
Jetpack Protect is a free plugin that uses WPScan data to alert you about threats to your website. Upgrade for WAF and one‑click fixes.
Get Jetpack Protect
View all FAQ
View our Enterprise Terms of Service
1795 chars
SUB-PAGE (https://wpscan.com/terms/) WPScan Terms of Service | WPScan
[H1] WPScan Terms of Service
These terms of service (“TOS”) and the Order Form in which they are referenced (together the “Agreement”) shall govern Customer’s subscription to use the WPScan enterprise solution (the “Services”) offered by Automattic Inc. (“Automattic”). By executing an order form referencing the TOS (“Order Form”), Automattic and Customer agree to be bound by both the TOS and the Order Form. “Customer” means the party that enters in an Order Form with Automattic.
[H3] 1. General.
Subject to the terms of this Agreement, including Customer’s payment of all applicable Subscription Fees (as set forth on the Order Form), Automattic shall provide the Services on the terms set forth herein.
[H3] 2. License Grant.
During the Term (defined below) and subject to Customer’s compliance with the terms of this Agreement, Automattic hereby grants Customer a non‑assignable, non‑transferable, non‑exclusive, revocable license to use the Services, but only in accordance with the terms herein and any other applicable legal restrictions set forth in any third party software used in association with the Services.
[H3] 3. Usage Restrictions.
Customer is prohibited from storing or downloading (in any fashion or for any length of time) any data relating to the Services, including but not limited to: any database provided by Automattic, instant email alerts, vulnerability data, latest API endpoints, webhooks: slack & HTTP, description of and proof of concept API data, CVSS Risk Scores (“Service Data”) other than for the purpose of using the Services, in accordance with this Agreement. Customer warrants that Customer shall not circumvent the Services by any means, including, without limitation, using email alert updates regarding Service Data, webhooks or other custom callbacks to the Service Data, or utilizing endpoints. Customer agrees that the Service Data is a vital part of Automattic’s Services and shall not do anything to undermine or dilute Automattic’s Service Data. The Customer further warrants that Customer will not use, access, download, reverse engineer or exploit any of the Service Data to create any similar or competing service and/or product of the Services.
[H3] 4. Service Limits.
Customer’s access and use of the Services is subject to Automattic’s API guidelines (https://developer.wordpress.com/guidelines/). Customer is responsible for maintaining the security of its access to the Services and is fully responsible for all activities that occur under its account and any other actions taken in connection with its use of the Services. Customer shall immediately notify Automattic of any unauthorized uses of the Services, its account or any other breaches of security. Automattic will not be liable for any acts or omissions by Customer, including any damages of any kind incurred as a result of such acts or omissions.
[H3] 5. Ownership.
Customer acknowledges and agrees that the Services and Service Data are the property of Automattic and its’ licensors and that the software, and all databases, data, and know‑how used in the provision and operation of the Services or Service Data are owned exclusively by Automattic and its licensors. Where applicable, the software, and all databases, data, and know‑how used in the provision and operation of the Services or Service Data are protected by copyright and other applicable intellectual property laws and Customer shall claim no ownership or interest therein. Nothing in this Agreement grants Customer any rights to, and Customer agrees not to store, modify, adapt, alter, copy, reverse engineer or disassemble the Services or Service Data, including without limitation any software, database or data contained therein, in any way.
[H3] 6. Fees and Payment.
Subscription Fees for the Services are as set forth on the Order Form. All payments shall be made in advance for the provision of Services and in United States Dollars or as otherwise agreed between the parties in writing. Any payments more than thirty (30) days overdue will bear a late payment fee of 1.5% per month, or, if lower, the maximum rate allowed by applicable law. In addition, Customer will pay all taxes, shipping, duties, withholdings, backup withholding and the like. When Automattic has the legal obligation to pay or collect such taxes, such amount shall be paid by Customer directly to Automattic. Customer will reimburse Automattic for all reasonable travel and other related expenses incurred by Automattic in its performance hereunder. Where the Customer has chosen to proceed with an Order Form specifying a number of sites, in the event Customer exceeds the number of sites set forth on the Order Form, as part of the Services for a given month, Automattic reserves the right to charge Customer for the exceeding number of sites.
