WPScan is a black-box WordPress vulnerability scanner written in Ruby. It analyzes WordPress sites to identify outdated core, plugins, themes, exposed APIs, and known vulnerabilities using a large built-in vulnerability database. It is a popular security auditing tool for pentesters and site administrators.

Features

  • Detects vulnerable WordPress core, plugin, and theme versions
  • Enumerates users, media files, backups, and server info
  • Integration with WPScan vulnerability API for detailed results
  • Supports brute-force login tests and password enumeration
  • CLI and Docker-based usage for flexibility
  • Regularly updated vulnerability database

Project Samples

Project Activity

See All Activity >

Categories

Security

Follow WPScan

WPScan Web Site

Other Useful Business Software
Award-Winning Medical Office Software Designed for Your Specialty Icon
Award-Winning Medical Office Software Designed for Your Specialty

Succeed and scale your practice with cloud-based, data-backed, AI-powered healthcare software.

RXNT is an ambulatory healthcare technology pioneer that empowers medical practices and healthcare organizations to succeed and scale through innovative, data-backed, AI-powered software.
Learn More
Rate This Project
Login To Rate This Project

User Reviews

Be the first to post a review of WPScan!

Additional Project Details

Operating Systems

Linux, Mac, Windows

Programming Language

Ruby

Related Categories

Ruby Security Software

Registered

2025-07-31