Tools like WordPresscan are useful to perform vulnerability scans on the popular WordPress platform. It can be used during development and on existing installations.

Wordpresscan is commonly used for application security, penetration testing, or web application analysis. Target users for this tool are developers, pentesters, security professionals, and system administrators.

  • + The source code of this software is available


Wordpresscan is known to work on Linux.


Several dependencies are required to use Wordpresscan.

  • requests
  • tornado

WordPress Exploit Framework

The WordPress Exploit Framework (WPXF) is a framework written in Ruby. As the name implies, it aids in pentesting WordPress installations.



Vane is a forked project of the now non-free popular WordPress vulnerability scanner WPScan.



Wordstress is a security scanner for WordPress installations. It uses a white-box approach in scanning, which makes it different than most other scanners.