[H3] 7. Term and Termination.
This Agreement shall commence as of the Effective Date and shall continue for the initial term set forth on the Order Form (the “Initial Term”). Following the Initial Term, this Agreement shall automatically renew for additional successive terms of the same duration as the Initial Term (each, a “Renewal Term”) at a 5% increase per year of the Initial Term (e.g. max 15% increase for a 3 year Initial Term), unless either party gives notice to the other party of its intention not to renew this Agreement no later than thirty (30) days before the end of the Initial Term or then‑current Renewal Term, as applicable. Ahead of each Renewal Term, Automattic may further increase the Subscription Fees for a Renewal Term subject to giving the Customer 45‑days notice of such increase. The Initial Term, together with any subsequent Renewal Term(s), shall be collectively referred to as the “Term.” Either party may terminate this Agreement by written notice to the other party in the event that such other party materially breaches this Agreement and does not cure such breach within thirty (30) days of written notice of such breach. Upon termination of this Agreement for any reason, Customer must, at request of Automattic, return or destroy all Service Data and cease using the Services, immediately. If the Agreement is terminated for any reason other than Automattic’s material breach, all amounts due or outstanding, will become immediately due and payable.
[H3] 8. Trademarks.
Automattic’s trademarks, service marks, graphics and logos used in connection with the Services are trademarks or registered trademarks of Automattic or Automattic’s licensors. Other trademarks, service marks, graphics and logos used in connection with Automattic’s products, services and sites may be the trademarks of other third parties. Customer’s use of the Services does not grant any rights or licenses to reproduce or otherwise use any Automattic or third‑party trademarks.
[H3] 9. Disclaimer.
Except as otherwise expressly stated, the Services is provided “as is”, and Automattic, its suppliers and its licensors make no representations or warranties, express or implied, including but not limited to warranties of merchantability, fitness for a particular purpose, title or non-infringement of proprietary rights. Automattic makes no representations and warranties regarding uptime for the Services and the accuracy of the Services.
[H3] 10. Limitation of Liability.
In no event will Automattic, its suppliers or its licensors be liable to Customer or any other party for any direct, indirect, special, consequential or exemplary damages, regardless of the basis or nature of the claim, resulting from or related to this Agreement or any use of the Services including without limitation any lost profits, business interruption, loss of data or otherwise, even if Automattic, its suppliers or its licensors were expressly advised of the possibility of such damages. In no event will the aggregate liability for any and all claims against Automattic, its suppliers and its licensors arising out of or related to use of the Services exceed the amounts actually paid by Customer to Automattic during the 6‑month period prior to the date a claim is made. Customer agrees that this Section 10 represents a reasonable allocation of risk.
[H3] 11. Representations and Warranties.
Customer represents and warrants that its performance under this Agreement and its use of the Services (i) will be in accordance with this Agreement and with any applicable laws, rules, and regulations; and (ii) will not violate, misappropriate, or infringe any intellectual property right of any third party.
[H3] 12. Indemnification.
Customer shall defend, indemnify and hold harmless Automattic, its contractors and its licensors, and their respective directors, officers, employees and agents from and against any and all claims and expenses, including attorneys’ fees, arising out of its use of the Services, including but not limited to out of Customer’s violation of any representation or warranty contained in this Agreement or Customers breach of Section 3 (Usage Restrictions).
[H3] 13. Intellectual Property Rights
All rights, title, and interests, including, but not limited to, all copyrights, trade secret rights, patent and trademark rights, whether foreign or domestic, in and to the Services (including, but not limited to, any source or object code, images, photographs, animations, video, audio, music, text, and apps incorporated into the Services), any accompanying printed materials, and any copies of the Services, are owned by and shall remain the sole property of Automattic.
