WPScan is a black-box WordPress vulnerability scanner written in Ruby. It analyzes WordPress sites to identify outdated core, plugins, themes, exposed APIs, and known vulnerabilities using a large built-in vulnerability database. It is a popular security auditing tool for pentesters and site administrators.
Features
- Detects vulnerable WordPress core, plugin, and theme versions
- Enumerates users, media files, backups, and server info
- Integration with WPScan vulnerability API for detailed results
- Supports brute-force login tests and password enumeration
- CLI and Docker-based usage for flexibility
- Regularly updated vulnerability database
Categories
SecurityFollow WPScan
Other Useful Business Software
Demo Series - Small Business Backup By Veeam
Watch this on-demand demo series and learn how to protect your Microsoft 365 data with clear, simple, actionable steps that are easy to implement for businesses of all sizes.
Rate This Project
Login To Rate This Project
User Reviews
Be the first to post a review of WPScan!