WPScan
WordPress security scanner to detect vulnerable plugins, themes, and core configurations.
Why consider WPScan?
WPScan is a free, open-source black-box WordPress vulnerability scanner written in Ruby. WPScan enumerates installed plugins, theme versions, user usernames, sensitive backups, and XML-RPC endpoints, cross-referencing findings against the WPScan Vulnerability Database.
Learn WPScan by building
Practical setup notes, real use cases, and copy-ready examples in one focused guide.
In this guide2 sections
Overview of WPScan
WPScan scans WordPress instances for known CVE security flaws in plugins, themes, and database configs.
Quickstart
wpscan --url https://example.com --enumerate vp,vt,uWPScan is licensed under the GNU General Public License v3.0 (GPL-3.0).
Related tools
More options with a similar category or technology profile.
diskus
Minimal, fast alternative to du -sh written in Rust using multi-threaded directory traversal.
peco
Simplistic interactive filtering tool for Unix pipelines, process lists, and file trees.
Dapr CLI
Command-line tool for managing Dapr distributed application runtime environments and sidecars.
Freeze
Generate beautiful image screenshots and SVGs of code snippets and terminal outputs.