WPScan
WordPress Security Scanner·wpscan.com
WPScan is an enterprise vulnerability database and scanning service for WordPress, cataloging vulnerabilities in WordPress core, plugins, and themes. It offers a command-line security scanner, a versatile API, and integrations for detecting vulnerabilities and common security misconfigurations on WordPress sites. Vulnerabilities are manually vetted by WordPress security professionals and the database is updated continuously.
What it's for
Features 20
- Command-line interface (CLI) security scanner
- CVE Numbering Authority (CNA) for WordPress core, plugin, and theme vulnerabilities
- CVSS Risk Scores (Enterprise)
- Daily full vulnerability database dump (6am GMT)
- Detection of exposed plugin error logs
- Detection of publicly accessible database dumps
- Detection of publicly accessible wp-config.php backups
- Detection of vulnerable Timthumb files
- Full path disclosure detection
- Instant email vulnerability alerts (Enterprise)
- Media file enumeration
- Upload directory listing detection
- User registration enabled detection
- Username enumeration detection
- Vulnerability lookup API
- Weak password detection via brute forcing
- Webhooks via Slack and HTTP (Enterprise)
- WordPress core, plugin, and theme vulnerability database
- WordPress readme file detection
- WP-Cron enabled detection
At a glance
Integrations
Pricing
Enterprise pricing is quote-based, scaled by number of sites. Non-commercial use of the API is free up to 25 calls per day; commercial use requires a paid license. A separate free plugin, Jetpack Protect, uses WPScan data for small business site protection.
Contact for a price quote; WordPress protection with custom solutions for large enterprises.
Custom pricing by number of sites
For non-commercial use; the WPScan CLI Scanner is free to use for everyone, without the API.
Capped at 25 API calls per day