Skip to content
hackingtools.ai
WPScan

WPScan

WPScan is a freemium WordPress security scanner with a free CLI for authorised assessments, plus paid API plans for commercial vulnerability intelligence.

0

0 upvotes · 0 downvotes

No ratings yet

Pricing
Freemium
Platforms
LinuxWindowsmacOS
Reviewed
Last reviewed 2 October 2026

What it is

WPScan is a WordPress vulnerability scanner from the WPScan team (wpscan.com, GitHub wpscanteam/wpscan). In authorised web assessments and Hack The Box Academy WordPress and bug-bounty style modules, the free CLI enumerates themes, plugins and users, while optional API data enriches known vulnerability matching.

What it helps with

- Enumerating WordPress core, themes and plugins on authorised targets.
- Checking for known issues when an API key and plan allow vulnerability lookups.
- Supporting HTB Academy and lab modules that teach WordPress attack surface mapping.
- Producing structured findings for further manual verification in scoped tests.
- Running the CLI freely for non-commercial use under the project licence.
- Upgrading to paid API tiers when commercial teams need higher volume intelligence.

Who it's for

Web penetration testers and HTB Academy students who need a dedicated WordPress scanner as a peer to general web tools such as Nikto, Burp and Nuclei, on authorised targets only.

Worth knowing

The WPScan CLI is free to use; the vulnerability API is freemium (limited non-commercial calls, paid commercial licences). Official site: wpscan.com. Confirm current API and commercial licence terms on wpscan.com/pricing. Authorised testing only.

Discussion & reviews

0 comments

Your rating (optional)

0/4,000

No contributions yet. Be the first to review or comment.

← Back to directory