[H3] 14. Confidentiality.
Both parties agree that all business, technical and financial information (including, without limitation, the identity of and information relating to both parties customers or employees) that either party develops, learns, or obtains in connection with this agreement or that are received by or for either party in confidence, constitute “Confidential Information.” Both parties will hold in confidence and not disclose or, except in performing the services, use any Confidential Information. However, neither party shall be obligated under this paragraph with respect to information which is or becomes readily publicly available without restriction through no fault of the respective party. Upon termination and as otherwise requested, both parties will promptly return all items and copies containing or embodying Confidential Information, except that each party may keep its personal copies of its compensation records and this Agreement.
[H3] 15. Changes.
No amendment, modification, extension, release, discharge or waiver of this Agreement, or any provision hereof, shall be valid or binding unless in writing and signed by a duly authorized representative of each Party. Notwithstanding the foregoing, Automattic may, in its sole discretion: (i) change or modify the basis for calculating fees and other charges with respect to the Services, to which Customer will be informed; or (ii) add new features or remove existing features offered through the Services. Customer’s continued use of the Services after any change outlined in (i) or (ii), or as required by Automattic from time to time, will be deemed as Customer’s acceptance.
[H3] 16. Audit.
If Automattic has a reasonable basis to believe that Customer is not in compliance with any of its obligations or usage restrictions (including, if applicable, Customer exceeds the agreed upon number of sites per year in the Order Form) under this Agreement, Automattic may audit or engage a third party to audit the Customer’s compliance with this Agreement, with ten (10) days’ prior notice. If a third party is engaged to perform an audit, should such audit confirm Customer’s non‑compliance with Customer’s obligations under this Agreement, Customer will bear the cost of such third‑party audit.
[H3] 17. No Refunds.
Customer is not entitled to any refund, rebate, compensation, or restitution for prepaid fees for any reason whatsoever.
[H3] 18. Publicity.
Customer must receive prior written approval to use Automattic’s name and logo for promotional purposes. If approval is granted, Customer agrees to abide by Automattic’s published trademark guidelines at all times, available athttps://automattic.com/press/brand‑materials/.
[H3] 19. Survival.
Upon termination, all rights and obligations created by this Agreement will terminate, except that the parties will continue to be bound by those terms that would by their nature survive such termination, including without limitation sections 2, 3, 5, 10, 11, 12, 13 and 14.
[H3] 20. Miscellaneous.
This Agreement constitutes the entire agreement between Automattic and Customer and supersedes and cancels all previous written and oral agreements and communications relating to the subject matter hereof. Any pre‑printed or standard terms of any purchase order, quote, confirmation, code of conduct or similar form, even if signed by the parties after the Effective Date hereof, shall have no force or effect. This Agreement is governed by the laws of the state of California, excluding its conflict of law provisions, and the proper venue for any disputes arising out of or relating to any of the same will be the state and federal courts located in San Francisco County, California. If any part of this Agreement is held invalid or unenforceable, that part will be construed to reflect the parties’ original intent, and the remaining portions will remain in full force and effect. A waiver by either party of any term or condition of this Agreement, any breach thereof, in any one instance, will not waive such term or condition or any subsequent breach thereof. This Agreement is not assignable or transferable by either party, provided that this Agreement may be assigned in its entirety by either party to a parent or affiliated company or to a successor‑in‑interest in connection with a sale of all or substantially all of a party’s assets or business.
Last Updated – June 27, 2024
13938 chars
SUB-PAGE · THIN (https://wpscan.com/themes/) WordPress Theme vulnerabilities | WPScan
[H1]
WordPress Theme Vulnerabilities

