WPScan is a black-box WordPress vulnerability scanner written in Ruby. It analyzes WordPress sites to identify outdated core, plugins, themes, exposed APIs, and known vulnerabilities using a large built-in vulnerability database. It is a popular security auditing tool for pentesters and site administrators.
Features
- Detects vulnerable WordPress core, plugin, and theme versions
- Enumerates users, media files, backups, and server info
- Integration with WPScan vulnerability API for detailed results
- Supports brute-force login tests and password enumeration
- CLI and Docker-based usage for flexibility
- Regularly updated vulnerability database
Categories
SecurityFollow WPScan
Other Useful Business Software
Earn up to 15% annual interest with Nexo.
Generate interest, access liquidity without selling, and execute trades seamlessly. All in one platform.
Geographic restrictions, eligibility, and terms apply.
Rate This Project
Login To Rate This Project
User Reviews
Be the first to post a review of WPScan!