Is wordpress.com legit?
WordPress.com is a well-established and generally trustworthy platform with strong infrastructure and good security practices. However, the unexpected amount of hidden content raises a moderate concern regarding transparency.
Hosting & Domains average: 77/100 · based on 38 sites
Checked: April 21, 2026 at 5:19 PM UTC
Is wordpress.com a scam? Here's what we found.
The site uses a modern TLS 1.3 encryption with a valid certificate from Let's Encrypt and enforces HTTPS, indicating robust security for user connections. Google Web Risk also confirms no immediate threats.
With a 26-year-old domain registered through a professional registrar and public WHOIS information, WordPress.com demonstrates a clear and long-standing online identity.
As one of the most highly ranked global websites with a long history and clean DNS blacklists, its reputation is strong, even with a lack of Trustpilot presence.
While contact info, legal pages, and social media links are present, the significant number of hidden elements is a red flag that hinders complete transparency about the site's content.
The site provides essential legal safeguards by having readily available privacy policy and terms of service pages, which is crucial for user trust and regulatory adherence.
The robust infrastructure includes multiple IP resolutions, proper email authentication (SPF/DMARC), and responsive operation, ensuring reliable service and communication.
Signals Detected
This is one of the most visited websites globally
Site uses structured data identifying itself as: Organization, WebSite, BreadcrumbList
This business has no Trustpilot presence — not unusual for smaller or newer companies
Domain created 2000-03-03T12:13:23Z (26 years, 6 months ago)
Registered through MarkMonitor Inc.
Expires in 2507 days
DNSSEC status from WHOIS
Excessive hidden content found — may indicate cloaking or deceptive content
Valid certificate, expires in 46 days
Certificate issued by Let's Encrypt
Connection uses TLS 1.3
Resolves to: 192.0.78.9, 192.0.78.17
Mail servers: mx-ams.automattic.com., mx-dfw.automattic.com.
Domain has SPF email authentication configured
Domain has DMARC email authentication configured
DNS providers: ns4.wordpress.com., ns2.wordpress.com., ns1.wordpress.com., ns3.wordpress.com.
Site has custom branding and social media metadata
robots.txt has 45 directives and references a sitemap
Sitemap found with 1 entries
Site enforces HTTPS via HSTS
X-Frame-Options: SAMEORIGIN
Web server: nginx
No threats detected by Google Web Risk
Website is live and responding
Website appears to have contact information
Website has both privacy policy and terms of service pages
Website links to multiple social media platforms
Not found on any DNS blacklists
Could not query Wayback Machine
Could not query certificate transparency logs
Fast page load
Stay Safe Online
Good habits to protect yourself, no matter the scan result.
Never reuse passwords across sites.
Add a second layer of security to your accounts.
Always verify unfamiliar stores before entering payment info.