ScanTitan is a WordPress vulnerability scanner that fingerprints your core, every plugin, and every theme, then matches each version against the WPScan database and 100,000+ CVEs, with proof-based HTTP evidence for every finding and authenticated depth most free scanners miss.
100,000+ CVEs matched · CVSS 3.1 scoring
WPScan database: 75,000+ cataloged WordPress vulnerabilities
56% of WordPress hacks start with a vulnerable plugin
100,000+ CVEs matched · CVSS 3.1 scoring
WPScan database: 75,000+ cataloged WordPress vulnerabilities
56% of WordPress hacks start with a vulnerable plugin
A WordPress vulnerability scanner is an automated tool that inspects a WordPress site for known security weaknesses in its core, plugins, and themes. It fingerprints the exact version of each component, then matches those versions against a database like WPScan and the wider CVE feeds to report which ones carry known, exploitable flaws.
A version check tells you a plugin is outdated. ScanTitan tells you the CVE, the CVSS score, the HTTP evidence that confirms it, and the exact version that fixes it, so your team spends time patching, not guessing.
Whether you run one blog, a WooCommerce store, or a portfolio of client sites, ScanTitan gives you attacker-level enumeration plus authenticated depth, and it flags risky plugins even when no CVE has been published yet.
ScanTitan identifies the exact core version from the generator meta tag, readme.txt stable tag, static file paths under wp-includes, and the WordPress.org API, cross-checking multiple signals for accuracy.
The scanner detects every installed plugin and theme with its exact version by analyzing wp-content paths, CSS and JavaScript fingerprints, and stylesheet headers, including inactive components most scanners skip.
Each detected version is matched against the WPScan vulnerability database and 100,000+ CVEs, so an outdated component becomes a named CVE with a CVSS 3.1 score and the release that fixes it.
ScanTitan looks for the leaks an attacker grabs first: readable wp-config.php backups, database dumps, directory listing, and enumerable usernames that feed brute-force attacks.
Every finding ships with the exact request and response that confirmed it, so nothing reaches your dashboard as an unproven guess and no client can dispute it.
Findings are ranked by CVSS and real-world exploitability, each with a plain-language fix and a one-click re-scan that verifies the vulnerability is closed.
Real result (placeholder), A 12-site agency ran ScanTitan across its whole portfolio and found three sites running a Revolution Slider build with a public arbitrary-file-download exploit. All three were patched the same afternoon, before a single site was compromised.
Most free WordPress scanners run one way: unauthenticated, seeing only what a logged-out visitor sees. That is a useful attacker’s-eye view, but it misses everything behind the login. ScanTitan runs both, so you choose the depth.
Passive scan fingerprints core, plugins, and themes from public signals with low impact, safe on production and ideal for a fast portfolio sweep. Authenticated scan logs in and reaches the admin surface: inactive plugins, admin-only pages, and configuration a logged-out visitor never sees, exactly what a compromised-credential attacker would reach.
No noise, Aggressive enumeration can send thousands of requests, so ScanTitan rate-limits deep scans and schedules them off-peak. You get attacker-level depth without tripping your own intrusion prevention.
Every finding ships with a plain-language fix tailored to the component: the exact plugin version to update to, the config to change, or the file to remove. Not a generic CVE link, a specific next step.
After you apply the fix, trigger a one-click re-scan. ScanTitan confirms the vulnerable version is gone and attaches a clean-scan record to the issue, which doubles as audit and client evidence that the problem was found and fixed.
Clean stays clean, Scheduled scanning re-checks every component against the latest WPScan data, so the day a new plugin CVE drops, the sites running it get flagged automatically, not at your next manual review.
| How WordPress sites get hacked | Share of compromises | What ScanTitan checks |
|---|---|---|
| Vulnerable plugins | 56% | Every plugin version matched to WPScan + CVEs |
| Brute force attacks | 16% | Exposed usernames and weak login surface |
| Theme vulnerabilities | 12% | Active and inactive theme versions and CVEs |
| WordPress core vulnerabilities | 9% | Exact core version and applicable core CVEs |
| Server misconfiguration | 7% | Exposed config backups, dumps, directory listing |
Exact core version from the generator tag, readme.txt, wp-includes paths, and the WordPress.org API, cross-checked and matched to core CVEs with CVSS scores.
Every plugin and version enumerated and matched to WPScan and CVEs, covering WooCommerce, Elementor, Yoast SEO, Contact Form 7, ACF, Jetpack, and thousands more.
Active and inactive themes detected from stylesheet headers and file paths, with each version matched to known theme CVEs and the patch that resolves it.
Flags plugins and themes with no published CVE but no updates in years or removed from the directory. An unmaintained component is a latent exposure, scored as elevated risk.
Detects readable wp-config.php backups, database dumps, leftover installer files, and directory listing on wp-content paths, each with the URL and HTTP response that proves it.
Finds publicly enumerable usernames that feed the brute-force attacks behind 16% of WordPress compromises, so you can close the login surface before it is sprayed.
Every detected version matched against the WPScan database, the most authoritative WordPress vulnerability catalog, plus the wider CVE and NVD feeds, updated continuously.
Multiple independent detection methods, generator tag, static file analysis, path-based checks, WordPress.org API, and readme.txt parsing, for high version accuracy.
Every finding includes the HTTP request and response that confirmed it. No probability guesses, so you or your client can act and verify without second-guessing.
Exact core version from the generator tag, readme.txt, wp-includes paths, and the WordPress.org API, cross-checked and matched to core CVEs with CVSS scores.
