← All website monitoring tools
WPScan
WordPress-specific vulnerability database + scanner — free CLI with optional API key.
Free tier: free CLI, free API tier limited daily requests
What it does well
- Maintains the most comprehensive, up-to-date database of WordPress core, plugin, and theme vulnerabilities.
- A free, open-source command-line tool allows for easy automation and scripting.
- Generous free API tier provides vulnerability data for personal or small-scale use.
Where it falls short
- Strictly a command-line tool; no official graphical user interface is provided.
- Only scans WordPress sites, offering no support for other CMS or custom applications.
- Requires self-hosting and manual execution; it is not a managed, continuous monitoring service.
Alternatives to WPScan
OWASP ZAP
freeMost popular free open-source DAST scanner — active/passive web scanning, intercepting proxy, CI/CD integration.
Greenbone / OpenVAS
freemiumOpen-source vulnerability scanner descended from Nessus — free Community Edition, paid appliances for enterprise.
Template-driven fast scanner — community templates cover thousands of CVEs. Free CLI, paid managed cloud.
Nikto
freeLong-running open-source web server scanner — checks 6,700+ dangerous files and outdated software.