SECURITY FINDING

WordPress readme.html exposes your exact version

What it is

readme.html is publicly accessible and reveals the exact WordPress version installed. Combined with a known vulnerability for that exact version, this makes the site an easy, specific target.

How to fix it

Remove or block access to readme.html, and keep WordPress core updated — the WordPress Plugin's Security tab can block it for you.

In depth

Your WordPress site has a file called readme.html that anyone on the internet can find and read, and it tells them exactly which version of WordPress you're running. Think of it like having your home address and a sign on your door announcing the exact model of your front door lock and when it was made. If someone knows about a security problem in that specific lock model, they can target your house directly and try to break in using that weakness. This matters because hackers use automated tools to find sites running outdated WordPress versions with known problems, and this file makes their job trivial. Fixing it is straightforward and you have two options: either completely remove the readme.html file from your server, or configure your website to block anyone from accessing it. Most security plugins, including the free ones, have a simple on-off toggle in their settings that will automatically hide or delete this file for you, so you don't need technical knowledge to fix it. After you enable that protection, you should also make sure WordPress itself is always updated to the latest version, which you can do in just a few clicks from your WordPress dashboard.

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.