Scanning WordPress for vulnerabilities


wpscan on github

The quickest way to use it seems to be docker.

docker pull wpscanteam/wpscan
# minimal run
docker run --rm wpscanteam/wpscan -u
# more details options (enumerate vulnerabilities of identify plugins)
docker run --rm wpscanteam/wpscan -u --follow-redirection --update --enumerate

