search
Get Started
search
WPScan CLI Scanner - Website Analyzer
zoom_in Click to enlarge

WPScan CLI Scanner

language

description WPScan CLI Scanner Overview

The WPScan CLI Scanner is a command-line utility for security professionals and developers. It analyzes WordPress websites to identify outdated software versions – including themes, plugins, and core files – which are frequently targeted by cyberattacks. The scanner compares website data against extensive vulnerability databases providing an immediate assessment of potential risks and enabling proactive security measures.

help WPScan CLI Scanner FAQ

What does WPScan check on a WordPress site?

WPScan checks WordPress core, plugins, themes, users, and known vulnerability data. It is commonly run from the command line during WordPress security audits.

Does WPScan need an API token?

WPScan can run basic scans without a token, but vulnerability database results typically require a WPScan API token. The token lets the scanner match detected versions against known CVEs and advisories.

Can WPScan fix vulnerable WordPress plugins?

No, WPScan is a scanner, not a patching tool. It reports issues such as outdated plugins or exposed usernames, and the site owner still has to update WordPress, replace plugins, or harden configuration.

Is WPScan only for Linux servers?

No, WPScan is a Ruby-based CLI tool and can be used from common security workstations, containers, and CI environments. Many users run it from Kali Linux, Docker, or a local development machine.

Reviews & Comments

Write a Review

rate_review

Be the first to review

Share your thoughts with the community and help others make better decisions.

Save to your list

Save your favorites and follow how their scores change over time.

Save favorites
Track changes
Compare scores

Already have an account? Sign in

Compare Items

See how they stack up against each other

Comparing
VS
Select 1 more item to compare