Is wordpress.org legit?
This site appears largely trusted, having a long-standing online presence and robust infrastructure. However, a significant amount of hidden content, missing direct contact information, and incomplete legal pages are areas for concern.
Software & Downloads average: 78/100 · based on 75 sites
Checked: April 21, 2026 at 10:51 PM UTC
Is wordpress.org a scam? Here's what we found.
The site uses modern TLS 1.3 encryption and has a valid SSL certificate, and Google Web Risk reports no threats. However, 14 hidden elements are a moderate concern, potentially indicating attempts to conceal content.
With a domain age of over 23 years, the site demonstrates a strong, long-established online identity. Domain registration details are clear and managed by a reputable registrar.
The site enjoys a high global Tranco rank, indicating significant web traffic and widespread recognition. It is not listed on any DNS blacklists, reinforcing a clean reputation.
While the site has complete branding and a presence across multiple social media platforms, the absence of clear contact information on the homepage hinders user accessibility and direct communication.
The site provides some legal information but is noted to be missing either a privacy policy or terms of service. This is a noticeable gap for user protection and regulatory adherence.
The site boasts excellent infrastructure, including proper DNS resolution, robust email authentication (SPF and DMARC), and strong HSTS and clickjacking protection, ensuring a stable and secure foundation.
Signals Detected
This is one of the most visited websites globally
Site uses structured data identifying itself as: Organization, WebSite
This business has no Trustpilot presence — not unusual for smaller or newer companies
Excessive hidden content found — may indicate cloaking or deceptive content
Resolves to: 2607:f978:5:8002::c68f:a4fc, 198.143.164.252
Mail servers: mail.wordpress.org.
Domain has SPF email authentication configured
Domain has DMARC email authentication configured
DNS providers: ns1.wordpress.org., ns2.wordpress.org., ns4.wordpress.org., ns3.wordpress.org.
Valid certificate, expires in 64 days
Certificate issued by Let's Encrypt
Connection uses TLS 1.3
Site has custom branding and social media metadata
crt.sh returned status 502
Domain created 2003-03-28T01:07:35Z (23 years, 4 months ago)
Registered through MarkMonitor Inc.
Expires in 3262 days
DNSSEC status from WHOIS
Sitemap found with 3 entries
robots.txt has 37 directives and references a sitemap
Site enforces HTTPS via HSTS
X-Frame-Options: SAMEORIGIN
Web server: nginx
No threats detected by Google Web Risk
Website is live and responding
No obvious contact information found on homepage
Website is missing either privacy policy or terms of service
Website links to multiple social media platforms
Not found on any DNS blacklists
Could not query Wayback Machine
Fast page load
Stay Safe Online
Good habits to protect yourself, no matter the scan result.
Never reuse passwords across sites.
Add a second layer of security to your accounts.
Always verify unfamiliar stores before entering payment info.