WPScan – WordPress Security Scanner icon

WPScan – WordPress Security Scanner

by ethicalhack3r

View on WordPress.org
73 Quality Score
Active Installs
17/30

Roughly 8,000 active installs places this in niche territory, well below mainstream security plugins but enough to indicate a loyal technical audience.

Update Freshness
22/25

Updated within the past month and tested against WordPress 6.9.4, the maintenance signals are strong and current.

User Rating
11/15

A 76 out of 100 from 28 raters suggests users find it useful but not exceptional, and the small sample size limits confidence.

Support Health
8/15

Zero support threads opened or resolved is unusual and could mean either no issues exist or that users are not engaging with the developer through WordPress.org.

WP Compatibility
15/15

Tested on the latest WordPress release with a PHP 5.5 minimum, the compatibility score is near perfect and broadly accommodating.

Scores higher than 30% of indexed plugins

About

WPScan WordPress Security Scanner - Scans your system for security vulnerabilities listed in the WPScan Vulnerability Database.

Active Installs 8k+
Rating ★★★½ 3.8/5
Last Updated 2026-01-12 1:09pm GMT
Requires WordPress 3.4+
Tested Up To 6.9.7
Requires PHP 5.5+
✓ No known vulnerabilities

What It Does

WPScan connects your WordPress site to the WPScan Vulnerability Database, scanning your installed plugins, themes, and core for known security issues. It pulls from a curated repository of WordPress-specific vulnerabilities and flags components that need updating or removal. The plugin focuses on detection rather than remediation, so it tells you what is at risk but does not patch or quarantine anything.

Who It's For

This plugin suits site owners, developers, and agencies who want a focused vulnerability check that taps into a dedicated WordPress CVE database, especially those already using WPScan tooling elsewhere. It works well for compliance-focused businesses and multi-site managers who need to document known vulnerabilities across client installations. Anyone comfortable interpreting security scan results without hand-holding will get the most out of it.

Who Should Skip It

If you want an all-in-one firewall, malware cleaner, and login protection in a single package, skip this and choose Wordfence or Really Simple Security. Casual bloggers and small hobby sites without compliance needs will likely never act on the scan output.

The Bottom Line

WPScan delivers a focused, database-backed vulnerability scan and nothing more, which is its biggest strength and limitation. With an overall quality score of 76.22 out of 100 and a tiny but active install base, it is best viewed as a specialist tool for users who already trust the WPScan ecosystem. Anyone wanting a full security stack will be better served by Wordfence or Really Simple Security.

Tags

hack security vulnerability wpscan wpvulndb