Show Previous Letters

0-9

a

b

c

d

e

f

g

h

i

j

k

l

m

n

o

p

q

r

s

t

u

v

w

x

y

z

Show Next Letters

Slug
15zine

Published
2020-09-21
Title
15Zine < 3.3.0 - Reflected Cross-Site Scripting

Slug
5star

Published
2014-08-01
Title
5star by Templatic - CSRF File Upload

Previous

1

Next
496 chars
SUB-PAGE (https://wpscan.com/wordpresses/) WordPress Vulnerabilities | WPScan
[H1]
WordPress Vulnerabilities

Published
2025-09-22
Title
WP < 6.8.3 - Contributor+ Sensitive Data Disclosure

Published
2025-09-22
Title
WP < 6.8.3 - Author+ DOM Stored XSS

Published
2024-06-24
Title
WordPress < 6.5.5 - Contributor+ Path Traversal in Template-Part Block

Published
2024-06-24
Title
WordPress < 6.5.5 - Contributor+ Stored XSS in Template-Part Block

Published
2024-06-24
Title
WordPress < 6.5.5 - Contributor+ Stored XSS in HTML API

Published
2024-04-09
Title
WP < 6.5.2 - Unauthenticated Stored XSS

Published
2024-01-30
Title
WordPress < 6.4.3 - Admin+ PHP File Upload

Published
2024-01-30
Title
WordPress < 6.4.3 - Deserialization of Untrusted Data

Published
2023-12-06
Title
WP 6.4-6.4.1 - POP Chain

Published
2023-10-12
Title
WP < 6.3.2 - Unauthenticated Post Author Email Disclosure

Published
2023-10-12
Title
WP < 6.3.2 - Contributor+ Comment Disclosure

Published
2023-10-12
Title
WP < 6.3.2 - Subscriber+ Arbitrary Shortcode Execution

Published
2023-10-12
Title
WP < 6.3.2 - Denial of Service via Cache Poisoning

Published
2023-10-12
Title
WP 5.6-6.3.1 - Reflected XSS via Application Password Requests

Published
2023-10-12
Title
WP 5.6-6.3.1 - Contributor+ Stored XSS via Navigation Block

Published
2023-10-12
Title
WP 6.3-6.3.1 - Contributor+ Stored XSS via Footnotes Block

Published
2023-05-16
Title
WP < 6.2.1 - Contributor+ Content Injection

Published
2023-05-16
Title
WP < 6.2.2 - Shortcode Execution in User Generated Data

Published
2023-05-16
Title
WP < 6.2.1 - Contributor+ Stored XSS via Open Embed Auto Discovery

Published
2023-05-16
Title
WP < 6.2.1 - Thumbnail Image Update via CSRF

Published
2023-05-16
Title
WP < 6.2.1 - Directory Traversal via Translation Files

Published
2022-12-13
Title
WP <= 6.2 - Unauthenticated Blind SSRF via DNS Rebinding

Published
2022-10-17
Title
WP < 6.0.3 - Multiple Stored XSS via Gutenberg

Published
2022-10-17
Title
WP < 6.0.3 - Data Exposure via REST Terms/Tags Endpoint

Published
2022-10-17
Title
WP < 6.0.3 - Stored XSS via RSS Widget

Previous

1

2

3

4

5

Next
2408 chars
🛡️ Trust Signals — reviews, proof links, trust-theatre flag (Trust & Proof)
20Review mentions (all pages)
4External proof links (all pages)
PageReviewsProof links
/ (home) 5 1
/terms/ 5 1
/themes/ 5 1
/wordpresses/ 5 1
🔗 Identity & Technical Layer — schema JSON-LD: identity chains, entity gaps (Identity & Authority)
Homepage — no schema detected (entity gap)
/terms/ — no schema detected (entity gap)
/themes/ — no schema detected (entity gap)
/wordpresses/ — no schema detected (entity gap)

Your Diagnosis

Before revealing the machine’s verdict, predict the BS score for each signal. Higher = more BS (more fluff, less verifiable substance). Drag each slider, then submit to compare your judgment against the engine.

