TiloBox
Back to directory
WPScan project preview

WPScan

WordPress security scanner to detect vulnerable plugins, themes, and core configurations.

LicenseGPL-3.0
GitHub stars8.5k
Last commit1 weeks ago
Tags5 topics
Wordpress ScannerAppsec AuditorRuby SecurityVulnerability ScannerSecurity
Overview

Why consider WPScan?

WPScan is a free, open-source black-box WordPress vulnerability scanner written in Ruby. WPScan enumerates installed plugins, theme versions, user usernames, sensitive backups, and XML-RPC endpoints, cross-referencing findings against the WPScan Vulnerability Database.

Guided learning

Learn WPScan by building

Practical setup notes, real use cases, and copy-ready examples in one focused guide.

1 min read 2 sections
In this guide2 sections

Overview of WPScan

WPScan scans WordPress instances for known CVE security flaws in plugins, themes, and database configs.

Quickstart

bash
1wpscan --url https://example.com --enumerate vp,vt,u

WPScan is licensed under the GNU General Public License v3.0 (GPL-3.0).

Related tools

More options with a similar category or technology profile.

WPScan FAQs

WPScan is listed as a Developer Tools tool on TiloBox. Review the overview, features, and official documentation on this page to decide whether it solves your specific workflow.

Start with the project's GitHub repository and official website for supported installation and deployment instructions. Test the setup with representative data or a small project before rolling it out more widely.

WPScan is listed under the GPL-3.0 license. Read the complete license text and the project's notices before using, modifying, or distributing the software.

Production readiness depends on your requirements. Review maintenance activity, security practices, documentation, backup and upgrade procedures, and compatibility with your stack; then validate it in a non-production environment.

WPScan is listed as an alternative to Wordfence. Compare the core workflow, deployment model, integrations, and licensing against your must-have requirements before switching.