wpscanteam/wpscan

WPScan WordPress security scanner. Written for security professionals and blog maintainers to test the security of their WordPress websites. Contact us via...

View on GitHub ↗Jump to charts ↓Open shareable report

Summary Information

Updated 10 minutes ago
Added to GitGenius on September 6th, 2026
Created on July 11th, 2012
Open Issues & Pull Requests: 0 (+0)
GitHub issues: Enabled
Number of forks: 1,343
Total Stargazers: 9,758 (+0)
Total Subscribers: 263 (+0)

Repository Insights (GitGenius)

Median issue/PR response: 16.2 days
Mean response time: 287.3 days
90th percentile: 739.6 days
Tracked items: 105

How this project is maintained

Around half of the issues opened in the past year never receive a reply. Only 4% of issues opened in the past year have been closed. Three people close 82% of everything that gets resolved.

Charts & Analytics

Fetching additional details & charts...

Issue Activity (beta)

Open issues: 0
New in 7 days: 0
Closed in 7 days: 0
Avg open age: N/A days
Stale 30+ days: 0
Stale 90+ days: 0

Recent activity

Opened in 7 days: 0
Closed in 7 days: 0
Comments in 7 days: 0
Events in 7 days: 0

Top labels

  • Feature request (26)
  • bug (7)
  • needs info (6)
  • priority: low (6)
  • enhancement (5)
  • needs triage (5)
  • needs documentation (3)
  • priority: high (3)

Most active issues this week

No issue events were indexed in the last 7 days.

Detailed Description

WPScan is a command-line security scanner that identifies vulnerabilities in WordPress installations.

The tool addresses the need to audit WordPress sites for security weaknesses before attackers exploit them. It scans for outdated plugins, themes, and WordPress core versions that contain known vulnerabilities, as well as misconfigurations and weak security practices. The scanner cross-references findings against a vulnerability database to report exploitable issues specific to the installed software versions.

Security professionals and WordPress site maintainers should use WPScan to validate their deployments before going live or as part of regular security audits. It suits any WordPress installation where understanding the security posture matters, from small blogs to larger sites. The tool is designed for hands-on security testing rather than passive monitoring, making it appropriate for penetration testers and site owners who want direct control over scanning parameters and timing.

The project maintains steady development activity with regular updates to its vulnerability detection capabilities. The codebase receives consistent refinement to improve scan accuracy and add detection for newly discovered WordPress security issues. Development includes ongoing maintenance of the underlying vulnerability database integration that powers the scanner's findings.