Skip to content
AppClap
WPScan is unclaimed —
W

WPScan

WordPress Security Scanner·wpscan.com

Visit

WPScan is an enterprise vulnerability database and scanning service for WordPress, cataloging vulnerabilities in WordPress core, plugins, and themes. It offers a command-line security scanner, a versatile API, and integrations for detecting vulnerabilities and common security misconfigurations on WordPress sites. Vulnerabilities are manually vetted by WordPress security professionals and the database is updated continuously.

What it's for

Scanning WordPress sites for known core, plugin, and theme vulnerabilitiesChecking WordPress installations for username enumeration risksDetecting weak passwords via password brute forcingFinding publicly accessible wp-config.php backupsFinding publicly accessible database dumpsDetecting exposed error logs from pluginsMedia file enumerationDetecting vulnerable Timthumb filesChecking if WP-Cron or user registration is enabledIntegrating vulnerability data into other products/services via APIReceiving instant email alerts on new vulnerabilities

Features 20

  • Command-line interface (CLI) security scanner
  • CVE Numbering Authority (CNA) for WordPress core, plugin, and theme vulnerabilities
  • CVSS Risk Scores (Enterprise)
  • Daily full vulnerability database dump (6am GMT)
  • Detection of exposed plugin error logs
  • Detection of publicly accessible database dumps
  • Detection of publicly accessible wp-config.php backups
  • Detection of vulnerable Timthumb files
  • Full path disclosure detection
  • Instant email vulnerability alerts (Enterprise)
  • Media file enumeration
  • Upload directory listing detection
  • User registration enabled detection
  • Username enumeration detection
  • Vulnerability lookup API
  • Weak password detection via brute forcing
  • Webhooks via Slack and HTTP (Enterprise)
  • WordPress core, plugin, and theme vulnerability database
  • WordPress readme file detection
  • WP-Cron enabled detection

At a glance

free tierself-hostableAPI
TypeCLI tool
DeploymentHybrid
PlatformsWeb
Forsecurity researchers, developers, enterprises, WordPress site owners

Integrations

Slack

Pricing

Enterprise pricing is quote-based, scaled by number of sites. Non-commercial use of the API is free up to 25 calls per day; commercial use requires a paid license. A separate free plugin, Jetpack Protect, uses WPScan data for small business site protection.

EnterpriseQuote

Contact for a price quote; WordPress protection with custom solutions for large enterprises.

Custom pricing by number of sites

ResearcherFree

For non-commercial use; the WPScan CLI Scanner is free to use for everyone, without the API.

Capped at 25 API calls per day

Last checked 5 days ago·