Information Density 0 / 30
Read the Narrative & headings: do hard facts (prices, dates, numbers) outweigh fluff power-words?
Semantic Coherence 0 / 20
Compare the homepage promise against the sub-page reality. Do they hold the same line?
Trust & Proof 0 / 20
Weigh review mentions against actual external proof links. Claims without verification = theatre.
Commodity Fingerprint 0 / 15
Check headings & narrative against the industry clichés in the setup above.
Identity & Authority 0 / 15
Inspect the schema: is there real Organization/Person identity with sameAs links, or gaps?
Your predicted BS score 0 / 100
💡 Stuck? Reveal the heuristic lens — how the deterministic page-auditor reads each signal (no AI, pure pattern rules)

These are the structural rules a local, deterministic auditor applies — the same lens you can use to judge each signal. They describe what to look for, not this company’s result.

Information Density

Classify each sentence as substantive or hollow. Grounding markers — numbers, currencies, dates, technical units, named entities — outweigh marketing adjectives. When fluff sits right next to hard evidence, the fluff is forgiven.

Semantic Alignment

Pull the main entities out of the H1, then check whether they actually recur through the body. A page that announces one thing and then talks about another drifts. Headings with no real sentences underneath read as pseudo-substance.

Trust & Proof

Count trust words (review, testimonial, rating, verified) against real outbound proof links (Google, Trustpilot, Clutch, G2, Yelp). Lots of trust language with zero verification links is trust theatre. Unlinked logo galleries count against it.

Commodity Fingerprint

Look at how much sentence length varies. Natural writing varies its rhythm; templated or mass-produced copy is statistically uniform. Very low variation reads as commodity content — unless unique named entities break the pattern.

Identity & Authority

Inspect the JSON-LD. Is there an Organization or Person schema, and does it carry sameAs links to real external profiles (LinkedIn, socials)? Missing schema or no identity declaration signals an anonymous entity.

Want to apply this lens yourself? The free BS Indicator Chrome extension runs these heuristic checks live on any page. Bear in mind it is a single-page, deterministic tool — it relies only on pattern rules for the page in front of it and does not perform the cross-page semantic correlation this audit uses, so its readout is a starting lens, not the full verdict.

B
BS Level
Security, Surveillance & Cybersecurity
36.5 Avg BS

Based on 370 businesses audited.

BS Detector

Security, Surveillance & Cybersecurity BS: WPScan (wpscan.com)

https://wpscan.com 📍 Industry: Security, Surveillance & Cybersecurity
16 BS / 100

WPScan is a rare example of a product-led security site where the substance actually outweighs the signal. It functions more as a technical utility than a marketing brochure, providing immediate access to the data it claims to catalog.

Info Density Power-words vs. Substance ratio.
5
17% BS
Semantic Coherence Homepage promise vs. Sub-page reality.
0
0% BS
Trust & Proof Verifiable evidence vs. Trust Theatre.
4
20% BS
Commodity Fingerprint Detection of industry clichés/templates.
2
13% BS
Identity & Authority Expert verifiability & Schema depth.
5
33% BS

Implement Organization and Person schema to formally link the ‘crack team’ to their professional credentials and connect the site to Automattic’s corporate identity. Increase the number of external proof links pointing to CVE entries or third-party security audits to substantiate the ‘enterprise’ trust claims. Replace the slightly generic H1 with a data-driven heading that highlights the database’s live update frequency.

The website perfectly aligns with the Security & Cybersecurity category, specifically focusing on vulnerability management and threat intelligence for the WordPress ecosystem. Technical indicators such as CVSS Risk Scores, API endpoints, and a database of 73,239 vulnerabilities confirm high industry specificity.

“The low score of 16 is driven by exceptional semantic coherence and high information density. The points accrued are primarily due to technical metadata failures (null schema) and standard marketing cliches in the hero section that do not reflect the high technical quality of the underlying content.”

Verified Analysis Date: May 24, 2026 © 1EuroSEO Independent Evaluator — Non-Sponsored Result
Brand AI Reputation