Tool and Usage
WPScan is a security tool to perform black box WordPress vulnerability scans, including enumeration of used plugins
Why this tool?
WPScan can scan WordPress installations and determine if there are vulnerabilities in a particular installation.
While the code is available and the tool can be freely used, there are limitations when using this software commercially. The tool does not have to be installed, as it can also be used as part of a Docker image.
Usage and audience
WPScan is commonly used during penetration test, security assessment, or vulnerability scanning. Target users for this tool are pentesters, security professionals, and system administrators.
- + More than 25 contributors
- + More than 2000 GitHub stars
- + The source code of this software is available
- - Software usage is restricted (e.g. commercially)
Author and Maintainers
Support operating systems
WPScan is known to work on Linux.
Several alternative tools are available for WPScan that might be a good replacement.
Vane is a forked project of the now non-free popular WordPress vulnerability scanner WPScan.
WPSeku is a WordPress vulnerability scanner that can be used to scan remote WordPress installations.
|Latest release||2.9.3 [2017-07-19]|
|Last updated||Sept. 17, 2017|
|WPScan GitHub project page|
|WPScan project website|
|WPScan vulnerability database|