search
Get Started
search
WPScan - Vulnerability Scanner
zoom_in Click to enlarge

WPScan

8.62
Great
language

description WPScan Overview

WPScan is a free, open-source command-line scanner designed to identify security vulnerabilities within WordPress websites. It achieves this by cross-referencing website configurations with extensive vulnerability databases and plugin/theme version information. Security professionals, web developers, and system administrators utilize WPScan to proactively assess and mitigate risks associated with WordPress installations.

help WPScan FAQ

What does WPScan check on a WordPress site?

WPScan checks WordPress core, themes, plugins, exposed users, and known vulnerabilities. It is a command-line scanner commonly used by security teams and WordPress administrators.

Does WPScan need an API token?

WPScan can run basic checks without one, but vulnerability data from the WPScan Vulnerability Database typically requires an API token. That token lets the tool map detected plugin and theme versions to known CVEs or advisories.

Is WPScan only for attackers?

No, WPScan is widely used for defensive audits of owned WordPress sites. The same enumeration features can be abused, so it should only be run against sites where you have permission.

Who maintains WPScan?

WPScan began as an open-source WordPress security scanner and later became part of Automattic's security ecosystem. It remains strongly associated with WordPress vulnerability research and command-line site assessment.

Reviews & Comments

Write a Review

rate_review

Be the first to review

Share your thoughts with the community and help others make better decisions.

Save to your list

Save your favorites and follow how their scores change over time.

Save favorites
Track changes
Compare scores

Already have an account? Sign in

Compare Items

See how they stack up against each other

Comparing
VS
Select 1 more item to compare