wpscanteam/wpscan
WPScan WordPress security scanner. Written for security professionals and blog maintainers to test the security of their WordPress websites. Contact us via [email protected] observed · 2026-08-28
Health v2 · maintenance only
93/100
- Activity 98
- Release rhythm 82
- Longevity 100
Flags: no_license
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: 50
- age_days: 5166
- days_rel: 41
- days_push: 13
- n_releases_24m: 6
Adoption not part of the score
9740 stars · 1343 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded
WPScan is a black-box WordPress security scanner written in Ruby, used by security professionals and site maintainers to audit WordPress installations. It enumerates core, plugin, and theme versions and cross-references them against the WPScan vulnerability database of tens of thousands of vetted WordPress vulnerabilities.
Use cases
- scan a wordpress site for vulnerable plugins and themes
- enumerate wordpress usernames
- brute force weak wordpress passwords
- check wordpress core version for known vulnerabilities
- find exposed wp-config backups and database dumps
- pentest a wordpress website from the command line
When to choose
- you need a dedicated, actively maintained WordPress-specific security scanner
- you want vulnerability data from a manually vetted WordPress vulnerability database (API token required)
- you work in Kali Linux or other pentesting distributions where it is a standard tool
When to avoid
- you need a general-purpose web vulnerability scanner for non-WordPress sites
- you require heavy automated scanning without an API token (free tier is capped at 25 API calls/day)
- you need a GUI-based scanner rather than a CLI tool
Facets
cli-tool · maturity active
security vulnerability-scanning cli http-client security penetration-testing cms web-development developer-tools windows cli ruby wordpress wpscan vulnerability-database pentesting black-box-scanner wpvulndb kali-linux linux macos docker
4 sources
- readme: https://github.com/wpscanteam/wpscan · fetched 2026-08-28 · 794962856ff3
- homepage: https://wpscan.com/wordpress-cli-scanner · fetched 2026-08-29 · 3863df0781d0
- site_page: https://wpscan.com/features · fetched 2026-08-29 · e8ba26fe3aa2
- site_page: https://wpscan.com/pricing · fetched 2026-08-29 · 18b0a9d09bfa
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| wpscanteam/wpscan | main | 93 |
For agents
markdown · JSON · MCP: product_card(name="wpscanteam/wpscan")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem