WordPress Vulnerability Scanner for Plugins, Themes, and Core.

ScanTitan is a WordPress vulnerability scanner that fingerprints your core, every plugin, and every theme, then matches each version against the WPScan database and 100,000+ CVEs, with proof-based HTTP evidence for every finding and authenticated depth most free scanners miss.

ScanTitan - WordPress scan
Scanning…
Target: https://example-blog.com · WordPress 6.4.2
CRITICAL
Revolution Slider 4.1.4 - Arbitrary File Download
CVE-2014-9734 · CVSS 8.1 · Public exploit · reads wp-config.php
HIGH
WooCommerce 7.0.0 - SQL Injection
CVE-2023-28121 · CVSS 8.6 · Patch: update to 7.0.1
MEDIUM
Exposed wp-config.php.bak in web root
Database credentials readable · CVSS 5.3

100,000+ CVEs matched · CVSS 3.1 scoring

WPScan database: 75,000+ cataloged WordPress vulnerabilities

56% of WordPress hacks start with a vulnerable plugin

A WordPress vulnerability scanner that shows its work

WordPress vulnerability scanner is an automated tool that inspects a WordPress site for known security weaknesses in its core, plugins, and themes. It fingerprints the exact version of each component, then matches those versions against a database like WPScan and the wider CVE feeds to report which ones carry known, exploitable flaws.

A version check tells you a plugin is outdated. ScanTitan tells you the CVE, the CVSS score, the HTTP evidence that confirms it, and the exact version that fixes it, so your team spends time patching, not guessing.

Whether you run one blog, a WooCommerce store, or a portfolio of client sites, ScanTitan gives you attacker-level enumeration plus authenticated depth, and it flags risky plugins even when no CVE has been published yet.

of all websites run WordPress, the #1 attack target (W3Techs)
0 %
of WordPress compromises start with a vulnerable plugin
0 %
CVEs matched against the WPScan vulnerability database
0 K+
to your first findings, no plugin install required
< min

How to scan WordPress for vulnerabilities

Six stages, from fingerprinting the core to a verified fix. ScanTitan enumerates like an attacker, then goes deeper with authenticated access your attacker does not have.
Fingerprint the WordPress core

ScanTitan identifies the exact core version from the generator meta tag, readme.txt stable tag, static file paths under wp-includes, and the WordPress.org API, cross-checking multiple signals for accuracy.

Enumerate plugins and themes

The scanner detects every installed plugin and theme with its exact version by analyzing wp-content paths, CSS and JavaScript fingerprints, and stylesheet headers, including inactive components most scanners skip.

Match against WPScan + CVEs

Each detected version is matched against the WPScan vulnerability database and 100,000+ CVEs, so an outdated component becomes a named CVE with a CVSS 3.1 score and the release that fixes it.

Check exposed files and users

ScanTitan looks for the leaks an attacker grabs first: readable wp-config.php backups, database dumps, directory listing, and enumerable usernames that feed brute-force attacks.

Validate with HTTP evidence

Every finding ships with the exact request and response that confirmed it, so nothing reaches your dashboard as an unproven guess and no client can dispute it.

Prioritize and remediate

Findings are ranked by CVSS and real-world exploitability, each with a plain-language fix and a one-click re-scan that verifies the vulnerability is closed.

Real result (placeholder), A 12-site agency ran ScanTitan across its whole portfolio and found three sites running a Revolution Slider build with a public arbitrary-file-download exploit. All three were patched the same afternoon, before a single site was compromised.

Passive from the outside, authenticated for depth

Most free WordPress scanners run one way: unauthenticated, seeing only what a logged-out visitor sees. That is a useful attacker’s-eye view, but it misses everything behind the login. ScanTitan runs both, so you choose the depth.

Passive scan fingerprints core, plugins, and themes from public signals with low impact, safe on production and ideal for a fast portfolio sweep. Authenticated scan logs in and reaches the admin surface: inactive plugins, admin-only pages, and configuration a logged-out visitor never sees, exactly what a compromised-credential attacker would reach.

 

No noise, Aggressive enumeration can send thousands of requests, so ScanTitan rate-limits deep scans and schedules them off-peak. You get attacker-level depth without tripping your own intrusion prevention.

Fix it, verify it, close it

Every finding ships with a plain-language fix tailored to the component: the exact plugin version to update to, the config to change, or the file to remove. Not a generic CVE link, a specific next step.

After you apply the fix, trigger a one-click re-scan. ScanTitan confirms the vulnerable version is gone and attaches a clean-scan record to the issue, which doubles as audit and client evidence that the problem was found and fixed. 