Every plugin and version enumerated and matched to WPScan and CVEs, covering WooCommerce, Elementor, Yoast SEO, Contact Form 7, ACF, Jetpack, and thousands more.
Active and inactive themes detected from stylesheet headers and file paths, with each version matched to known theme CVEs and the patch that resolves it.
Detects readable wp-config.php backups, database dumps, leftover installer files, and directory listing on wp-content paths, each with the URL and HTTP response that proves it.
Finds publicly enumerable usernames that feed the brute-force attacks behind 16% of WordPress compromises, so you can close the login surface before it is sprayed.
Flags plugins and themes with no published CVE but no updates in years or removed from the directory. An unmaintained component is a latent exposure, scored as elevated risk.
Every detected version matched against the WPScan database, the most authoritative WordPress vulnerability catalog, plus the wider CVE and NVD feeds, updated continuously.
Multiple independent detection methods, generator tag, static file analysis, path-based checks, WordPress.org API, and readme.txt parsing, for high version accuracy.
Every finding includes the HTTP request and response that confirmed it. No probability guesses, so you or your client can act and verify without second-guessing.
A WordPress vulnerability scanner finds weaknesses before they are exploited: outdated plugins, unpatched core, exposed config, the open doors. It is proactive and prevents the compromise.
A malware scanner finds the damage after a breach: injected backdoors, SEO spam, redirect scripts, the intruder already inside. It is reactive and cleans up after one. Running only a malware scanner is like checking for burglars without ever locking the door.
Proactive. Finds exploitable plugins, themes, core, and exposed files so you can close them before an attacker gets in.
Reactive. Detects backdoors, SEO spam, and redirects on an already-compromised site. See ScanTitan malware removal.
Vulnerability scanning locks the doors; malware scanning cleans up if someone got in. ScanTitan covers both under one roof.
WordPress core, every plugin, and every theme with its exact version and vulnerable status.
CVE ID, CVSS 3.1 score, exploit availability, and the exact version that patches it.
Request sent and response received for each finding. Fully reproducible, dispute-proof.
Unmaintained or removed plugins and themes scored as elevated risk even with no CVE.
A specific fix per finding, followed by a one-click re-scan that verifies it is closed.
Agency-ready reports that show what was found, what was fixed, and when.
# Scan a WordPress site, authenticated deep scan curl -X POST https://api.scantitan.com/v1/wp-scans \ -H "Authorization: Bearer YOUR_API_KEY" \ -H "Content-Type: application/json" \ -d '{ "target": "https://client-blog.com", "scan_type": "authenticated", "notify": ["slack","email"] }' # Response { "scan_id": "wp_4a8c2f", "status": "queued", "plugins_found": 24 }- schedule: weekly targets: all_sites alert_on: new_cve,critical,high report: white_label_pdfAll sites, one screen
Daily / weekly / monthly
Instant vuln alerts
Clean-to-vulnerable alerts
Auto-create tickets
Client-ready reports
Authenticated access
Any tool via JSON
Trigger + pull results
Real outcomes from real scans. Numbers are placeholders, replace with verified client data before publishing.
Three client sites ran a Revolution Slider build with a public arbitrary-file-download exploit that reads wp-config.php. The agency patched all three the same afternoon.
3
1 aft
0
A WooCommerce extension was running a version with a known SQL injection CVE. ScanTitan flagged it with HTTP evidence and the exact patch version before any customer data was touched.
1
2h
0
Newly disclosed plugin CVEs sat unpatched for weeks across a large site network. Scheduled portfolio scanning now flags every affected site the day a CVE is published.
80
<24h
1
A leftover wp-config.php.bak in the web root exposed database credentials in plaintext. ScanTitan surfaced it with the exact URL and response, and the owner removed it immediately.
1
5 min
0
July 2026
ScanTitan now scores plugins and themes with no published CVE but no updates in years, or removed from the WordPress.org directory, as elevated risk, so you can replace latent exposures before a CVE exists.
May 2026
Authenticated scans now enumerate installed-but-inactive plugins and themes, catching vulnerable components that a logged-out scan never sees.
March 2026
Continuous synchronization with the WPScan vulnerability database means a plugin gets re-flagged the day a new CVE is published, and your scheduled scan catches it automatically.
January 2026
Agencies can now scan and monitor an entire portfolio from one dashboard, with white-label PDF reports and per-site alerting on new vulnerabilities.
| ScanTitan | WPScan | Pentest-Tools | WPSec | HackerTarget | |
|---|---|---|---|---|---|
| Core, plugin, theme CVE detection | ✓ | ✓ | ✓ | ✓ | ✓ |
| Authenticated scanning | ✓ | CLI | ✓ | Partial | Partial |
| Proof-based HTTP evidence | ✓ | ✗ | ✓ | ✗ | ✗ |
| Risk score for plugins with no CVE | ✓ | ✗ | ✗ | ✓ | ✗ |
| Plain-language fix + re-scan | ✓ | Partial | Partial | ✓ | ✗ |
| Multi-site / agency dashboard | ✓ | Enterprise | Partial | ✓ | ✓ |
| Vulnerability + malware in one platform | ✓ | ✗ | ✗ | ✗ | ✗ |
| Entry point | Free scan | Free DB / API | 7-day trial | Free basic | Free basic |
4.8
G2 · placeholder
4.9
Capterra · placeholder
"We run 40 client WordPress sites. ScanTitan flagged a critical plugin CVE across three of them the day it was disclosed. The white-label reports are now part of every client's monthly care plan."
OSCP · CISSP · 12 years in web application security · Author profile →