It’s like having your own team of WordPress security experts
Be the first to know about vulnerabilities affecting your WordPress installation, plugins, and themes.
Check your WordPress site for vulnerabilities
Scan your site and get a free, instant report of your site safety.
Trusted by the world’s largest brands




Cataloging 64,362 WordPress core, plugin, and theme vulnerabilities
The WPScan database is continuously updated by leading WordPress security professionals.
Security solutions for everyone
Enterprise
WordPress protection with custom solutions for large enterprises.
- Custom pricing by number of sites
- Instant email alerts
- Vulnerabilities details by ID
- Latest API endpoints
- Webhooks: Slack & HTTP
- Description & PoC API data
- CVSS Risk Scores
Researcher
Security researchers are welcome to use the CLI scanner and API for non‑commercial purposes.
- CLI tools for researchers
- Capped at 25 API calls per day
Need a small business plan?
Jetpack Protect is a free plugin that uses WPScan data to alert you about threats to your website. Upgrade for WAF and one‑click fixes.

Formed in 2009, the Archive Team (not to be confused with the archive.org Archive-It Team) is a rogue archivist collective dedicated to saving copies of rapidly dying or deleted websites for the sake of history and digital heritage. The group is 100% composed of volunteers and interested parties, and has expanded into a large amount of related projects for saving online and digital history.