Clean stays clean, Scheduled scanning re-checks every component against the latest WPScan data, so the day a new plugin CVE drops, the sites running it get flagged automatically, not at your next manual review.

Why WordPress is the internet's most attacked CMS

WordPress core is hardened and patched fast. The third-party plugins and themes bolted on top are where the exposure lives, and that is exactly where attackers look. A scanner that only checks core misses more than half of how sites actually get breached.
How WordPress sites get hacked Share of compromises What ScanTitan checks
Vulnerable plugins 56% Every plugin version matched to WPScan + CVEs
Brute force attacks 16% Exposed usernames and weak login surface
Theme vulnerabilities 12% Active and inactive theme versions and CVEs
WordPress core vulnerabilities 9% Exact core version and applicable core CVEs
Server misconfiguration 7% Exposed config backups, dumps, directory listing
← اسحب يمين / شمال لمشاهدة باقي الجدول →

Eight scanning capabilities. One platform.

Not a bundle of open-source tools duct-taped together. A single, integrated scanning engine — with a proprietary DAST layer, ML accuracy, and unified reporting.

WordPress Core Detection

Exact core version from the generator tag, readme.txt, wp-includes paths, and the WordPress.org API, cross-checked and matched to core CVEs with CVSS scores.

Plugin Vulnerabilities

Every plugin and version enumerated and matched to WPScan and CVEs, covering WooCommerce, Elementor, Yoast SEO, Contact Form 7, ACF, Jetpack, and thousands more.

Theme Vulnerabilities

Active and inactive themes detected from stylesheet headers and file paths, with each version matched to known theme CVEs and the patch that resolves it.

Abandoned Plugin Risk Score

Flags plugins and themes with no published CVE but no updates in years or removed from the directory. An unmaintained component is a latent exposure, scored as elevated risk.

Exposed Files & Config Backups

Detects readable wp-config.php backups, database dumps, leftover installer files, and directory listing on wp-content paths, each with the URL and HTTP response that proves it.

User Enumeration & Brute-Force Surface

Finds publicly enumerable usernames that feed the brute-force attacks behind 16% of WordPress compromises, so you can close the login surface before it is sprayed.

WPScan Database + CVE Intelligence

Every detected version matched against the WPScan database, the most authoritative WordPress vulnerability catalog, plus the wider CVE and NVD feeds, updated continuously.

Multi-Signal Detection

Multiple independent detection methods, generator tag, static file analysis, path-based checks, WordPress.org API, and readme.txt parsing, for high version accuracy.

Proof-Based Evidence

Every finding includes the HTTP request and response that confirmed it. No probability guesses, so you or your client can act and verify without second-guessing.

WordPress Core Detection

Exact core version from the generator tag, readme.txt, wp-includes paths, and the WordPress.org API, cross-checked and matched to core CVEs with CVSS scores.

Plugin Vulnerabilities

Every plugin and version enumerated and matched to WPScan and CVEs, covering WooCommerce, Elementor, Yoast SEO, Contact Form 7, ACF, Jetpack, and thousands more.

Theme Vulnerabilities

Active and inactive themes detected from stylesheet headers and file paths, with each version matched to known theme CVEs and the patch that resolves it.

Exposed Files & Config Backups

Detects readable wp-config.php backups, database dumps, leftover installer files, and directory listing on wp-content paths, each with the URL and HTTP response that proves it.

User Enumeration & Brute-Force Surface

Finds publicly enumerable usernames that feed the brute-force attacks behind 16% of WordPress compromises, so you can close the login surface before it is sprayed.

Abandoned Plugin Risk Score

Flags plugins and themes with no published CVE but no updates in years or removed from the directory. An unmaintained component is a latent exposure, scored as elevated risk.

WPScan Database + CVE Intelligence

Every detected version matched against the WPScan database, the most authoritative WordPress vulnerability catalog, plus the wider CVE and NVD feeds, updated continuously.

Multi-Signal Detection

Multiple independent detection methods, generator tag, static file analysis, path-based checks, WordPress.org API, and readme.txt parsing, for high version accuracy.

Proof-Based Evidence

Every finding includes the HTTP request and response that confirmed it. No probability guesses, so you or your client can act and verify without second-guessing.

Vulnerability scanning vs malware scanning

different questions, and you need both answered
0

A WordPress vulnerability scanner finds weaknesses before they are exploited: outdated plugins, unpatched core, exposed config, the open doors. It is proactive and prevents the compromise.

A malware scanner finds the damage after a breach: injected backdoors, SEO spam, redirect scripts, the intruder already inside. It is reactive and cleans up after one. Running only a malware scanner is like checking for burglars without ever locking the door.

Vulnerability scanning (this page)

Proactive. Finds exploitable plugins, themes, core, and exposed files so you can close them before an attacker gets in.

