WPScan
Web Applicationkali · parrotWordPress vulnerability scanner for plugins, themes, and users.
Install
sudo apt install wpscan
Common commands
wpscan --url https://target.com --enumerate u,vp,vt wpscan --url https://target.com --api-token YOUR_TOKEN
Use only on systems you are authorized to test. Follow program scope.
Related tools
Burp Suite
featuredThe industry-standard intercepting proxy for web app and API testing. Core bug bounty tool.
ffuf
featuredFast web fuzzer for directories, virtual hosts, and parameters. Preferred over older gobusters for speed.
httpx
featuredFast HTTP toolkit from ProjectDiscovery for probing live hosts and tech detection.
OWASP ZAP
featuredFree open-source web app scanner and proxy — solid Burp alternative for automated scans.