WPScan
The standard vulnerability scanner for WordPress sites.
What it does
WPScan enumerates your WordPress installation — core version, active themes and plugins, users, and exposed settings — and matches each against a dedicated database of known WordPress vulnerabilities.
What data you get
A report of your exact WordPress components and which of them have known vulnerabilities, plus exposures like enumerable usernames and accessible config or backup files.
Why it matters to your site
WordPress powers a huge share of the web and most of its risk comes from outdated plugins. This tells you precisely which of your plugins or themes are a known way in — the single most common cause of WordPress hacks.
More in this category
Other cms tools
Droopescan
Plugin-based scanner for Drupal, Silverstripe and more.
JoomScan
OWASP scanner dedicated to Joomla installations.
CMSScan
One dashboard for scanning WordPress, Joomla and Drupal.