Is wordpress.org legit?
WordPress.org is the legitimate and authoritative home of the world’s most popular content management system. You can trust this site for downloading software and accessing developer resources, as it is a foundational pillar of the internet with a clean security track record.
Software & Downloads average: 65/100 · based on 120 sites
Checked: May 20, 2026 at 7:24 PM UTC ·
Is wordpress.org a scam? Here's what we found.
The site employs a robust security posture with properly configured modern TLS 1.3 and HSTS, ensuring a secure environment for software distribution.
With over two decades of consistent domain history and high global traffic, the identity of this site is well-established as the official home of the WordPress software project.
As a foundational pillar of the web, its reputation is backed by its status as a widely recognized nonprofit and open-source project leader.
The site provides a clear About page and identifies its project leadership well, though the lack of a standardized contact page is a typical oversight for large-scale open-source repositories.
While this is a non-commercial software hub, the inconsistent presence of formal legal pages like Privacy Policies or Terms of Service is a notable gap for a site of this massive scale.
The site uses high-quality professional infrastructure with properly configured email authentication and a reliable, long-term domain registration strategy.
Signals Detected
This is one of the most visited websites globally
Site uses structured data identifying itself as: Organization, WebSite
WordPress
Open source software which you can use to easily create a beautiful website, blog, or app.
Blog Tool, Publishing Platform, and CMS – WordPress.org
Open source software which you can use to easily create a beautiful website, blog, or app.
HTML declares lang="en-US"
Meet WordPress
og:type declared as website
This business has no Trustpilot presence — not unusual for smaller or newer companies
Excessive hidden content found — may indicate cloaking or deceptive content
Resolves to: 2607:f978:5:8002::c68f:a4fc, 198.143.164.252
Mail servers: smtp1-ord.wordpress.org., smtp2-ord.wordpress.org.
Domain has SPF email authentication configured
Domain has DMARC email authentication configured
DNS providers: ns4.wordpress.org., ns2.wordpress.org., ns3.wordpress.org., ns1.wordpress.org.
Valid certificate, expires in 36 days
Certificate issued by Let's Encrypt
Connection uses TLS 1.3
Site has custom branding and social media metadata
Domain created 2003-03-28T01:07:35Z (23 years, 5 months ago)
Registered through MarkMonitor Inc.
Expires in 3233 days
DNSSEC status from WHOIS
Sitemap found with 3 entries
robots.txt has 37 directives and references a sitemap
Site enforces HTTPS via HSTS
X-Frame-Options: SAMEORIGIN
Web server: nginx
No threats detected by Google Web Risk
Wayback CDX returned status 503
Website is live and responding
No obvious contact information found on homepage
Website is missing either privacy policy or terms of service
No dedicated legal-entity disclosure page detected — common and expected outside the EU, but required for commercial sites in Germany, France, Spain, Italy, and other EU jurisdictions.
Site publishes an About / Team / Company page — a transparency signal that the operator is willing to describe who runs the business.
Website links to multiple social media platforms
Not found on any DNS blacklists
13 certificates found for 14 unique names
Average page load time
Stay Safe Online
Good habits to protect yourself, no matter the scan result.
Never reuse passwords across sites.
Add a second layer of security to your accounts.
Always verify unfamiliar stores before entering payment info.