description WPScan Overview
WPScan is a free, open-source command-line scanner designed to identify security vulnerabilities within WordPress websites. It achieves this by cross-referencing website configurations with extensive vulnerability databases and plugin/theme version information. Security professionals, web developers, and system administrators utilize WPScan to proactively assess and mitigate risks associated with WordPress installations.
help WPScan FAQ
What does WPScan check on a WordPress site?
WPScan checks WordPress core, themes, plugins, exposed users, and known vulnerabilities. It is a command-line scanner commonly used by security teams and WordPress administrators.
Does WPScan need an API token?
WPScan can run basic checks without one, but vulnerability data from the WPScan Vulnerability Database typically requires an API token. That token lets the tool map detected plugin and theme versions to known CVEs or advisories.
Is WPScan only for attackers?
No, WPScan is widely used for defensive audits of owned WordPress sites. The same enumeration features can be abused, so it should only be run against sites where you have permission.
Who maintains WPScan?
WPScan began as an open-source WordPress security scanner and later became part of Automattic's security ecosystem. It remains strongly associated with WordPress vulnerability research and command-line site assessment.
explore Explore More
Similar to WPScan
See all arrow_forwardReviews & Comments
Write a Review
Be the first to review
Share your thoughts with the community and help others make better decisions.