Malware scanning (pairs with)

Reactive. Detects backdoors, SEO spam, and redirects on an already-compromised site. See ScanTitan malware removal.

You need both layers

Vulnerability scanning locks the doors; malware scanning cleans up if someone got in. ScanTitan covers both under one roof.

What a ScanTitan WordPress scan report looks like

Built for two readers at once: the developer who fixes the issue and the owner who needs to understand the risk. Exportable as PDF, JSON, and HTML.
Full component inventory

WordPress core, every plugin, and every theme with its exact version and vulnerable status.

Per-finding CVE detail

CVE ID, CVSS 3.1 score, exploit availability, and the exact version that patches it.

HTTP evidence panel

Request sent and response received for each finding. Fully reproducible, dispute-proof.

Abandoned component flags

Unmaintained or removed plugins and themes scored as elevated risk even with no CVE.

Plain-language remediation

A specific fix per finding, followed by a one-click re-scan that verifies it is closed.

White-label client export

Agency-ready reports that show what was found, what was fixed, and when.

🛡
WordPress Scan - example-blog.com
1 Critical 2 High 4 Medium
Revolution Slider - Arbitrary File Download
CVSS 8.1
GET /wp-admin/admin-ajax.php?action=revslider_show_image&img=../wp-con...
GET /wp-admin/admin-ajax.php
action=revslider_show_image&img=../wp-config.php
HTTP/1.1 200 OK ← wp-config.php contents returned
WooCommerce 7.0.0 - SQL Injection
CVSS 8.6
Plugin: woocommerce · version 7.0.0 · CVE-2023-28121
Detected version: 7.0.0 (vulnerable)
Fix: update to 7.0.1 or later

Scan a whole portfolio, not one site at a time

If you manage 10, 50, or 500 WordPress sites, ScanTitan watches every property from one dashboard. Trigger scans from the API, schedule them across all sites, and alert the right person the moment a site turns vulnerable.
bash - Scan a WordPress site via API
# Scan a WordPress site, authenticated deep scan curl -X POST https://api.scantitan.com/v1/wp-scans \ -H "Authorization: Bearer YOUR_API_KEY" \ -H "Content-Type: application/json" \ -d '{ "target": "https://client-blog.com", "scan_type": "authenticated", "notify": ["slack","email"] }' # Response { "scan_id": "wp_4a8c2f", "status": "queued", "plugins_found": 24 }
yaml - Scheduled portfolio scan
- schedule: weekly targets: all_sites alert_on: new_cve,critical,high report: white_label_pdf

Built for portfolio scale

One dashboard for every client site. Findings flow into the tools you already use, and white-label reports turn your security work into a visible deliverable.

Portfolio view

All sites, one screen

Scheduled scans

Daily / weekly / monthly

Slack

Instant vuln alerts

Email

Clean-to-vulnerable alerts

Jira

Auto-create tickets

White-label PDF

Client-ready reports

WP plugin

Authenticated access

Webhooks

Any tool via JSON

REST API

Trigger + pull results

What teams achieve with ScanTitan

Real outcomes from real scans. Numbers are placeholders, replace with verified client data before publishing.

Latest WordPress scanner updates

ScanTitan ships detection and database improvements on a rolling basis. This page is updated every 90 days.

July 2026

Abandoned plugin risk scoring

ScanTitan now scores plugins and themes with no published CVE but no updates in years, or removed from the WordPress.org directory, as elevated risk, so you can replace latent exposures before a CVE exists.

May 2026

Authenticated scan for inactive plugins

Authenticated scans now enumerate installed-but-inactive plugins and themes, catching vulnerable components that a logged-out scan never sees.

March 2026

WPScan database sync

Continuous synchronization with the WPScan vulnerability database means a plugin gets re-flagged the day a new CVE is published, and your scheduled scan catches it automatically.

January 2026

Multi-site portfolio dashboard

Agencies can now scan and monitor an entire portfolio from one dashboard, with white-label PDF reports and per-site alerting on new vulnerabilities.

ScanTitan vs WPScan, Pentest-Tools, WPSec, and HackerTarget

All five are credible WordPress scanners, and most build on the WPScan database. The difference is depth, evidence, and who the tool is built for.
ScanTitan WPScan Pentest-Tools WPSec HackerTarget
Core, plugin, theme CVE detection
Authenticated scanning CLI Partial Partial
Proof-based HTTP evidence
Risk score for plugins with no CVE
Plain-language fix + re-scan Partial Partial
Multi-site / agency dashboard Enterprise Partial
Vulnerability + malware in one platform
Entry point Free scan Free DB / API 7-day trial Free basic Free basic
Swipe to see all columns

What WordPress teams say

4.8

G2 · placeholder

4.9

Capterra · placeholder

"We run 40 client WordPress sites. ScanTitan flagged a critical plugin CVE across three of them the day it was disclosed. The white-label reports are now part of every client's monthly care plan."

