toolcompass.

Find your next AI tool

Search by product name or task. Press Escape to close.

official WPScan

● Identity checked

Assistant · Vendor site 2026-10-04

WPScan is a WordPress vulnerability scanner and API backed by a catalog of core, plugin, and theme security issues. Security teams and researchers use the CLI scanner, vulnerability database, and commercial API alerts to monitor WordPress estates.

Updated 2026-10-04View sources
Official website
Category
Assistant
Free access
Researcher plan copy allows free non-commercial CLI and API use capped at 25 API calls per day.
API access
Site documents a vulnerability API with enterprise endpoints, webhooks, and CLI tooling for researchers.

Is official WPScan right for you?

A good fit for

WordPress maintainers, agencies, and researchers who need continuous vulnerability intelligence.

Before you choose

Enterprise pricing is quote-based by number of sites rather than a public monthly USD card price.

WordPress security intelligence

WPScan.com combines a maintained vulnerability database with scanning tools and API access so teams can detect issues affecting WordPress sites and plugins.

What it can do

Features & capabilities

Unknown is different from unavailable. Each fact carries its own evidence.

CapabilityValueEvidenceChecked
Vulnerability catalogHomepage states the database catalogs tens of thousands of WordPress core, plugin, and theme vulnerabilities.Facts sourced2026-10-04
Researcher tierPricing page offers researchers free CLI and API access with a 25 API calls per day cap.Facts sourced2026-10-04

Understand the total cost

official WPScan pricing & plans

Free

Free

Researcher plan copy allows free non-commercial CLI and API use capped at 25 API calls per day.

Access
Researcher plan copy allows free non-commercial CLI and API use capped at 25 API calls per day.
Explore pricing & history

Alternatives to official WPScan

View all ↗

The practical questions

Frequently asked questions

Where does the vulnerability data come from?

WPScan FAQ explains entries are manually verified by WordPress security professionals sourced from the community, researchers, and their own findings as a CVE Numbering Authority.

What is official WPScan used for?

WPScan is a WordPress vulnerability scanner and API backed by a catalog of core, plugin, and theme security issues. Security teams and researchers use the CLI scanner, vulnerability database, and commercial API alerts to monitor WordPress estates.

Does official WPScan have a free plan?

Researcher plan copy allows free non-commercial CLI and API use capped at 25 API calls per day.. This record lists ongoing free access; check the plan limits before starting.

How much does official WPScan cost?

No paid monthly price is listed; this record treats the product as free to start. See the plan cards for entitlements, billing commitments and seat minimums.

Can I use official WPScan through an API?

Site documents a vulnerability API with enterprise endpoints, webhooks, and CLI tooling for researchers.. API access and subscription access may have different terms; consult the linked sources.

What should I check before choosing it?

Enterprise pricing is quote-based by number of sites rather than a public monthly USD card price.

Price history

No retained pricing changes yet. A current price alone does not establish a historical trend.

How this profile is supported

Facts apply to the named version and check date. Send a sourced correction if something changed.