WPScan: WordPress Vulnerability Scanner

WPScan is a free, for non-commercial use, black box WordPress security scanner. It is primarily used by security professionals and WordPress site owners to identify security weaknesses in WordPress installations, including:

  • Vulnerabilities in WordPress core, plugins, and themes.
  • Weak passwords for user accounts.
  • Misconfigurations.
  • Enumeration of users, plugins, themes, and more.

WPScan API Token

While WPScan can run basic scans without an API token, registering for a free API token (for non-commercial use) significantly enhances its capabilities by providing access to a larger and more up-to-date vulnerability database.

  1. Register: Go to the official WPScan website (wpscan.com) and register for a free account.
  2. Get Token: After registration, you will find your API token in your account dashboard.

Basic Usage: Scanning a WordPress Site

Once you have your API token, you can run a comprehensive scan against a target WordPress website.

wpscan --url <target-wordpress-url> --api-token <YOUR_API_TOKEN>
# Example:
wpscan --url https://www.example.com --api-token <WP_SCAN_API_TOKEN>

Command Breakdown:

  • wpscan: Invokes the WPScan tool.
  • --url <target-wordpress-url>: Specifies the URL of the WordPress site you want to scan.
  • --api-token <YOUR_API_TOKEN>: Provides your personal API token for enhanced vulnerability detection.

Other Useful WPScan Options

  • --enumerate u: Enumerate users (can take a long time).
  • --enumerate vp: Enumerate vulnerable plugins.
  • --enumerate vt: Enumerate vulnerable themes.
  • --password-attack wp-login --passwords <wordlist>: Perform a password attack against wp-login.php using a wordlist.
  • --update: Update the WPScan vulnerability database.
  • --proxy <protocol>://[user:pass@]host:port: Use a proxy for the scan.
  • -o <filename>: Output results to a file.

Disclaimer: WPScan is a powerful security tool. Its use should be restricted to legal and ethical purposes, such as authorized penetration testing, security auditing of your own WordPress sites, or academic research with proper consent. Unauthorized scanning of websites is illegal and unethical.