awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
wpscanteam avatar

wpscanteam/wpscan

0
View on GitHub↗
9,636 stars·1,338 forks·Ruby·34 viewswpscan.com/wordpress-cli-scanner↗

Wpscan

WPScan is a security analysis utility and vulnerability scanner designed specifically for auditing WordPress installations and other content management systems. It functions as a web application security tool that identifies misconfigurations, outdated software, and security holes in core installations, plugins, and themes.

The tool employs black-box scanning techniques to perform site component enumeration, identifying users, themes, and plugins by matching known file paths and response signatures. It matches these detected components against a database of known security flaws to analyze the total attack surface of a website.

The system supports vulnerability management through both local security database synchronization and remote API lookups using authentication tokens. Operational settings and target lists can be managed via JSON or YAML configuration files to automate scanning tasks.

Features

  • CMS Security Auditing - Scans WordPress installations to find security holes in the core software, plugins, and themes.
  • Web Security Analysis - Provides a comprehensive security analysis tool for identifying vulnerabilities in WordPress web installations.
  • Web Security Tools - Provides utilities for scanning and enumerating exposed users and sensitive data on web applications.
  • Vulnerability Management - Checks website components against databases of known security flaws to prioritize updates and patching.
  • Component Enumeration - Identifies installed plugins, themes, and users to locate potential entry points or exposed sensitive data.
  • Attack Surface Analysis - Maps the total attack surface by discovering installed plugins, themes, and user accounts.
  • Component Enumeration - Identifies plugins, themes, and users by matching known file paths and response signatures.
  • WordPress Security Scanning - Detects outdated software and security holes specifically within WordPress installations.
  • Vulnerability Matching - Matches detected plugins, themes, and core versions against a database of known security flaws.
  • Penetration Testing Suites - Provides a suite of tools for conducting black-box security assessments to identify potential entry points.
  • Black Box Scanning - Implements black-box scanning techniques to identify security holes via public HTTP responses.
  • Vulnerable Library Detectors - Matches detected WordPress plugins and themes against a database of known vulnerable versions.
  • Black Box Security Scanning - Analyzes public HTTP responses to identify site components and security weaknesses without requiring internal system access.
  • Security Maintenance - Regularly verifies that plugins and themes are secure and up to date for site owners.
  • Remote-to-Local Database Synchronizers - Maintains a local copy of vulnerability definitions synchronized from a remote source for offline checks.
  • Vulnerability Database Management - Synchronizes and maintains local copies of security metadata to ensure current vulnerability definitions.
  • Vulnerability Data Query Engines - Implements a query engine to match detected software versions against a remote vulnerability database.
  • Vulnerability Database APIs - Provides API-based lookups to a remote security database to identify flaws in detected plugins and themes.
  • Vulnerability Data Synchronization - Retrieves real-time security information from a remote database via API tokens to ensure scan accuracy.
  • Vulnerability Scanners - WordPress vulnerability scanner.
  • Web Application Scanners - Security scanner specifically for WordPress installations.
  • CMS Scanners - Dedicated security scanner for identifying vulnerabilities in WordPress installations.
  • CMS Vulnerability Scanning - Black-box security scanner for WordPress sites.
  • Security Tools - Black box WordPress vulnerability scanner
  • Vulnerability Auditing - Black-box vulnerability scanner specifically for WordPress sites.
  • Web Application Analysis - Black-box scanner specifically for WordPress security vulnerabilities.
  • Web Application Scanning - Specialized vulnerability scanner for WordPress sites.
  • Web Hacking - Black-box vulnerability scanner for WordPress installations.
  • Web Vulnerability Scanners - Black-box vulnerability scanner for WordPress sites.

Star history

Star history chart for wpscanteam/wpscanStar history chart for wpscanteam/wpscan

How this analysis was created: This summary and feature list are AI-generated from collected project material and can contain mistakes. Stars, license and language are imported from GitHub. Inclusion does not mean that we have tested or audited this project. Check the source documentation for any feature you depend on. Learn more on our About page.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Frequently asked questions

What does wpscanteam/wpscan do?

WPScan is a security analysis utility and vulnerability scanner designed specifically for auditing WordPress installations and other content management systems. It functions as a web application security tool that identifies misconfigurations, outdated software, and security holes in core installations, plugins, and themes.

What are the main features of wpscanteam/wpscan?

The main features of wpscanteam/wpscan are: CMS Security Auditing, Web Security Analysis, Web Security Tools, Vulnerability Management, Component Enumeration, Attack Surface Analysis, WordPress Security Scanning, Vulnerability Matching.

Which projects share features with wpscanteam/wpscan?

Projects with overlapping indexed features include: dependencytrack/dependency-track — Dependency-Track is a software composition analysis tool and vulnerability management system designed to track… google/osv.dev — OSV is a distributed database and aggregator of open-source security advisories that uses a standardized vulnerability… cve-search/cve-search — cve-search is a vulnerability search engine and database manager designed to index, synchronize, and query CVE and CPE… dionach/cmsmap — CMSmap is a python open source CMS scanner that automates the process of detecting security flaws of the most popular… sullo/nikto — Nikto is an open-source HTTP security auditing tool and web server vulnerability scanner. It functions as a… bitsadmin/wesng — This project is a set of specialized utilities for Windows vulnerability assessment and patch management auditing. It…

Projects sharing features with Wpscan

These projects share indexed features with Wpscan. Shared tags can include platform or build tooling; verify the primary use case before treating a result as a replacement.
  • dependencytrack/dependency-trackDependencyTrack avatar

    DependencyTrack/dependency-track

    3,612View on GitHub↗

    Dependency-Track is a software composition analysis tool and vulnerability management system designed to track dependencies and supply chain risk. It functions as a platform for ingesting and analyzing CycloneDX software bills of materials to identify known vulnerabilities and license compliance issues within third-party software components. The system distinguishes itself by mirroring external vulnerability databases locally to enable fast offline analysis and using VEX documents to differentiate between technical vulnerabilities and actual contextual risks. It also integrates with identity

    Javaappsecbill-of-materialsbom
    View on GitHub↗3,612
  • google/osv.devgoogle avatar

    google/osv.dev

    2,494View on GitHub↗

    OSV is a distributed database and aggregator of open-source security advisories that uses a standardized vulnerability schema to track security flaws. It functions as a system for collecting and normalizing security data from diverse ecosystems into a single unified format, providing a web API for querying package vulnerabilities and submitting standardized records. The project distinguishes itself through a security advisory distribution service that supports bulk dataset exports via cloud storage buckets and incremental synchronization of security record updates. It also employs sandbox-bas

    Pythonsecuritysecurity-toolsvulnerability
    View on GitHub↗2,494
  • cve-search/cve-searchcve-search avatar

    cve-search/cve-search

    2,593View on GitHub↗

    cve-search is a vulnerability search engine and database manager designed to index, synchronize, and query CVE and CPE security vulnerability data. It functions as a security data warehouse that imports vulnerability feeds into a local database to enable fast, keyword-based discovery of security flaws. The project provides a web-based vulnerability browser and a programmatic JSON API for retrieving records and risk scores. It utilizes full-text indexing for vulnerability descriptions and implements an identity-verified security portal using the OpenID Connect standard for user authentication.

    Pythoncommon-vulnerabilitiescpecve
    View on GitHub↗2,593
  • dionach/cmsmapDionach avatar

    Dionach/CMSmap

    1,166View on GitHub↗

    CMSmap is a python open source CMS scanner that automates the process of detecting security flaws of the most popular CMSs.

    Python
    View on GitHub↗1,166
Compare all 30 related projects→