WordPress vulnerability scanner

Check your plugins, themes and core against the WPScan and Patchstack vulnerability databases, using your own API key, with resumable scans and a full scan history.

Requires a free or paid API key from WPScan or Patchstack. Email notifications of scan results are Pro.

2
databases supported: WPScan and Patchstack
Resumable
scans run in batches and pick up where they left off
History
every scan stored, so you can see what changed
Masked
API keys are never echoed back once saved

What it does

Most compromised WordPress sites fall to a known vulnerability in an outdated plugin or theme: a hole that was public before the attack. The scanner cross-references everything you run against professionally maintained vulnerability databases so you hear about the hole before an attacker uses it.

How it works

Add an API key from WPScan or Patchstack (both offer free tiers) and run a scan. The plugin prefers WPScan when both keys are configured and falls back to Patchstack. Scans run in batches with saved state, so a large site can finish a scan across multiple runs instead of timing out.

Results land in a scan history you can revisit, and a separate free module verifies WordPress core files against the official WordPress.org checksums to catch tampering.

  • Plugins, themes and core checked against WPScan or Patchstack
  • Your own API key, with free tiers from both providers
  • Batched, resumable scan execution
  • Stored scan history
  • Core file-integrity check against WordPress.org checksums (separate free module)

Free today, deeper with Pro

The scanner itself is free. Pro adds email notification of scan results, plus the continuous file monitoring and AI malware scanning that catch what a database lookup cannot: novel or targeted malicious code.

Documentation

Scanner dashboard

Run scans and read results.

Read the guide →

API key setup

Configure WPScan or Patchstack.

Read the guide →

Scan history

Review past scans and changes.

Read the guide →

File integrity

Core checksum verification.

Read the guide →

Vulnerability scanner questions

Do I need an API key?

Yes. The scanner queries WPScan or Patchstack with your own key. Both providers offer free tiers suitable for a single site.

Which provider should I pick?

Either works. If both keys are configured the plugin prefers WPScan and uses Patchstack as the fallback.

Does it detect malware too?

This module finds known vulnerabilities in the software you run. Detecting injected malicious code is the job of the Pro file monitoring and AI malware scanner.

Related features

Free

Core file-integrity scan

WordPress core verified against official checksums.

Learn more →
Pro

AI malware scanner

Suspicious files analyzed by an AI provider you choose.

Learn more →
Pro

Continuous file monitoring

Baseline monitored files and get alerted when one changes.

Learn more →

All features →

Secure your site today

Install the free plugin from WordPress.org and set up real protection with the guided setup wizard. Upgrade to Pro whenever you need more.