Back to Directory

WPScan

Web Testing

WordPress security scanner to find vulnerabilities and misconfigurations.

Customize the parameters below to generate your target command. Use the preview box to verify syntax and click the clipboard icon to copy.

Configure Options

The URL of the WordPress site to scan.

Required for vulnerability database lookups.

Generated Command

bash - CommandsLab
$ wpscan --url "http://target.com" --enumerate vp,vt

Command Breakdown

  • Tool:WPScan — WordPress security scanner to find vulnerabilities and misconfigurations.
  • Enumerate:vp,vt

About this tool

WPScan is a free, for non-commercial use, black box WordPress security scanner written for security professionals and blog maintainers to test the security of their sites.

Pro Tip: Focus on understanding the core options first. You can use the generated command directly in your terminal, and view the Command Breakdown above to see what each flag does.