WPScan
cli Subscriptionwpscan.com
🇬🇧 United Kingdom
Quick Facts
What it does
WordPress security scanner with database of 69,931+ vulnerabilities across WordPress core, plugins, and themes. Operated by Automattic (WordPress.com parent company). Available as CLI tool for researchers and API for integration. Partners with Jetpack Protect for free WordPress plugin. Enterprise tier includes Slack webhooks, CVSS scores, and instant alerts.
When to use it
- WordPress security audits
- Identifying vulnerable plugins/themes
- Continuous WordPress monitoring
- Security research and CVE lookups
When not to use it
- Non-WordPress sites
- General web vulnerability scanning
- When you need more than 25 API calls/day (free tier)
Limitations
- Free tier: 25 API calls/day
- WordPress-specific only
- Enterprise features require custom pricing
Frequently Asked Questions
Is WPScan free to use?
What platforms does WPScan support?
What are the rate limits for WPScan?
Does WPScan require an account?
Is WPScan open source?
What are the limitations of WPScan?
What does WPScan do?
Related Tools
Professional IonCube decoder supporting versions 10 through 15 with PHP 7.1 to 8.4. Upload encrypted PHP files and get readable source code back.
Test PHP code across 5 versions simultaneously. From PHP 4.0 to 8.4, see exactly how your code behaves.
AI-powered PHP malware detection. Learns from new samples to catch threats signatures miss.
Free remote website malware scanner. Checks blacklists, detects infections, and identifies outdated software.