Liam P. Founder · WordPress agency

"Every finding comes with the HTTP request and the exact patch version. No more guessing whether a plugin flag is real. The authenticated scan found an inactive plugin our old scanner never saw."

Maria R. Lead Developer · WooCommerce store

"I am not a security expert, and I did not need to be. It told me exactly which plugin to update and confirmed the fix with a re-scan. Five minutes, done."

Jon T. Owner · small business blog

Common questions about WordPress Vulnerability Scanner

Answered by our security team — not by a chatbot.
A WordPress vulnerability scanner is an automated tool that inspects a WordPress site for known security weaknesses in its core, plugins, and themes. It fingerprints the version of each component, then matches those versions against a database like WPScan and the wider CVE feeds to report which carry known, exploitable flaws. Unlike a malware scanner, which detects code that is already malicious, a vulnerability scanner finds the outdated or misconfigured components an attacker could exploit before any breach happens. ScanTitan adds proof for every finding and reaches the authenticated surface most free scanners cannot.
Enter your site URL into ScanTitan and run a passive scan, which fingerprints your core, plugins, and themes from the outside in a couple of minutes with no installation. For deeper coverage, connect authenticated access so the scanner reaches admin-only pages and inactive plugins. ScanTitan then matches every detected version against the WPScan database and 100,000+ CVEs, reports each finding with its CVSS score and HTTP evidence, and gives a plain-language fix. You can schedule scans so newly disclosed vulnerabilities are caught automatically.
Plugins account for more than half of all WordPress compromises because they are third-party code of wildly varying quality, installed with high privileges, and often left unmaintained. WordPress core is patched fast and auto-updates by default, but a plugin from a small developer may go months or years without a security fix, and site owners rarely track which of their two dozen plugins is behind. Attackers scan the internet for specific vulnerable plugin versions with public exploits, so a scanner that checks only core misses the biggest source of real-world breaches.
A passive scan is low-impact and safe on production at any time; it sends a small number of requests and reads public signals. A deep authenticated scan that enumerates thousands of plugin and theme paths generates far more requests, which is why ScanTitan rate-limits it and lets you schedule it off-peak. The scanner uses non-destructive checks: it confirms a vulnerable version exists without exploiting it, so it never modifies your data or takes your site down.
Continuously, or at minimum weekly. New plugin and theme CVEs are published constantly, so a site that scanned clean last month can be exposed today without a single change on your end, simply because a vulnerability was disclosed in a plugin you already run. ScanTitan's scheduled scanning re-checks your components against the latest vulnerability data automatically and alerts you the moment a clean site turns vulnerable. For agencies, automated portfolio scanning is the only realistic way to keep up with the pace of WordPress disclosures.
Yes, to the extent they can be fingerprinted and have known vulnerabilities. ScanTitan detects premium plugins like Advanced Custom Fields Pro, Elementor Pro, and WooCommerce extensions by their file signatures and version markers, then matches them against the WPScan database and CVE feeds the same way it handles free plugins. For fully custom plugins with no public record, it still flags risk signals like an unmaintained codebase and exposed files, and the authenticated web-application scan on the parent hub tests the custom code itself for issues like SQL injection and XSS.
A vulnerability scan is proactive: it finds the outdated plugins, unpatched core, and exposed files an attacker could exploit, so you close them before a breach. A malware scan is reactive: it detects malicious code, such as backdoors, SEO spam, and redirects, that is already on a compromised site. Both matter, and running only one leaves a gap. ScanTitan covers vulnerability scanning here and pairs it with a dedicated malware removal service, so the same platform handles both closing the doors and cleaning up if someone got in.
No. The passive and unauthenticated scans run entirely from ScanTitan's side, so you just enter your URL and get results, no installation required. If you want authenticated depth that reaches admin-only pages and inactive plugins, you can connect access with a lightweight WordPress plugin or credentials, but that is optional. The external scan alone already covers core, active plugins, themes, exposed files, and user enumeration, which is where most real-world WordPress compromises begin.

Is ScanTitan's WordPress scanner right for you?

We would rather tell you now than after you have signed up.

Your WordPress plugins have known vulnerabilities. Find them before attackers do.

ScanTitan scans your WordPress core, plugins, and themes against the WPScan database and 100,000+ CVEs, proves every finding with HTTP evidence, and tells you exactly what to patch first.

OSCP · CISSP · 12 years in web application security · Author profile →