Be the first to know about new WordPress vulnerabilities

  • CheckmarkAll vulnerabilities are manually entered into our database by dedicated WordPress security professionals.
  • CheckmarkWe work with security researchers, vendors, and WordPress to triage vulnerabilities.
  • CheckmarkOur vulnerability database is updated constantly as new information becomes available.
WPScan vulnerability database example
127Vulnerabilities added in May
28,701Total vulnerabilities in our database

Install the WordPress plugin to get started

Our WordPress security services

WordPress Logo

Free WordPress plugin

Get daily vulnerability scans, email reports, and report downloads with the WordPress plugin.

Get it now
Vector icon

CLI security scanner

Get the hackers’ point of view with a command line interface written for security professionals.

Get details
Vector icon

Versatile API

Tap directly into the vulnerability database API to get the latest WordPress vulnerabilities.

Get details

For Enterprise & Small Businesses

Enterprise

  • Custom API requests per day*
  • Instant email alerts
  • Vulnerabilities details by ID
  • Latest API endpoints
  • Webhooks: Slack & HTTP
  • Description & PoC API data
  • CVSS Risk Scores

Business

For most sites, we recommend Jetpack Scan — the partner product of WPScan, by Automattic. It has all the power of WPScan with an easy-to-use interface.
  • Automated daily scanning
  • One-click fixes for most issues
  • Instant email notifications
  • Priority support

Researchers can use the CLI tool to make 75 API requests per day. Get started

*WPScan makes one API request for the WordPress version, one request per installed plugin, and one request per installed theme. Add these to calculate API requests of your site. View all FAQ

Trusted by enterprise & small businesses

Kinsta
Go Daddy
Sonyo
Daimler
Accenture

A tiny plugin that timely reports vulnerable themes and plugins installed on your website. Effective and very easy to use - must have!

Exmi

Very helpful! It saves hours of work, and still it's pretty simple to use

Kenny Moore