Free Moodle Security Scanner
Get an instant security and hygiene report for any public Moodle installation. Non-intrusive, read-only scanning. No login required.
Security Scan Results
Want enterprise-grade Moodle security?
WebbLMS provides hardened Moodle hosting with security best practices built in from day one.
Book a Security ReviewHTTPS & TLS
Certificate validity, TLS version, HSTS headers, and mixed content detection.
Security Headers
CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and more.
File Exposure
Detection of exposed .git, .env, backups, SQL dumps, and sensitive directories.
Version Hygiene
Detection of exposed Moodle version, PHP version leakage, and outdated software.
Infrastructure
Directory indexing, server software exposure, and admin access controls.
How to use your scan
The report highlights checks visible from outside your Moodle site. Open each finding to see why it matters and a suggested next step, then review it with the team responsible for your platform.
What a finding tells you
For example, a missing security header may be flagged with an explanation and a configuration to review. A finding is a prompt to investigate, not proof that a site has been compromised.
What this scan cannot see
It does not log in, test permissions or plugins, exploit vulnerabilities, or inspect your server configuration. A strong score does not replace patching, monitoring, backups or a professional security assessment.
Questions about a result? Read why we built the Moodle Site Integrity Tester, or talk to our team.