Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. Web Security
  3. wpscan

wpscan

NOASSERTIONRubyv4.1.0

A free, open-source WordPress security scanner for professionals and site maintainers to test website vulnerabilities.

Visit WebsiteGitHubGitHub
9.7k stars1.3k forks0 contributors

What is wpscan?

WPScan is a free, open-source security scanner specifically designed for WordPress websites. It helps identify vulnerabilities in WordPress core, plugins, and themes by checking against an updated vulnerability database. The tool is used to perform security assessments, enumerate users, and detect misconfigurations that could be exploited.

Target Audience

Security professionals, penetration testers, and WordPress site maintainers who need to assess and improve the security posture of WordPress installations.

Value Proposition

Developers and security teams choose WPScan because it is a dedicated, command-line tool that provides accurate, up-to-date vulnerability data through its API, supports stealthy scanning, and can be easily integrated into automated workflows via Docker or configuration files.

Overview

WPScan WordPress security scanner. Written for security professionals and blog maintainers to test the security of their WordPress websites. Contact us via contact@wpscan.com

Use Cases

Best For

  • Performing security audits on WordPress websites
  • Identifying vulnerable plugins and themes in WordPress installations
  • Enumerating WordPress usernames for penetration testing
  • Checking for exposed WordPress configuration backup files
  • Integrating WordPress vulnerability scanning into CI/CD pipelines
  • Conducting stealthy security assessments to avoid detection

Not Ideal For

  • Enterprises requiring continuous, automated vulnerability monitoring across hundreds of sites without API rate limits
  • Non-technical users or teams that prefer graphical user interfaces over command-line tools
  • Projects focused on non-WordPress content management systems or custom web applications

Pros & Cons

Pros

WordPress-Specific Accuracy

Leverages the dedicated WPScan Vulnerability Database for precise checks on core, plugins, and themes, ensuring relevance to WordPress ecosystems as stated in the README.

Stealth and Configuration Flexibility

Offers stealth scanning options to avoid detection and supports config files for easy setup and repeatable scans, detailed in the usage section.

Docker and API Integration

Can be run via Docker for isolation and integrates with an API for real-time data, though with a free tier limit of 25 requests per day, as mentioned in the API documentation.

Cons

API Request Limitations

The free API tier allows only 25 requests daily, which can be exhausted quickly when scanning sites with many plugins or themes, limiting real-time data access without payment.

Ruby Dependency and Setup Complexity

Requires Ruby >= 3.0 and specific curl versions, which can complicate installation compared to standalone binaries, especially on non-Linux systems, as noted in the prerequisites.

No GUI for Easier Use

Being command-line only, it lacks a graphical interface, making it less accessible for users unfamiliar with terminal commands or automated workflows.

Frequently Asked Questions

Quick Stats

Stars9,699
Forks1,343
Contributors0
Open Issues0
Last commit17 hours ago
CreatedSince 2012

Tags

#vulnerability-assessment#web-security#ruby-gem#penetration-testing#cli-tool#scan#security#docker#hacking-tool#scanner#wordpress#security-scanner#api-integration

Built With

c
curl
R
RubyGems
R
Ruby
N
Nokogiri
D
Docker

Links & Resources

Website

Included in

Web Security13.2k
Auto-fetched 4 hours ago

Related Projects

NucleiNuclei

Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.

Stars29,958
Forks3,633
Last commit14 hours ago
JoomlaScanJoomlaScan

A free software to find the components installed in Joomla CMS, built out of the ashes of Joomscan.

Stars260
Forks72
Last commit3 years ago
Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub