Wordfence looks for vulnerabilities such as old or outdated plugins, weak passwords, or compromised files.
Wordpress is delivered in a pretty secure state. Most hackers get in through weak passwords our poorly coded add-ons. Here's some more info on securing your site:
http://codex.wordpress.org/Hardening_WordPress