WPScan maintains the most established database of WordPress vulnerabilities, covering core, plugins, and themes. Its command-line scanner enumerates a WordPress installation (users, plugins, versions) and cross-references what it finds against that database to flag components with known CVEs.
If you represent WPScan, claiming is free and adds a Verified badge to this security profile. Start verification →
Beyond the CLI, WPScan offers an API and an official plugin so sites can be checked continuously and alert when an installed plugin or theme gains a newly disclosed vulnerability. Automattic acquired WPScan in 2021, giving it first-party standing in the WordPress ecosystem.
WPScan finds known vulnerabilities; it does not block attacks or remove malware. It complements a WAF and scanner: use WPScan to know what is vulnerable and needs updating, and a tool like Patchstack, Wordfence, or a server WAF to block exploitation in the meantime.
Category context: Plug-in or service that runs inside the WordPress install. Application-level protection; the user controls it directly.
Vulnerability database and virtual patching layer for WordPress.
Compare →The most-installed WordPress security plugin. Application-level WAF + malware scanner.
Compare →A long-running WordPress security plugin covering logins, hardening, and monitoring, formerly iThemes Security.
Compare →WPScan is a WordPress vulnerability database and scanner maintained by Automattic. Its command-line tool enumerates a WordPress site and checks the core, plugins, and themes against its vulnerability database to report known CVEs. It also offers an API and plugin for continuous monitoring.
The WPScan CLI and its use of the vulnerability database are free under a fair-use API allowance, which suits occasional scans and individual sites. Higher-volume and commercial use of the API moves to paid plans. The database itself is the reference source many other WordPress security tools build on.
WPScan tells you which installed components have known vulnerabilities so you can update them; Patchstack additionally ships virtual patches that block exploitation of those vulnerabilities before an official fix lands. WPScan is detection and intelligence; Patchstack adds active mitigation on top of similar intelligence.
HostList is independent. This profile is editorial; HostList accepts no sponsorship, affiliate commission, or paid placement from WPScan or any security vendor.