---
title: WPScan Reviews
meta_title: 'WPScan Reviews 2026: Details, Pricing, & Features | G2'
meta_description: Filter reviews by the users' company size, role or industry to find
  out how WPScan works for a business like yours.
aggregate_rating:
  rating_value: 5.0
  review_count: 2
  scale: '5'
date_modified: '2026-08-02'
parent_category:
  name: "DevSecOps\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t"
  url: https://www.g2.com/categories/devsecops
---


# WPScan Reviews
**Vendor:** Automattic Inc.  
**Category:** [Vulnerability Scanner Software](https://www.g2.com/categories/vulnerability-scanner)  
**Average Rating:** 5.0/5.0  
**Total Reviews:** 2
## About WPScan
Enterprise grade WordPress malware database. Be the first to know about vulnerabilities affecting your WordPress installation, plugins, and themes. It’s like having your own team of WordPress security experts. - All vulnerabilities are manually vetted in our database by seasoned WordPress security professionals. - WPScan works with security researchers, vendors, and the WordPress community to triage vulnerabilities. - The vulnerability database is updated constantly as we discover new threats. WordPress integrations - No matter the size of your business, we’ve got a WordPress plugin that fits into your existing workflows. CLI security scanner - Get the hackers’ point of view with a command line interface written for security professionals. Versatile API - Tap directly into the vulnerability database API to get the latest WordPress vulnerabilities.




## WPScan Reviews
  ### 1. A practical security check for WordPress sites carrying years of plugin baggage

**Rating:** 5.0/5.0 stars

**Reviewed by:** Alamgir H. | Senior WordPress Engineer, Information Technology and Services, Mid-Market (51-1000 emp.)

**Reviewed Date:** July 28, 2026

**What do you like best about WPScan?**

WPScan CLI Scanner is most useful for us when a WordPress installation has been running long enough that nobody fully trusts the plugin inventory anymore. It does far more than simply report that WordPress is outdated. It can identify the Core version, enumerate plugins and themes, match installed versions against known vulnerabilities, and look for the kinds of leftovers that build up after years of migrations and emergency fixes: public configuration backups, exposed database dumps, accessible error logs, directory listing, user enumeration, and other risky configuration details. Its vulnerability data covers WordPress Core, plugins, and themes, and the findings may include references, fixed versions, CVEs, vulnerability types, and proof-of-concept information. That extra context helps us distinguish between a plugin that’s merely old and one where the installed version has a documented issue we need to address before touching production. Version 4 also made plugin discovery more deliberate. A standard scan no longer tries to identify every installed plugin automatically, so when we need a full inventory review, we explicitly enable the relevant enumeration options. I prefer that behavior because it makes the scan’s scope clearer. A quick command shouldn’t give the team false confidence that a deep audit happened in the background.

**What do you dislike about WPScan?**

I haven’t run into any major issues that would make me stop using WPScan, but you do need to be clear on exactly what it does—and what it doesn’t do.

**What problems is WPScan solving and how is that benefiting you?**

A WooCommerce store needed a PHP and WordPress upgrade within a tight maintenance window, but the installation had more than thirty plugins, and several hadn’t been updated in months. We ran WPScan CLI against staging with explicit plugin and theme enumeration, authenticated using a WPScan Vulnerability Database API token, and exported the results as SARIF so the findings could be reviewed alongside the repository work. The scan flagged a form plugin with a vulnerability that was fixed in the next release, an abandoned component with no patch available, and a configuration backup that was still publicly accessible inside a directory left behind from an earlier migration. The first run also returned enough 403 responses to make the inventory unreliable, because the hosting security layer was blocking part of the enumeration. Instead of treating that incomplete output as definitive, we arranged an authorized testing window, reran the scan, and confirmed the installed versions from the WordPress admin before finalizing the change plan. We upgraded the plugin that had a fix available, replaced the abandoned component, removed the exposed backup, and documented why another finding didn’t apply under the site’s configuration. WPScan surfaced a file the admin panel would never have shown, and it helped us prioritize based on actual risk rather than blindly updating every outdated plugin while production was already offline.

  ### 2. WP Scan is the industry standard for WordPress vulnerabilities

**Rating:** 5.0/5.0 stars

**Reviewed by:** Jon B. | VP of partnerships, Mid-Market (51-1000 emp.)

**Reviewed Date:** January 02, 2024

**What do you like best about WPScan?**

WPScan is the WordPress vulnerability scanner that professionals trust. They have been doing it for much longer than anyone else and are run by the team that manages WordPress.com, WordPress VIP, Woo Commerce, etc. WPScan is  integrated with many other tools so it's easy to integrate into your workflow.

**What do you dislike about WPScan?**

Looking forward to seeing additional features from WPScan

**What problems is WPScan solving and how is that benefiting you?**

We have hundreds of WordPress sites and WPScan gives us full confidence that we are not running vulnerable plugins.



- [View WPScan pricing details and edition comparison](https://www.g2.com/products/wpscan/reviews?section=pricing&secure%5Bexpires_at%5D=2026-08-08+11%3A40%3A22+-0500&secure%5Bsession_id%5D=df393377-a5c5-4e42-b070-a2a7f902ea49&secure%5Btoken%5D=fecc96d18815d559b35b0ff25f766909649d41990cd14493a813c2ebbddbb728&format=llm_user)

## WPScan Features
**Performance**
- Issue Tracking
- Detection Rate
- False Positives
- Automated Scans
- Anomaly/Malware Detection

**Network**
- Compliance Testing
- Perimeter Scanning
- Configuration Monitoring
- Vulnerability Scanning
- Source-Code Scanning
- Web Scanning

**Application**
- Manual Application Testing
- Static Code Analysis
- Black Box Testing
- Risk Analysis

**Agentic AI - Vulnerability Scanner**
- Autonomous Task Execution
- Proactive Assistance

**Additional Functionality**
- SSL Security
- HIPAA Compliant
- API
- Threat Response
- Endpoint Protection
- Maintenance Scheduling
- Third-Party Integrations
- Security Auditing
- Application Security
- Encryption
- Network Security
- Real-Time Reporting
- AI Copilot
- Reporting/Analytics
- Authentication
- Financial Data Protection
- Anti Virus
- Secure Data Storage
- Virus Definition Update
- Activity Dashboard
- VPN
- Audit Trail
- Anti Spam
- Access Controls/Permissions
- Data Visualization
- Alerts/Escalation
- Data Security
- Runtime Container Security
- Asset Discovery
- Threat Intelligence
- Vulnerability Protection
- Alerts/Notifications
- Vulnerability/Threat Prioritization
- Generative AI
- SQL Injections
- Real-Time Analytics
- Threat Protection
- Web-Application Security
- Password Protection
- Website Crawling
- Vulnerability Assessment

## Top WPScan Alternatives
  - [Wiz](https://www.g2.com/products/wiz-wiz/reviews) - 4.7/5.0 (838 reviews)
  - [Red Hat Ansible Automation Platform](https://www.g2.com/products/red-hat-ansible-automation-platform/reviews) - 4.6/5.0 (369 reviews)
  - [Orca Security](https://www.g2.com/products/orca-security/reviews) - 4.7/5.0 (315 reviews)

