WPScan is a black-box WordPress vulnerability scanner written in Ruby. It analyzes WordPress sites to identify outdated core, plugins, themes, exposed APIs, and known vulnerabilities using a large built-in vulnerability database. It is a popular security auditing tool for pentesters and site administrators.

Features

  • Detects vulnerable WordPress core, plugin, and theme versions
  • Enumerates users, media files, backups, and server info
  • Integration with WPScan vulnerability API for detailed results
  • Supports brute-force login tests and password enumeration
  • CLI and Docker-based usage for flexibility
  • Regularly updated vulnerability database

Project Samples

Project Activity

See All Activity >

Categories

Security

Follow WPScan

WPScan Web Site

Other Useful Business Software
AI-generated apps that pass security review Icon
AI-generated apps that pass security review

Stop waiting on engineering. Build production-ready internal tools with AI—on your company data, in your cloud.

Retool lets you generate dashboards, admin panels, and workflows directly on your data. Type something like “Build me a revenue dashboard on my Stripe data” and get a working app with security, permissions, and compliance built in from day one. Whether on our cloud or self-hosted, create the internal software your team needs without compromising enterprise standards or control.
Try Retool free
Rate This Project
Login To Rate This Project

User Reviews

Be the first to post a review of WPScan!

Additional Project Details

Operating Systems

Linux, Mac, Windows

Programming Language

Ruby

Related Categories

Ruby Security Software

Registered

2025-07-31