WordPress itself is uncritical — the data-protection issues almost always come via themes, plugins and embedded content.
Common sources: themes that load Google Fonts from Google; analytics or marketing plugins without consent logic; embedded YouTube/Maps blocks; emojis and Gravatars from external servers. For all non-necessary access, § 25 (1) TDDDG applies.
The free scan checks the delivered HTML and shows which services are embedded, whether a cookie banner is detected and whether privacy-policy and legal-notice links are present — with context for each finding. It is not a substitute for legal advice.
This text is general information to the best of our knowledge, not legal advice. For an individual case, consult a law firm specialising in IT law.